aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-08-02/iocs/README.md
blob: 7bef1c9bfd992c2751435609128028fc6dfa744b (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
# Weekly BP Report -- 2026-08-02

Generated: 2026-08-03T03:43:00Z
ASNs covered: 26
Sponge sessions found: 10,000+ across 21 active ASNs (capped per query)
Honeylabs events found: 8,400 (AS51396 PFCLOUD only; 25 ASNs: zero)
Censys IPs profiled: 6 ASNs (190K+ hosts, all BULLETPROOF-labeled)
Anomalies flagged: 1 (universal BULLETPROOF classification across all profiled ASNs)

## Key Findings

- Only 1 of 26 ASNs (PFCLOUD) generated honeypot events; the other 25 show
  targeted scanning against real infrastructure
- All Censys-profiled ASNs are universally classified as BULLETPROOF
- KAOPU-HK (AS138915): 818K NTP/SSDP amplification scanning sessions
- PFCLOUD (AS51396): active proxy-checking (SOCKS5 + HTTP CONNECT) against honeypots
- HOSTKEY (AS57043) and AEZA (AS210644): largest infrastructure (100K+ and 69K hosts)
- PLI-AS (AS51852): massive Telnet brute-forcing (34K sessions)
- PROTON66 (AS198953): SSH/MSSQL/RDP scanning (102K sessions from single IP)

## Data Sources

- Sponge (Arkime): network sensor sessions across full deployment
- Honeylabs: global honeypot network, 7-day window (2026-07-27 to 2026-08-02)
- Censys: internet-wide host profiling