Mastodon
Go back

Bulletproof Hosting Watch: Week of 2026-09-14

Executive summary

Two events define the week of 2026-09-07 to 2026-09-14. A PFCLOUD host pulled IoT botnet payloads from a decoy endpoint 854 times. A single FLOKINET host SYN-scanned one port across five honeypot sensors roughly 20,000 times. Those two hosts account for 26,191 of the 36,243 measured sessions.

The tracked set produced 36,243 sensor sessions and 15,012 tagged honeypot events. Three ASNs hit the 10,000-session aggregation cap: KAOPU-HK, PFCLOUD, and FLOKINET. The single PFCLOUD host 204.76.203.4 hit it as well. Every monitored ASN except KPRONET carries the Censys BULLETPROOF label on at least one host.

Infrastructure moved in three places. THE (AS209847) lost 83% of its Censys-visible fleet and its distinctive high-port cluster disappeared. PLI-AS (AS51852) rotated its Hydra Authentication RSA SubCA serial and grew certificate issuance by 894. HOSTKEY-AS (AS57043) added 531 visible hosts and shifted its sensor profile from HTTP to Telnet, SSH, and FTP.

By the numbers

Source IPs counts distinct source addresses in each ASN’s top-20 aggregation for 2026-09-07 to 2026-09-14. Honeylabs events are per-ASN totals from asn_enrich. Censys hosts are visible host counts. Change compares matched 7-day windows.

ASNProviderSource IPsHoneylabs eventsCensys hostsTop portChange
AS138915KAOPU-HK20012,58480 (HTTP)0%
AS51396PFCLOUD2011,4002,39280 (HTTP)0%
AS200651FLOKINET3123,9968091+13,058%
AS198953PROTON6682,763358443 (HTTPS)+42%
AS57043HOSTKEY-AS82102,45023 (Telnet)+605%
AS51852PLI-AS91328,6493000+1,131%
AS14956ROUTERHOSTING2063425,85422 (SSH)+185%
AS200593PROSPERO-AS38334443 (HTTPS)1 to 326
AS210644AEZA-AS10072,012445 (SMB)+106%
AS214940KPRONET20008022+80%
AS400992ZHOUYISAT148,051443 (HTTPS)-59%
AS209847THE30255445 (SMB)+1,933%
AS216246RU-AEZA-AS106,87462641new
AS30823AUROLOGIC122,1763389 (RDP)-50%
AS211720Datashield05550--100%
AS216309INVISIONTECH0038--100%
AS216139IRONHOST009,251-0%
AS33993UFO-AS004,726-0%
AS213702QWINS-LTD007,615-0%
AS140666ADPL-AS-AP006,870-0%
AS214351FEMOIT00760-0%
AS206728MEDIALAND-AS0012-0%
AS58854KAOPY00589-0%
AS202685TR-ARKEL004-0%
AS394711KORGRID003-0%

THE’s +1,933% sits on a base of 3 prior-week sessions. HOSTKEY’s +605% sits on a base of 196. Treat both as churn against small denominators.

Measurement notes

Three limits apply to this week’s comparisons.

The Arkime aggregations cap totals at 10,000. KAOPU-HK, PFCLOUD, and FLOKINET report capped values, so their session counts are floors, not measurements.

Source-IP diffs use top-20 aggregations per ASN. An address outside the top 20 in either window does not appear in the diff.

The leading KAOPU-HK source, 38.54.2.209 is host background noise: captive-portal checks on port 80, NTP on 123, and SSDP on 1900. Read the KAOPU-HK session total as decoy-host noise, not as adversary scanning.

Top ASN deep dives

AS51396 (PFCLOUD)

PFCLOUD produced 11,400 honeypot events from 54 addresses, up from 7,883 last week. The busiest host is 204.76.203.18. It opened 6,299 sessions on port 80 in one week and sent no User-Agent on any of them. Every request went to 38.54.2.209 or 130.94.89.46.

The request paths name IoT botnet payloads across 16 CPU architectures. The observed set includes morte.sh4, morte.arc, morte.m68k, morte.x86_64, and siblings, plus the same architecture set under nwfaiehg4ewijfgriehgirehaughrarg.*. Other paths include /bns/gang123isgodloluaintgettingthesebinslikedammwtf.arm, /HBTs/top1miku.powerpc-440fp, /LjEZs/uYtea.sh4, /klogd, /arm4, and /csky. The host walks the candidate payload URLs, one architecture after another, and stops when one returns a body.

Four source addresses made 992 payload requests in total. 204.76.203.18 made 854. Three others — 23.234.116.20 and 23.234.119.20 in AS11878, and 169.150.201.16 in AS212238 — made 46 each against 209.141.62.110.

The proxy fleet from prior weeks is still present. 204.76.203.213, .214, .221, and .222 run OpenSSH 8.9p1 with banner hash 75d49f84. Each serves an authenticated HTTP proxy on port 81 and returns 407 Proxy Authentication Required. Two more PFCLOUD addresses, 45.135.193.193 and 176.65.134.48, run OpenSSH 9.6p1 on Ubuntu 24.04 from a newer image. 45.135.193.193 scans the proxy-port set, and 176.65.134.48 scans 8097 through 8099.

AS200651 (FLOKINET)

FLOKINET went from 76 sessions to the 10,000 cap. One host caused it. 185.165.170.59 produced 19,892 sessions, 16,905 of them to port 8091 across five decoy endpoints in Germany, Singapore, the United States, Finland, and Bahrain.

Every sampled session carries zero bytes in both directions, so the remote side never answered. The pattern is a SYN probe of a single port at roughly 100 attempts per hour, sustained for the full window. It is the largest single-port scan against the sensor fleet this week.

Censys sees 185.165.170.59 as a Linux web host: nginx on 80 and 443, OpenSSH 9.6p1 on 22, and an unidentified binary service on 8090. Prior weeks showed a different FLOKINET address, the Tor exit 185.100.87.136, and that host produced only 27 sessions this week.

AS14956 (ROUTERHOSTING)

Sessions rose from 277 to 790, and honeypot events rose from 95 to 634. The headline finding is 216.126.225.6, which ran 30 sessions tagged ssh-reverse-shell against 209.141.62.110:22 between 2026-09-11T23:25 and 2026-09-13T13:54 UTC.

Arkime recorded the client fingerprint on those sessions: HASSH f555226df1963d1d3c09daf865abdc9a and JA4SSH c36s36_c13s17_c5s11. The client advertised SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.5. Suricata raised GPL ATTACK SSH Brute Force Attempt on the same flows. Honeylabs holds no record of this address, so the sensor view is the only evidence of the reverse shell activity.

The rest of the ASN serves a mixed fleet. 107.189.16.180 resolves to 180.16.189.107.static.cloudzy.com and shares the OpenSSH 8.9p1 Ubuntu-3ubuntu0.17 banner hash with the PFCLOUD proxy nodes. Ports 8545 through 8549 each took 21 sessions this week. Censys counts 7,521 RDP hosts against 15,751 SSH hosts, so remote desktop forms a large part of the platform.

AS198953 (PROTON66)

Honeylabs events rose from 1,669 to 2,763, and 2,622 of them came from 176.120.22.61. Censys shows a Windows host with RDP on 3389, WinRM on 5985 and 47001, DCERPC on 135, and NetBIOS on 137 and 139. The BULLETPROOF label sits at 0.75 confidence.

Sponge recorded 1,879 sessions from this address across 255 destination ports. No port took more than 12 sessions, and the lowest took 3. The targets spread across the full range, with clusters near 111, 1112, 1234, 1500, and the 2000s. Censys counts 164 RDP hosts and 163 SSH hosts across the ASN, so the platform skews toward remote desktop rather than web hosting.

AS51852 (PLI-AS)

Sessions rose from 97 to 1,194 and honeypot events from 32 to 132. The volume comes from proxy hunting. 179.43.134.114 logged 829 sessions across ports 999, 1080, 1081, 1111, 3125, 3128, and 5678, and it resolves to hostedby.privatelayer.com. 31.7.59.130 added 300 sessions.

The certificate profile changed more than the traffic did. PLI rotated from Hydra Authentication RSA SubCA #154 to #155, and issuance on the new serial jumped from 894 to 984. HydraPanel is proxy-panel software, so a serial rotation with rising counts marks an expanding panel deployment rather than routine renewal. Censys counts 4,327 HTTPS hosts and 4,085 SSH hosts in the ASN.

