Executive Summary
PFCLOUD (AS51396) drove the week. Its top talkers produced 87,938 sessions, up 152% from 34,932 the week before. A single host, 204.76.203.4, emitted 56,644 of those sessions. Honeylabs recorded 8,500 events from 49 PFCLOUD addresses. The fleet validates open proxies: our sensors caught GET http://proxy.flarevpn.digital:8080/judge from Go-http-client/1.1, aimed at ports 1080, 1082, 3128, 8000, 8080, and 8888.
AEZA-AS (AS210644) collapsed from 80,345 sessions to 97. Its only active Honeylabs source, 185.246.217.150, ran multi-vector exploit sweeps. The targets included PHPUnit eval-stdin.php under 37 distinct paths, ThinkPHP invokefunction RCE, a pearcmd file-inclusion chain, and the Docker API on port 2375. Censys labels the host BULLETPROOF. The same label now sits on 9 of the 10 hosts we enriched this week.
Two changes reshaped the tracking set. INVISIONTECH-GROUP-SRL (AS216309) appeared for the first time, and 20 addresses in 67.219.214.0/24 probed HTTP. ADPL-AS-AP (AS140666) added 3,757 visible hosts week-over-week, and one of its certificates names a USDTCDN issuer. At the other end, ten of the 25 tracked ASNs produced zero sensor sessions.
NOTE: The configuration of the Sponge fleet change, which has had some +/- impacts on the aggregate results. The majority of findings come from Honeylabs, but any changesd to UDP-based or SYN-only results may look different from previous weeks.
By the numbers
Sessions sum the top 20 source IPs per ASN over 2026-08-31 to 2026-09-07. Honeylabs event counts are sampled rows, capped at 100 per ASN. Censys hosts are the visible host count for each ASN.
| ASN | Provider | Top-talker sessions | Honeylabs events | Censys hosts | Top port | Change |
|---|---|---|---|---|---|---|
| AS51396 | PFCLOUD | 87,938 | 100 | 2,005 | 22 (SSH) | +152% |
| AS138915 | KAOPU-HK | 47,859 | 0 | 12,308 | 80 (HTTP) | -24% |
| AS198953 | PROTON66 | 1,469 | 100 | 359 | 4443 | -37% |
| AS14956 | ROUTERHOSTING | 270 | 95 | 25,632 | 22 (SSH) | -85% |
| AS400992 | ZHOUYISAT | 226 | 0 | 7,982 | 443 (HTTPS) | -12% |
| AS57043 | HOSTKEY-AS | 196 | 12 | 101,919 | 80 (HTTP) | +3167% |
| AS210644 | AEZA-AS | 97 | 51 | 71,701 | 443 (HTTPS) | -100% |
| AS51852 | PLI-AS | 97 | 32 | 8,634 | 443 (HTTPS) | -87% |
| AS200651 | FLOKINET | 76 | 24 | 3,824 | 443 (HTTPS) | +23% |
| AS214940 | KPRONET | 59 | 0 | 0 | 80 (HTTP) | -61% |
| AS216309 | INVISIONTECH | 26 | 0 | 37 | 80 (HTTP) | new |
| AS211720 | Datashield | 20 | 0 | 49 | 50443 | -61% |
| AS209847 | THE | 3 | 0 | 1,458 | 3389 (RDP) | -93% |
| AS30823 | AUROLOGIC | 2 | 0 | 2,178 | 5060 (SIP) | -78% |
| AS200593 | PROSPERO-AS | 1 | 0 | 340 | 443 (HTTPS) | -50% |
| AS216246 | RU-AEZA-AS | 0 | 2 | 6,960 | - | -100% |
| AS214351 | FEMOIT | 0 | 0 | 744 | - | -100% |
| AS216139 | IRONHOST | 0 | 0 | 8,797 | - | 0% |
| AS33993 | UFO-AS | 0 | 0 | 4,692 | - | 0% |
| AS213702 | QWINS-LTD | 0 | 0 | 7,681 | - | 0% |
| AS140666 | ADPL-AS-AP | 0 | 0 | 6,562 | - | 0% |
| AS206728 | MEDIALAND-AS | 0 | 0 | 15 | - | 0% |
| AS58854 | KAOPY | 0 | 0 | 614 | - | 0% |
| AS202685 | TR-ARKEL | 0 | 0 | 4 | - | 0% |
| AS394711 | KORGRID | 0 | 0 | 3 | - | 0% |
HOSTKEY-AS shows a large percentage on a base of 6 prior-week sessions, so treat that figure as churn, not growth.
Top ASN deep dives
AS51396 (PFCLOUD)
The proxy operation grew. Three hosts in 204.76.203.0/29 — .213, .221, and .222 — each logged more than 1,100 Honeylabs events. Every one presents an identical Censys profile: one open SSH port, OpenSSH 8.9p1, banner comment Ubuntu-3ubuntu0.17, Linux, Eygelshoven, Netherlands. Censys labels all three BULLETPROOF. Identical algorithm sets and banners across the /29 indicate cloned images.
The fleet’s purpose shows in its port list. Honeylabs saw sweeps across 1080, 1082, 1212, 1666, 3128, 8000, 8038, 8080, 8081, 8888, and more — all classic proxy or proxy-admin ports. Two events carried http://proxy.flarevpn.digital:8080/judge, a proxy-judge endpoint, with user agent Go-http-client/1.1. One certificate in the ASN names hosting12.coolsshservers.com. The picture fits a SOCKS and HTTP proxy network under active validation and rotation.
New certificates in the ASN include a Cloudbase-Init WinRM issuer and WIN-OU0SUKQBJN2, which puts Windows remote-management nodes inside a provider that presents as Linux SSH infrastructure.
AS138915 (KAOPU-HK)
Volume fell 24% but stayed high at 47,859 sessions. The 38.54.2.0/24 block did the work. Top talker 38.54.2.209 emitted 30,290 sessions, and 38.54.2.232 added 13,234. Destination ports tell the story: 80 and 443 lead, then 123 (NTP), 5355 (LLMNR), and 137 (NetBIOS name service). That mix matches Windows network-discovery scanning aimed at internal ranges, not internet service abuse.
Censys counts 12,308 visible hosts, down 1,246 from last week. A certificate issuer named tls.internal.ypc.org appeared this week. No Honeylabs events fired for this ASN, so the sensor view is the whole picture.
AS198953 (PROTON66)
One Windows box anchors this ASN: 176.120.22.61, Saint Petersburg. It produced 1,415 of 1,469 sensor sessions and 1,597 Honeylabs events. Censys shows RDP on 3389, WinRM on 5985, DCERPC on 135, and port 47001, with a BULLETPROOF label at 0.75 confidence.
Its scan pattern is a port sweep around MSSQL. Honeylabs recorded probes to 1431, 1433, 1440, 1441, 1444, and adjacent ports in the 1400 range, plus RDP and the targusdataspeed protocol label. Application protocols observed: http, rdp, mssql-tds, targusdataspeed. A second PROTON66 address, 193.143.1.66, logged 24 Honeylabs events and exposes zero ports to Censys. That host is a scan-only node.
New certificate issuers in the ASN include FASTPANEL and mail.the-slasher.com.
AS14956 (ROUTERHOSTING)
Sessions fell 85%, but the ASN’s 12 active Honeylabs sources show a Windows access fleet. Censys found RDP on 45.61.157.82, 144.172.108.79, and 144.172.99.200, with WinRM on 47001 and MSSQL 2008 (build 10.0.1600) on 144.172.108.79:1433. New issuers include AnyDesk Client and hostnames windows-Utah-4H, windows-Utah-2g, and windows-LasVega. Remote-access tooling on RDP boxes inside a bulletproof ASN suggests resale as access infrastructure.
The probes span legacy protocols: SMBv1, SMBv2, PPTP on 1723, SIP on 5061, and ports 8545 through 8549 from the sensor view. User agents include Python-urllib/3.13 and Python/3.13 aiohttp/3.13.5.
AS210644 (AEZA-AS)
Traffic collapsed, quality did not. 185.246.217.150 swept 37 distinct PHPUnit eval-stdin.php paths, among them /app/vendor, /apps/vendor, /public/vendor, /panel/vendor, /workspace/drupal/vendor, and /blog/vendor. It also tried the ThinkPHP invokefunction RCE twice, an LFI chain through pearcmd config-create, and /containers/json on Docker port 2375. Its user agent, libredtail-http, drove SSH probes with libssh2 1.11.1 handshakes. Censys shows a single SSH service, OpenSSH 10.2p1, and a BULLETPROOF label.
