aboutsummaryrefslogtreecommitdiff
path: root/kevlar/2026-08-17/changes/anomalies.csv
blob: 0ce74b3408a16d3e4471b7cc0680c9301eba651d (plain)
1
2
3
4
5
6
7
8
9
severity,asn,anomaly,rationale
high,AS198953,MSSQL-TDS brute force +594% to ~1700 events,176.120.22.61 swept 289 distinct ports (was 17); Win box has exposed DCERPC+NetBIOS - likely compromised
high,AS200651,SPARK C2 beacon observed,185.100.87.136 POST /api/client/update w/ commit+secret header, /eventmanager, /ajax, agent UUID path; HASSH e54ef3ec; Tor exit + C2 combo
high,AS51396,Cloned infra + attribution crossover,"204.76.203.224/226 identical ClickHouse+proxy banner hashes; 77.83.39.6 shares HASSH 41ff3ecd w/ prior clone pair; .env exfil attributed to PFCLOUD per Censys vs KPRONET per honeylabs"
high,AS214940,.git/.env exfil campaign resumed,77.83.39.6/.94 hammer /.env + /.git/HEAD over TLS 443 with rotating UAs; high-confidence malicious verdict from honeylabs (25 exploit-path hits)
medium,AS14956,PPTP campaign ended - SMBv1 surge,PPTP 1723 dropped to 1 event; SMB 445 brute from 3 IPs + Minecraft 25565 + SIP 5060/5061
medium,AS138915,New WinRM attack vector,Python WinRM client POST /wsman from 154.93.53.239 (SC) - first non-amplification attack observed
medium,AS210644,qBittorrent peer scanning,77.110.106.52 swept 16663 repeatedly (qB5230 fingerprint); P2P probing pattern new this week
low,AS51396,ClickHouse exposed on 9009,Proxy nodes run public ClickHouse web UI - data exfil surface