Executive Summary
Pfcloud UG (AS51396) remains the most active bulletproof hosting provider in the monitored set. It generated 11,483 honeypot events this week, a 37% increase over the prior week. The provider deployed a new block of proxy nodes in the 204.76.203.2xx range. Two of these nodes share the same SSH host key. This is a definitive signal of cloned infrastructure.
RouterHosting (AS14956) showed the largest relative change. Its event count rose 312% to 206 events. The provider added a new attack pattern: PPTP brute-force on port 1723. This pattern was not present in the prior week.
KPRONET (AS214940) stopped its .git and .env exfiltration campaign. Its event count fell 96% to 9 events. The same exfiltration pattern now appears on PLI-AS (AS51852). This suggests the operator moved infrastructure between providers.
By the Numbers
| ASN | Provider | Sponge Sessions | Honeylabs Events | Top Attack Profile | Change vs Prior Week |
|---|---|---|---|---|---|
| AS138915 | KAOPU-HK | 862,446 | 0 | NTP/SSDP amplification scanning | +5% |
| AS51396 | PFCLOUD | 10,000+ | 11,483 | Proxy checking (SOCKS5 + HTTP CONNECT) | +37% |
| AS51852 | PLI-AS | 10,000+ | 143 | .env/.git exfil, RDP brute, DCE/RPC | -29% |
| AS198953 | PROTON66 | 10,000+ | 245 | MSSQL-TDS brute on non-standard ports | +145% |
| AS14956 | ROUTERHOSTING | 10,000+ | 206 | PPTP brute (1723), RDP, binary scanning | +312% |
| AS57043 | HOSTKEY-AS | 2,509 | 0 | SSH variant port scanning | — |
| AS216246 | RU-AEZA-AS | 10,000+ | 1 | High-port web scanning (8888, 8080) | new |
| AS214940 | KPRONET | 9,776 | 9 | .git/.env exfiltration (largely stopped) | -96% |
| AS210644 | AEZA-AS | 3,999 | 4 | SSH variant port scanning | new |
| AS200651 | FLOKINET | 2,986 | 6 | Tor exit relay, SSH brute | -88% |
| AS209847 | THE | 3,062 | 0 | Port 0 traffic, SSH, DNS | — |
| AS400992 | ZHOUYISAT | 2,343 | 0 | Web scanning (80/443) | — |
| AS213702 | QWINS-LTD | 2,341 | 0 | Single-IP dominance, HTTPS | — |
| AS30823 | AUROLOGIC | 647 | 0 | SIP/VoIP scanning | — |
| AS211720 | Datashield | 222 | 0 | VNC/RDP/SQL scanning | — |
| AS216139 | IRONHOST | 150 | 0 | High SSH ports (22222, 2222) | — |
| Others (10 ASNs) | Various | < 50 | 0 | — | — |
“Others” includes 10 ASNs with negligible or zero Sponge activity.
Top ASN Deep Dives
AS51396 (PFCLOUD / Pfcloud UG)
As noted, PFCLOUD is the most active provider in the monitored set. It generated 11,483 honeypot events this week, up 37% from the prior week. The provider operates a large proxy-validation network.
The most significant finding is a new block of proxy nodes in the 204.76.203.2xx range. Five new IPs appeared this week: 204.76.203.221, .214, .213, .212, and .222. Each generated over 1,200 events. These nodes run a proxy service on port 9191. The service returns HTTP 407 Proxy Authentication Required. This is a paid-proxy gate.
Two of these nodes, 204.76.203.221 and 204.76.203.214, share the same SSH host key (27c4af41...). They also share the same HASSH fingerprint (41ff3ecd...). This is a definitive signal of cloned infrastructure. The operator provisioned both nodes from the same disk image. This is a common pattern in automated proxy fleets.
