knock-knock.net
A multinational bank, a US state, and a civilization teddy-bear shop each unwittingly joined the aforesaid phone-fraud botnet. Here's really to cheque whether 1 of your ain machines sewage caught successful the aforesaid honeypot.
August 5, 2026
On August 1st, Citigroup, the State of Idaho, and Build-A-Bear launched a coordinated attack connected me. They weren't alone. Lockheed Martin joined in, on pinch the Spanish National Police, the Los Angeles Superior Court, SoftBank, Argentina's authorities lipid company, a Swiss canton, a UK hedge fund, 2 universities, a hospital, and 3 further world banks. A partial database of these organizations is astatine the bottommost of this post.
Over the adjacent 27 hours, successful 4 chopped waves, each of them tried to usage my VoIP (SIP) server to spot telephone calls connected my dime. This is simply a scam called International Revenue Share Fraud (IRSF). The thought is simple: the attacker gets your telephone strategy to dial an world premium-rate number that they secretly own, and they pouch a trim of each minute. It's the telephone type of an unfastened message relay, and my server was being probed arsenic the unfastened relay.
Here's what makes "coordinated" much than a fig of speech. Every 1 of these networks tried to dial the aforesaid telephone number, and they spoofed the aforesaid mini group of clone caller IDs: the aforesaid fistful that surfaced, successful the aforesaid waves, connected servers I tally successful Los Angeles, New York, and Tokyo. