1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
|
# Weekly BP Report -- 2026-08-02
Generated: 2026-08-03T04:00:00Z
ASNs covered: 26
Sponge sessions found: 10,000+ across 21 active ASNs (capped per query)
Honeylabs events found: 8,400+ across 7 ASNs (PFCLOUD, HOSTKEY, ROUTERHOSTING, PLI-AS, PROTON66, FLOKINET, KPRONET, AUROLOGIC)
Censys IPs profiled: 6 ASN-level + 3 per-IP enrichments (190K+ hosts, all BULLETPROOF-labeled)
Anomalies flagged: 1 (FLOKINET operates Tor exit relay with concurrent brute-force activity)
## Key Findings
- 7 of 26 ASNs generated Honeylabs events (not 1 as initially reported)
- All Censys-profiled hosts are universally classified as BULLETPROOF
- KPRONET: .git/.env exfiltration campaign with 20+ spoofed user agents
- PLI-AS: Multi-modal attack (DCE/RPC, RDP brute, tRPC, WordPress scanning)
- FLOKINET: Tor exit relay (185.100.87.136) with SSH/Telnet brute-force
- HOSTKEY: RTSP camera credential stuffing against Hikvision cameras
- PROTON66: MSSQL-TDS brute-force on non-standard ports
- PFCLOUD: Consistent proxy checking with port-paired infrastructure
- KAOPU-HK: 818K NTP/SSDP amplification scanning sessions (zero Honeylabs)
## Data Sources
- Sponge (Arkime): network sensor sessions across full deployment
- Honeylabs: global honeypot network, 7-day window (2026-07-27 to 2026-08-02)
- Censys: internet-wide host profiling + per-IP enrichment
|