Infrastructure correlation

One SSH image spans three providers. The banner hash 75d49f84712e2426329e23d0aeccb5d8ef06fc439a357b916432d6502dc709ba appears on six hosts: the PFCLOUD /29 members, 204.76.203.49, 107.189.16.180 in ROUTERHOSTING, and 179.43.134.114 in PLI-AS. The same hash implies the same base image.

The PFCLOUD /29 adds a second signal. All four nodes return JA4T 65535_2-4-8-1-3_1460_9_1 on both port 22 and port 81. A TCP stack fingerprint that matches across two services on four addresses indicates a cloned deployment, not four configured hosts.

A newer generation sits beside the old one. 204.76.203.4, 45.135.193.193 in PFCLOUD and 107.189.16.180 in ROUTERHOSTING run OpenSSH 9.6p1 on Ubuntu 24.04 with JA4T 65160_2-4-8-1-3_1460_7_1-2-4-8-16. The operator rebuilt on a current Ubuntu LTS while the old 22.04 nodes kept running.

Sources from four ASNs converge on one destination set. 185.165.170.59 (FLOKINET), 204.76.203.4 (PFCLOUD), 185.203.4.221 (THE), and 179.43.134.114 (PLI) all hit 159.195.21.150, 217.15.163.226, 89.167.72.144, and 209.141.62.110. Those four destinations are decoy endpoints in Germany, Singapore, Finland, and the United States. A shared target list across unrelated providers points to shared tooling or a shared operator.

Fifteen of fifteen individually enriched hosts carry the BULLETPROOF label. That includes 185.231.33.46 in Datashield, a host Censys cannot otherwise profile.

Fleet observations

Five ASNs added more than 200 visible hosts each. HOSTKEY-AS grew 531 to 102,450, IRONHOST 454 to 9,251, ADPL-AS-AP 308 to 6,870, KAOPU-HK 276 to 12,584, and ROUTERHOSTING 222 to 25,854. KAOPY fell 25 to 589.

THE is the outlier. Its visible fleet fell from 1,458 hosts to 255, and every software family fell with it. aiohttp dropped from 1,112 to 16, and python from 1,126 to 18. openssh fell from 1,116 to 199, and nginx from 670 to 191. Its distinctive port cluster also vanished. Last week the ASN served 370 hosts each on ports 1030, 1050, 24442, 1234, and 1235. This week those ports do not appear. The fleet lost a uniform port signature and 83% of its hosts in one scan interval.

HOSTKEY-AS changed what its hosts do. Last week a single address, 82.38.67.164, drove 162 of 196 sessions on port 80. This week eight addresses share 1,382 sessions, and the top ports are 23 (Telnet), 22 (SSH), and 21 (FTP) — 341, 338, and 333 sessions. The ASN’s Censys port profile stays dominated by SSH on 77,268 hosts, but the sensor view says the active nodes now probe credential services. New ports in the ASN include 21, 23, 123, 3306, and a long tail of high ports.

KPRONET does not appear in Censys at all. It has zero visible hosts, yet 20 of its addresses generated 106 sessions on ports 8022, 443, and high ports. The fleet scans and stays out of the index.

IoCs and detection guidance

Full per-source data lives at the kevlar gist tree for 2026-09-14.

Hosts:

Fingerprints:

Paths and hosts to alert on:

Detection guidance. For the PFCLOUD pattern, alert when one source requests more than five distinct /0010101010* paths within an hour, or more than five distinct morte variants. Flag any HTTP session with an empty User-Agent that requests a file with an architecture suffix. For the FLOKINET pattern, alert on a single source that opens more than 50 half-open TCP sessions to one port across three or more destinations in an hour. For the reverse-shell pattern, alert on HASSH f555226df1963d1d3c09daf865abdc9a against any SSH service in the monitored set.



Previous Post
PQProbe Vendor Analysis: Where 100 Cybersecurity Vendors Actually Stand on Post-Quantum TLS
Next Post
What 100 cybersecurity vendors do about TLS and DNS: post-quantum 👍🏼, DNSSEC 🔴