Unrecognized DNS on a phone tether — Catch-all is still a truck anyone can load

Quantitative Security · @unccno

The sensor was a hardened laptop on a phone tether. The suite is QS-NetHarden: NetCloak to look like a new Windows box (fresh hostname, randomized hardware address, DHCP hostname quieted), Artillery decoys in front of the host firewall (banner-only; ban off — fake FTP, Telnet, RPC, MySQL, NTP), PhantomQS cycling real Firefox builds as attractors, and a local packet capture already running on the Wi-Fi interface.

Capture starts 09:08:20 PDT on 26 August. About a minute later Cloak finishes the costume. The phone’s access point and its resolver see what any LAN watcher sees: a new L2 identity and a short hostname that does not exist on the public internet. That hostname is queried for A and AAAA tens of times and comes back NXDOMAIN. It is the box’s own name, not a command channel.

From that new lease the same host asks for github.com, then api.github.com. At 09:12:04 it asks for release-assets.githubusercontent.com — the seed name for this case — and lands on GitHub’s Fastly content anycast. Phantom’s Firefox 128 cycle starts 09:14:03 and pulls Mozilla settings in the same breath as more NXDOMAIN for the local hostname.

Nothing in the honeypot log that morning is a remote hit. Artillery records allow-listed probes from the box itself. The decoys were up; nobody walked them in this file.

DNS volume in the capture matches the operator sitting on the tether, not an implant picking leaves: the chat proxy first, then GitHub’s GLB, Actions front door, Copilot, tool cache, user-images, viewscreen, pipeline listener, and only then release-assets as a first-class name. Low-count junk labels under the same parent zone arrive later, when enum starts. That is the tell.

How the traffic was caught: the sniffer was already on the interface when identity changed. The only party that “saw a new device” is the phone AP — and anyone who had been watching that hotspot. What they would have seen is a Windows-story laptop joining, then talking to GitHub like a developer workstation, then talking to GitHub like a recon suite.


Public IOC compare for the seed host and its neighbors. The leaf and the Fastly .133 catch-all are GitHub’s truck — URLhaus and CI/EDR feeds have burned the name; vendors already walked host-level blocks back. Campaign C2 is the off-CDN hop, not the VIP. Observer addresses on the tether are sensor, not indicators.

The /22 185.199.108.0–185.199.111.255 is RIPE US-GITHUB-20170413, org GitHub, Inc., abuse abuse@github.com, created 13 April 2017. BGP origin is AS54113 Fastly. Owner and announcer are different facts. Fastly’s published public-ip-list is Fastly-owned space and does not include this prefix. Treat it as GitHub addresses carried by Fastly.

Two anycast sets live inside that /22:

  • .133 — content catch-all: release-assets, raw, camo, avatars*, user-images*, media, objects, cloud, desktop, favicons, gist, marketplace images.

  • .154 — releases and packages: github-releases, github-cloud, github-registry-files, pkg-containers, pkg-npm, pkg.actions. Three apps on one VIP if you vhost them.

GitHub GLB in 140.82.112.0/20 holds token.actions, objects-origin, viewscreen. Microsoft anycast 13.107.42.0/24 and 13.107.43.0/24 is the Actions front door — T1’s live A for pipelines.actions was 13.107.43.16. Azure 20.x Kestrel rows (pipelinesghub*, runnerghub*) are regional snapshots. GitHub documents *.actions.githubusercontent.com and says CNAMEs change. Meta actions CIDRs are hosted-runner egress, the opposite direction from these listeners.

Copilot’s allowlist names copilot-proxy.githubusercontent.com (probe /_ping, not /). One Azure PoP in a single pass is not a singleton.

T1 HTTP on / was empty product, not a panel: Fastly Error 54113 (Fastly’s ASN), Kubernetes 404/19 B, Actions 404 with x-tfs-* / x-msedge-ref, OIDC at /.well-known/openid-configuration.

