DROP Nets, One Blind /32, and a WAN UniFi
Executive summary
Two short AT&T Lightspeed firewall windows — 26 minutes on 29 Aug and 19 minutes on 5 Sep — produced 530 unique events and 270 inbound public IPs. The first article already covered census scanners, CHINANET, and the named commercial lookers. This piece is only what was left: 105 dump IPs.
Seventy-four of 108 checked addresses hit a public feed on 5 Sep. None hit Feodo, SSLBL, ThreatFox, or Emerging Threats. This is not a named botnet C2 on the gateway.
This is not a second pass over the same story. The 5 Sep article already took T3/T5, CHINANET, Censys, Hydra, Modat, Xpanse, Recyber, CriminalIP. What follows is only the remainder: 105 dump-source inbound IPs, plus a small amount of org-infra glue and A-record extras pulled so those names could be interpreted.
What remains is narrower and worse:
21 IPs sit in Spamhaus DROP prefixes (list dated 4 Sep), including Pfcloud 176.65.148.0/22 — the same net that launched the June UniFi-OS exploits now on CISA KEV. Ghosty and Stormcloud /24s on that list are also URLhaus Mirai neighborhoods. Block the nets, not souvenir /32s.
QNAX 45.140.193.187 was the loudest remaining inbound (10 hits, 29 Aug). AbuseIPDB 412/100%, last seen 1 Sep on port 5000. Not in DROP, IPsum, or CINS the day we pulled feeds. Sales site is Cloudflare; the scanner is the /32.
Tamatiya / 4vendeta scanning VPS /24s are mass-reported. 4vendeta.com, Here-Host, and Roundcube info.php are the storefront. Do not mix them.
46.146.238.1 is an exact URLhaus host: :25306/bin.sh and :25306/i, telnet 23 open. One dropper, not a C2 overlay.
UniFi OS on 195.252.206.160:443 (WAN, cert ≠ IP) had no IP-feed hit. It is a service-class match to SAB-067 CVE-2026-77550 (CVSS 10) and to the Pfcloud campaign that already used a net in this dump.
Two clocks. Do not merge them into one spray.
Catch-all page: many HTTP-open hosts connect-fail or empty-reply from the runner. An identical 712-byte HTML blob, md5 d20b048101bf73818af37d6ab12fd134, landed on unrelated nets (16.5.0.254, 45.42.88.54, 45.155.90.234:80 and :5000, 45.156.87.127, 46.146.238.1, 176.65.149.233:3000, 198.46.134.48:80, 85.11.167.185:8888). That page is a sink/honeypot, not a unique implant.
PTR names ip-*.4vendeta.com, tfk162.templeforknowledge.com, get174.ingetitin.com, regular-t1ching.hillgent.com, ip-58-90.superbit.host have no A (FCrDNS fail).
Public feed check: 108 addresses (105 remaining + 3 Fibernet glue). 74 hit at least one local feed. Feodo C2, SSLBL, ThreatFox, Emerging Threats: 0.
Spamhaus DROP — 21 dump IPs, treat as nets
Pfcloud is the campaign neighborhood, not just a list row. Cybernews 25 Jun 2026: UniFi OS exploits launched from 176.65.148.183, same DROP /22 as dump .233. CISA put CVE-2026-34908 / 34909 / 34910 on KEV 23 Jun (SAB-064 chain, Mirai-class loader). SAB-067 (26 Aug) added CVE-2026-77550 UniFi OS unauth CRLF bypass, CVSS 10, plus Protect and Talk command injection. Neighbors on the /22 are mass-reported (.253 /.env spray; .254 4k–5k). Block the prefix.
URLhaus on the same DROP nets, not on the dump /32s. Ghosty siblings 43.228.157.{47,73,102,130} host jah.arm* / w.sh. Stormcloud 94.154.43.0/24 is a Mirai loader farm (~2,022 URLs / ~82 hosts: miron.*, persist.arm7) — same net as dump .7 / .140. That is why you block the /24, not because .7 served bin.sh to this gateway.
QNAX 45.140.193.187 AS268581 — hostile /32, zero
Loudest remaining inbound:
AbuseIPDB: 412 reports, 100%, 171 sources. First 27 Feb 2026. Last 1 Sep: unauthorized on port 5000, port scan, brute-force.
ISP QNAX LTDA, São Paulo. Domain qnax.sh. Abuse abuse@qnax.com.br.
Same /24 VPN PTRs: revhuntervpn.com, sockslite.com.
Tamatiya / 4vendeta AS50360 — scanners vs storefront vs glue
Dump SSH VPS: 22/tcp open except 79.124.59.78 closed. /24s .58 .49 .114 are port-scan factories. FCrDNS on the pretty PTRs fails.
Siblings not in the dump: 79.124.58.254 still scanning; 79.124.59.254 reported 4 Sep as RD-Web/RDP brute (UniFi-FW reporters). 79.124.59.78 dump host, 22 closed.
Storefront:
https://4vendeta.com — LiteSpeed, PHP 7.3.27 (EOL), Laravel.
https://here-host.com — “Live Infrastructure Catalog.”
https://mail.here-host.com (195.230.24.20) — Apache 2.4.10 Debian, Roundcube, Content-Language: bg. Cert name ≠ IP.