The proxy-checking behavior is unchanged from prior weeks. The nodes test HTTP CONNECT tunnels to httpbin.org:443 and google.com:443. They also test SOCKS5 proxies. The German nodes 45.135.193.193 and 45.135.194.113 run a proxy-judge check against proxy.flarevpn.digital:8080/judge. This is a proxy-quality validation service.
The 204.76.203.0/24 block is registered to Intelligence Hosting LLC, a Pfcloud affiliate.
AS14956 (ROUTERHOSTING / RouterHosting LLC)
RouterHosting showed the largest relative change this week. Its event count rose 312% to 206 events. The provider added a new attack pattern: PPTP brute-force on port 1723.
The source IP 144.172.100.63 (Las Vegas) sent sustained PPTP connection attempts to port 1723. The PPTP control packets contain the username “cananian”. This is a credential-guessing pattern. The same IP also probed port 25565 (Minecraft) and port 8291 (MikroTik RouterOS).
A second IP, 216.126.239.150 (Ogden), ran RDP probes against port 3389. The RDP packets carry the standard mstshash cookie. This is a common RDP brute-force signature.
Censys shows RouterHosting is a large fleet. It has 24,735 hosts. The fleet runs OpenSSH 9.6p1 and nginx. The IP 144.172.100.63 resolves to over 100 domains, including openmaven.org, hostabro.net, and uddoktaserver.org.
AS51852 (PLI-AS / Private Layer INC)
PLI-AS generated 143 events this week, down 29% from the prior week. The provider’s attack profile shifted. The .git and .env exfiltration pattern that previously appeared on KPRONET now appears on PLI-AS.
The source IP 179.43.150.26 (Switzerland) probed ports 8001 and 8443. It requested paths /.env, /.git, and randomized paths like /z5044, /s/5124, and /.e2382. The randomized paths suggest a directory-bruteforce tool. The /.env request targets environment files that contain database credentials and API keys.
A second IP, 179.43.186.199, ran RDP brute-force with the “Administrator” account. A third IP, 81.17.28.131, probed DCE/RPC on port 135 and HTTP on ports 8899 and 8089. The IP 179.43.146.27 resolved to mta2.smartfastjoy3.com and probed CouchDB ports 5984 and 5601 over TLS.
The provider is Swiss-located and Panama-incorporated. This legal and geographic separation is a classic bulletproof hosting pattern.
AS198953 (PROTON66 OOO)
PROTON66 generated 245 events this week, up 145% from the prior week. The provider ran a dense MSSQL-TDS brute-force campaign from a single Russian IP.
The source IP 176.120.22.61 (Russia) sent TDS pre-login packets to 17 non-standard ports. The ports include 1002, 1501, 18433, 8888, 14433, 8899, 55366, 7366, 25366, 3333, 7433, 16433, 8433, 1435, 3433, 2008, and 12345. The port selection suggests the attacker is scanning for SQL Server instances moved off the default port 1433.
The TDS packets are identical across all ports. This indicates a single automated tool. The campaign is systematic credential harvesting for SQL Server pivoting.
AS200651 (FLOKINET ehf)
FLOKINET generated only 6 events this week, down 88% from the prior week. The Tor exit relay 185.100.87.136 remains active but with reduced volume. The relay still probes ports 8080 and 443.
The reduced volume may indicate the operator is rotating infrastructure. The Tor exit relay remains a concern because it provides attribution ambiguity.
Infrastructure Correlation
PFCLOUD runs cloned proxy infrastructure. As noted, the IPs 204.76.203.221 and 204.76.203.214 share the same SSH host key and HASSH fingerprint. This is a core signal of automated provisioning from a single disk image. The operator can scale the proxy fleet rapidly.
The HASSH fingerprint e42184b06d45385a906f0803d04c83da spans multiple providers. This fingerprint appears on PFCLOUD nodes 45.135.193.193 and 45.135.194.113, and on RouterHosting nodes 144.172.104.239, 144.172.100.63, and 172.86.119.157. The shared fingerprint indicates a common OpenSSH 9.6p1 configuration. This is a weak correlation signal, but it suggests the operators use the same base image.