Public intel will burn the truck

release-assets.githubusercontent.com is a real GitHub leaf (permanent feature flag, 2025). It is also where people stash second-stage files. URLhaus has malware URLs on the host. Harden-Runner flagged it until GitHub said product change. .

Catch-all Fastly can be used. Shared VIP, signed path, wildcard already allowlisted. The hostname is the truck. The actor is the cargo plus the next hop that is not GitHub.

Block the follow-on VPS. Do not block .133, the leaf alone, AFD anycast, Kestrel snapshots, or the sensor.

Close

The morning is two pictures of the same host. First the costume change on the tether — new name, new layer-2 face, NXDOMAIN for a hostname that only the phone resolver will ever see — then a developer-shaped walk onto GitHub, then the operator turning around and mapping every leaf that walk had touched. A watcher on that access point saw a new Windows-story box. What they did not see is a second laptop or a Fastly panel. The catch-all answered because that is what it is built to do: one VIP, many names, signed cargo optional. Public intel that stops at the hostname will keep burning the truck. The work that remains is the same as it was: name the cargo, name the next hop that is not GitHub, and leave the sensor off the list.

Appendix

These are GitHub and Microsoft product edges. They are not a blocklist. Regional 20.x rows are snapshots; GitHub documents the names, not frozen IPs.

DNS (content, .githubusercontent.com unless noted): release-assets raw camo gist avatars avatars0–avatars3 user-images private-user-images secured-user-images private-avatars media objects cloud desktop favicons repository-images marketplace-images marketplace-screenshots octocat-generator-assets apps.workspaces github-releases github-cloud github-registry-files github-repository-files pkg-containers pkg-npm objects-origin viewscreen notebooks render alambic-origin patch-diff copilot-proxy copilot-telemetry copilot-telemetry-service.

DNS (Actions): token.actions.githubusercontent.com, pipelines.actions.githubusercontent.com, setup-tools.actions.githubusercontent.com, pkg.actions.githubusercontent.com, oidc-configuration.audit-log.githubusercontent.com, acghubeus0 acghubeus1 acghubeus2 acproxneu1 acproxwus31 mmsghubcswe1 mmsghubcus2 mmsghubcus3 mmsghubeus1 mmsghubeus2 mmsghubeus3 mmsghubeus4 mmsghubeus20 mmsghubeus23 mmsghubseau1 mmsghubweu1 mmsghadowus21 pipelinesghubeus2 pipelinesghubeus3 pipelinesghubeus4 pipelinesghubeus5 pipelinesghubeus10 pipelinesghubeus11 pipelinesghubeus21 pipelinesghubeus22 pipelinesghubeus24 runnerghubeus20 runnerghubeus21 runnerghubwus31 runnerproxweu1. Front-door CNAME: star-actions-githubusercontent-com.l-0007.l-msedge.net, GLB: glb-db52c2cf8be544.github.com. Also on the wire before recon: github.com, api.github.com.

IPs / prefixes: catch-all content 185.199.108.133 185.199.109.133 185.199.110.133 185.199.111.133 in 185.199.108.0/22 (GitHub on Fastly AS54113). Releases/packages 185.199.108.154 185.199.109.154 185.199.110.154 185.199.111.154. GLB 140.82.112.22 140.82.113.21 140.82.116.13 in 140.82.112.0/20. Actions AFD 13.107.43.16 in 13.107.42.0/24–13.107.43.0/24. Tool cache 150.171.109.145. Copilot proxy 138.91.182.224. Regional Kestrel: 20.102.38.122 20.237.33.78 20.242.161.191 20.22.166.15 20.10.226.54 20.96.133.71 20.102.36.236 20.232.252.48 20.253.95.3 20.75.4.210 20.65.21.88 20.14.42.190 20.31.193.160. SWA stub 20.80.156.48. patch-diff followed github.com to 172.182.252.133.


Previous
Previous

Policy Plug snowshoe mill-follow up

Next
Next

From Local Capture to Structured Protective Intelligence