Infrastructure correlation
One HTTP fingerprint now spans three providers. JA4H ge11nn0400_9c3956fad5da appeared on source IPs in ROUTERHOSTING, PLI-AS, and PFCLOUD. TLS fingerprint t13i181000_85036bcba153_d41ae481755e appeared on both ROUTERHOSTING and RU-AEZA sources. Shared client stacks across provider boundaries point to one operator or one shared toolkit.
The PFCLOUD and AEZA fleets share an SSH baseline. Every enriched host in both ASNs negotiated the same algorithm set: curve25519-sha256@libssh.org, ecdsa-sha2-nistp256, aes128-ctr, hmac-sha2-256. The PFCLOUD trio runs OpenSSH 8.9p1 on Ubuntu with banner Ubuntu-3ubuntu0.17. The AEZA host runs OpenSSH 10.2p1 with Ubuntu-2ubuntu3.6. Default Ubuntu server configs produce this algorithm set, so the signal is weak on its own. The cloned /29 images carry the linkage.
PLI-AS (AS51852) now emits certificates from a Hydra Authentication RSA SubCA. HydraPanel is proxy-panel software. Its source 179.43.150.26 hit cPanel login paths (/login/?login_only=1, /openid_connect/cpanelid) and random suffix paths (/z1356, /s/1974, /.e199, /.env) on port 8443. A Proxmox Virtual Environment certificate also appeared in the ASN.
Fleet observations
Censys visible-host counts moved in two places. ADPL-AS-AP grew 3,757 hosts to 6,562, with a USDTCDN certificate issuer among its new issuers. KAOPU-HK shrank by 1,246 to 12,308. HOSTKEY-AS remains the largest fleet at 101,919 hosts, up 908.
HOSTKEY-AS port distribution: 22 (77,184), 443 (50,237), 80 (33,035), 2096 (14,781), 8443 (8,370). Port 2096 is the cPanel alternate HTTPS port. The ASN added hypervisor.hv and HARICA DV TLS RSA issuers this week.
Nine of ten enriched hosts carry the Censys BULLETPROOF label. The exception, 193.143.1.66 (PROTON66), exposes no services at all. KPRONET (AS214940) shows zero visible hosts across the entire ASN, yet its sources produced 59 sensor sessions on ports 80, 443, and 2525. Its fleet hides from scanners while it scans.
The FLOKINET host 185.100.87.136 carries a Censys TOR label and runs OpenSSH 9.9 on ports 80, 7288, and 9001. It beaconed GET /eventmanager with a Firefox Focus Android user agent, three hits in the sample window. This host appeared in prior weeks and rotated endpoints again.
IoCs and detection guidance
Watch these indicators. Full per-source data lives at the kevlar gist tree for 2026-09-07.
Hosts:
204.76.203.4,204.76.203.213,204.76.203.221,204.76.203.222— PFCLOUD proxy fleet, 1,100+ events each176.120.22.61— PROTON66 MSSQL and RDP sweep node185.246.217.150— AEZA RCE sweep host,libredtail-http179.43.150.26— PLI cPanel credential probing67.219.214.0/24— INVISIONTECH first-activity sweep range
Fingerprints:
- JA4H
ge11nn0400_9c3956fad5da— three ASNs, one toolkit - JA4
t13i181000_85036bcba153_d41ae481755e— ROUTERHOSTING and RU-AEZA - JA4
t12i210600_76e208dd3e22_f28add8e7af0— PROTON66 TLS 1.2 scanner
Paths and hosts to alert on:
vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.phpunder any prefixindex.php?s=/index/\think\app/invokefunction— ThinkPHP RCE probepearcmdwithconfig-createin the query string/containers/jsonon port 2375proxy.flarevpn.digital— proxy-judge infrastructure/eventmanagerfrom185.100.87.136
Detection guidance for the PFCLOUD pattern: alert when one source hits six or more distinct ports within 60 seconds. Cover the ranges 1080-1090, 3128, 8000-8081, and 8888. For the PROTON66 pattern: alert on scans that hit more than five ports in the 1430-1450 range.