The .env exfiltration pattern moved from KPRONET to PLI-AS. The prior week’s report identified KPRONET as the source of .git and .env exfiltration. This week the pattern appears on PLI-AS. The operator likely moved infrastructure between providers to evade detection.
Fleet Observations
- SSH exposure is near-total: Port 22 is the most common open service across all Censys-profiled ASNs. HOSTKEY leads with 76,586 hosts on port 22.
- Port 2096 as proxy signal: HOSTKEY (15,128) and AEZA (12,758) show massive port 2096 exposure, associated with WebSocket and Cloudflare proxy tunnels.
- KAOPU-HK continues NTP amplification mapping: Despite zero Honeylabs events, KAOPU-HK dominates Sponge volumes with 862,446 sessions from a single IP (38.54.2.209) exclusively targeting NTP port 123 and SSDP port 1900.
- PFCLOUD proxy port moved to 9191: The prior week’s proxy service ran on port-paired 8080/3128. This week the new nodes expose the proxy on port 9191.
IoCs and Detection Guidance
Notable IPs (with Censys enrichment):
- 204.76.203.221 — PFCLOUD proxy node, shared SSH key, BULLETPROOF, GreyNoise: malicious
- 204.76.203.214 — PFCLOUD proxy node, shared SSH key, BULLETPROOF, GreyNoise: malicious
- 204.76.203.213 — PFCLOUD proxy node, 1,273 events
- 204.76.203.212 — PFCLOUD proxy node, 1,268 events
- 204.76.203.222 — PFCLOUD proxy node, 1,252 events
- 45.135.193.193 — PFCLOUD proxy-judge checker, proxy.flarevpn.digital, GreyNoise: malicious
- 45.135.194.113 — PFCLOUD SOCKS5 + HTTP proxy checker, GreyNoise: malicious
- 144.172.100.63 — ROUTERHOSTING PPTP brute (1723), 100+ hosted domains
- 216.126.239.150 — ROUTERHOSTING RDP brute (3389)
- 179.43.150.26 — PLI-AS .env/.git exfiltration, ports 8001/8443
- 179.43.186.199 — PLI-AS RDP brute (Administrator)
- 176.120.22.61 — PROTON66 MSSQL-TDS brute, 17 non-standard ports
- 185.100.87.136 — FLOKINET Tor exit relay, reduced volume
Fingerprints:
- HASSH
41ff3ecd1458b0bf86e1b4891636213e— PFCLOUD cloned proxy nodes (204.76.203.221/214) - HASSH
e42184b06d45385a906f0803d04c83da— shared OpenSSH 9.6p1 config across PFCLOUD + ROUTERHOSTING - JA4H
ge11nn0400_9c3956fad5da— PFCLOUD Go-http-client/1.1 proxy checker - JA4H
ge11nn0400_88d30a62b7ad— PFCLOUD zgrab/0.x web scanner - JA4H
ge10nn0400_17292dadbc7b— PFCLOUD odin-scanner/0.4 - JA4H
ge11nn0300_341eb0d8946c— PLI-AS .env/.git exfiltration - JA4
t13i1310h1_f57a46bbacb6_e7c285222651— PLI-AS Firefox/140 TLS
Detection Patterns:
- PFCLOUD proxy: HTTP 407 Proxy Authentication Required on port 9191 from 204.76.203.0/24
- PFCLOUD cloned infra: SSH host key
27c4af41372096a86b44300cce230144d9dec17b871fdf920c624bb8349adc2e - ROUTERHOSTING PPTP: PPTP control packets with username “cananian” to port 1723
- PLI-AS exfil:
/.envand/.gitpaths from 179.43.150.26 on ports 8001/8443 - PROTON66 MSSQL: TDS pre-login packets from 176.120.22.0/24 to non-standard ports
Full data: https://git.sr.ht/~hrbrmstr/gists/tree/main/item/kevlar/2026-08-10/