Glue, not dump sources:
195.230.25.175:53
195.230.24.14 filtered
templeforknowledge.com / ingetitin.com / hillgent.com / superbit.host / fibernet.bg
Exact malware URL — 46.146.238.1 ER-Telecom Perm
The only remaining dump IP that is an exact URLhaus host.
http://46.146.238.1:25306/i
nmap: 23/telnet + 80/http (80 is the 712-byte catch-all from this runner) Class: compromised CPE / IoT loader (classic bin.sh on a high port).
UniFi OS — service-class match, no /32 feed hit
195.252.206.160:443 Metronet, WAN, cert ≠ IP, nginx, noindex. Pulse/nmap saw UniFi OS.
Public context that does apply:
SAB-067 (26 Aug 2026): CVE-2026-77550 UniFi OS unauth CRLF authentication bypass, CVSS 10; plus Protect CVE-2026-77537 and Talk CVE-2026-77554 (unauth command injection). ~100k internet-reachable UniFi OS instances in the prior wave’s reporting.
SAB-064 chain already KEV (23 Jun). Observed June exploitation from Pfcloud 176.65.148.183, same DROP /22 as dump 176.65.149.233.
This box is in that exposure class. It is the one service on the remainder list that lines up with a live exploit campaign using a net that already hit this gateway. Pull WAN UI / remote access. Patch UniFi OS and apps. Assume logs can lie after a successful unauth-root chain.
EMBNEX 16.5.0.0/24 — eight dump origins, website is CloudFront
Dump PTRs all embnex.com: .236 .238 .239 .240 .242 .244 .245 .254. 22 open on the set; .254 also 80 (712-byte catch-all). .254 is IPsum + CINS + blocklist.de. Several other /24 hosts on CINS/IPsum. 16.5.0.236 reported ~16h before the feed pull as a web-app attack (empty request).embnex.com itself is CloudFront/CF.
Cloud /32s that feeds like and census
AWS: 98.90.43.197 AbuseIPDB 16,395 / 100%, persistent scan; nmap 22, 80, 9100; reported ~45 min before one of the HTML pulls on port 1025. Other dump AWS on CINS/IPsum: 13.219.1.233, 98.89.204.118, 98.90.43.197, 100.28.191.174, 100.51.6.16. Visionheight extra 18.116.101.220.
IPsum L3: Alibaba 8.219.76.182, 47.245.96.96, 47.245.128.247, 47.254.131.109; AWS as above; Shodan 66.240.192.138; IPIP 103.203.57.28; 198.46.134.48 (
srv1.electionserver.org — apex NX; nmap 21/80/443/587/3306; 80 is 712-byte).
Alibaba open proxy: 47.254.22.110 — 22 + 1080/socks. IPsum on siblings. Open-proxy class.
45.155.90.234: ftp/ssh/80/5000/8443; CINS; canned 712-byte HTML on 80 and 5000.
Payara: 157.230.180.149:8080 default splash Payara 5.2022.5 + ftp/ssh/mysql. DigitalOcean neighborhood noisy; this /32 not in local DROP. Exposed app server, not a named C2.
alexaust.in / 66.175.223.24: Apache 2.4.18 / OpenSSL 1.0.2n (2013–14).
118.24.129.122: nginx HTTP 200 of a 404 body; :443 HSTS; :8080 catch-all.
GCP v6 both days (Other DoS): 2600:1900:4090:356b:0:138:: and 2600:1901:0:4ba4:: — 443/80 → HTTP 404. Keep in remaining; not T5.
Named census:
visionheight AWS fleet (dump + 23 extras, all PTR scan.visionheight.com, nmap filtered, HTTPS timeout). Stretchoid Azure (8 IPs host-up, 200 ports filtered). Shodan 66.240.192.138 22+111. Shadowserver 65.49.1.239 + v6 lighttpd/1.4.74 :80. IPIP 103.203.57.28. BinaryEdge 173.255.192.58. form.securityresearch.net filtered / NX from runner. CINS listing them is their scanning. Host-up is expected.
Both-window addresses still in remaining
43.228.157.9 (Ghosty DROP, :53) · 78.128.114.162 (Tamatiya, 22, multi-k AbuseIPDB) · 80.94.95.226 (SS-Net DROP, filtered) · 193.46.255.72 (Unmanaged DROP, 22) · 2600:1900:4090:356b:0:138:: · 2600:1901:0:4ba4::.
Same source, two dumps a week apart. Still not a reason to merge the clocks into one “campaign.” It is persistence of the same dirty neighborhoods plus two GCP v6 probes.
Controls
DROP prefixes — Pfcloud 176.65.148.0/22 (and .149.0/24 if your copy lists it), Ghosty 43.228.157.0/24, SS-Net 80.94.92.0/22, Stormcloud 94.154.43.0/24, TechTies 45.156.87.0/24, Unmanaged 193.46.255.0/24 + 92.118.39.0/24, plus the other DROP rows in §1. Covers 21 dump IPs, the June UniFi loader net, and the Stormcloud/Ghosty URLhaus farms.
45.140.193.187/32 QNAX — no feed net; current; loudest remainder inbound.
Tamatiya VPS /24s .58 .49 .114. Never the CF storefronts, never Fibernet NS.
46.146.238.1/32 + the two :25306 URLs.
195.252.206.160:443 UniFi OS — take off WAN; patch SAB-067; do not wait for an IP feed.
EMBNEX origin 16.5.0.0/24. Not embnex.com.
Census, CF edges, CHINANET /12, 4vendeta HTTPS, Here-Host, Roundcube info.php (ticket as an ops leak, not an inbound IOC)