1
2
3
4
5
6
7
8
9
10
|
{"ip":"176.120.22.61","asn":198953,"org":"Proton66 OOO","country":"RU","labels":["BULLETPROOF"],"os":"windows","hostname":"M051108","services":[{"port":135,"protocol":"DCERPC","note":"MS-SCMR/MS-SAMR/MS-RPRN bindings exposed; REMOTE_ACCESS label"},{"port":137,"protocol":"NETBIOS","note":"exposed"},{"port":139,"protocol":"NETBIOS","note":"exposed"},{"port":3389,"protocol":"RDP","note":"self-signed CN=M051108 SHA1-RSA cert, valid to 2027-02-12; screenshot captured"},{"port":5985,"protocol":"WINRM","note":"Microsoft-HTTPAPI/2.0 404"},{"port":47001,"protocol":"WINRM","note":"Microsoft-HTTPAPI/2.0 404"}],"note":"mssql-tds sweeper (598 events this week); box itself fully exposed; unchanged from prior week"}
{"ip":"45.11.18.33","asn":30823,"org":"aurologic GmbH","country":"DE","labels":["BULLETPROOF"],"os":"windows_server_2016","hostname":"erp01.ad.reiscrew.de","services":[{"port":389,"protocol":"LDAP","note":"AD rootDSE leaks domain ad.reiscrew.de, host erp01, USN 21300127"},{"port":443,"protocol":"HTTPS","note":"IIS 10.0 default page; self-signed CN=erp01.ad.reiscrew.de"},{"port":445,"protocol":"SMB","note":"SMB 3.0.2, NTLM, target name AD; critical exposure CENSYS-2022-1063"},{"port":3389,"protocol":"RDP","note":"RDSTLS restricted-admin; self-signed cert renewed 2026-08-16"},{"port":5985,"protocol":"WINRM","note":"exposed"}],"note":"Windows Server 2016 AD domain controller for reiscrew.de; doubles as RDP masscan (Cookie: mstshash=hello, 455 events). Compromised corporate DC running from aurologic 'Network used for hosting/infrastructure' 45.11.18.0/24"}
{"ip":"204.76.203.7","asn":51396,"org":"Pfcloud UG / Intelligence Hosting LLC","country":"NL","labels":["BULLETPROOF"],"os":"ubuntu","services":[{"port":22,"protocol":"SSH","note":"OpenSSH 9.6p1 Ubuntu; hassh e42184b06d45385a906f0803d04c83da"},{"port":9001,"protocol":"HTTP","note":"nginx/1.24.0 Ubuntu 403"}],"greynoise":"malicious; tags: Ivanti/Pulse Secure/F5 BIG-IP/CrushFTP/Sophos scanners, Open Proxy Scanner, SOCKS5 Proxy Scanner, Wordpress Enumeration","note":"proxy-validation node: azenv.net + httpbin.org CONNECT + socks5 judges; whois shows Intelligence Hosting LLC behind PFCLOUD 204.76.203.0/24"}
{"ip":"107.189.26.103","asn":14956,"org":"RouterHosting LLC (Cloudzy)","country":"NL","labels":["BULLETPROOF"],"reverse_dns":"103.26.189.107.static.cloudzy.com","services":[{"port":500,"protocol":"IKE","note":"VPN endpoint (IKEv1 accepted proposal)"},{"port":1701,"protocol":"L2TP","note":"hostname sasradius, vendor xelerance.com (Openswan/Libreswan)"},{"port":80,"protocol":"HTTP","note":"Apache 2.4.29"}],"note":"libredtail-http PHPUnit eval-stdin.php sweep (99 events) + ThinkPHP RCE + Docker /containers/json probes; legacy Apache 2.4.29 with critical CVEs; L2TP VPN box"}
{"ip":"81.17.28.131","asn":51852,"org":"Private Layer INC","country":"CH","labels":["BULLETPROOF"],"reverse_dns":"hostedby.privatelayer.com","services":[{"port":22,"protocol":"SSH","note":"OpenSSH 8.9p1 Ubuntu; hassh 41ff3ecd1458b0bf86e1b4891636213e"}],"greynoise":"unknown; tags: DCERPC Protocol, Ping Scanner, TLS/SSL Crawler, Web Crawler","note":"SAME HASSH as PFCLOUD clone pair 204.76.203.221/214 (prior weeks) -- cross-AS shared SSH config persists. DCE/RPC + port 8899 scanner"}
{"ip":"46.19.138.42","asn":51852,"org":"Private Layer INC","country":"CH","labels":["BULLETPROOF"],"reverse_dns":"hostedby.privatelayer.com","services":[{"port":22,"protocol":"SSH"},{"port":80,"protocol":"HTTP"},{"port":443,"protocol":"HTTP"},{"port":3000,"protocol":"HTTP","note":"new since 2026-08-18"},{"port":4000,"protocol":"HTTP"},{"port":8888,"protocol":"HTTP"}],"note":"marketmaker-bot scanner: mmsk-scout/mm-scout UA probing /version /pairs /v6/marketmaker/status/1 on ports 8001/8100/9000/9001"}
{"ip":"179.43.150.26","asn":51852,"org":"Private Layer INC","country":"CH","labels":["BULLETPROOF"],"reverse_dns":"hostedby.privatelayer.com","services":[{"port":22,"protocol":"SSH","note":"only live service; WinRM 5985 seen Sep 2025 only"}],"note":".env + random-path prober (/z875 /.e9951 /s/6051) against Vite dev server port 5173"}
{"ip":"185.100.87.136","asn":200651,"org":"FlokiNET ehf","country":"RO","labels":["BULLETPROOF","PROXY_SERVER"],"privacy":"tor exit","services":[{"port":80,"protocol":"HTTP","note":"Tor exit notice page"},{"port":7288,"protocol":"SSH","note":"non-standard SSH"},{"port":9001,"protocol":"UNKNOWN","note":"Tor OR port"}],"note":"beacon host: POST /api/checkin (8443), GET /images/transparentpix.gif (443, TLS1.3 ChaCha20, ja4 t13i1909h2_9dc949149365_97f8aa674fd9), binary 16-byte probes; endpoint rotated from last week's /api/client/update SPARK COMMIT"}
{"ip":"38.54.2.209","asn":138915,"org":"Kaopu Cloud HK Limited","country":"HK","labels":["BULLETPROOF"],"services":[{"ports":"~100+ open","protocol":"HTTP","note":"HTTP on ports 23/53/74/943/1963/2112/5901/6443/9200/27017/44818 etc; SSH 22/2222; Telnet 23/2323"}],"note":"946k lifetime Sponge sessions, 43k this week, 940k+ sessions from 38.54.2.x cluster; port-sprawl farm -- HTTP listeners on nearly every scanned port; top Sponge talker in the watched set"}
{"ip":"204.76.203.225","asn":51396,"org":"Pfcloud UG","country":"NL","labels":["BULLETPROOF"],"services":[{"port":9000,"protocol":"CLICKHOUSE_NATIVE"},{"port":8123,"protocol":"HTTP","note":"ClickHouse web UI"},{"port":9191,"protocol":"HTTP","note":"proxy port"},{"port":25565,"protocol":"MINECRAFT"},{"port":3000,"protocol":"HTTP","note":"new since 2026-04"}],"note":"proxy-fleet node; same ClickHouse+proxy profile as .224/.226 clone pair from prior weeks; 1872 events this week, idle since 08-20"}
|