Post #4356621
2026-08-03 11:26 UTC
Bulletproof Hosting Watch, Week of 2026-08-02 is up, using data from @HoneyLabs@infosec.exchange, @censys@infosec.exchange & my fleet.
Full report w/IoCs: https://ai.rud.is/posts/2026-08-02-weekly-bulletproof-report
PLI-AS ran 4 ⚔️ from Swiss servers (Panama shell): DCE/RPC, RDP brute-force, tRPC setup, WordPress login.
KPRONET scanned .env & .git files w/20+ fake browser profiles. TLS fingerprint stayed fixed across rotations.
FLOKINET 185.100.87.136 is a Tor exit relay that brute-forces SSH and Telnet.
1/2
Replies (0)
No replies.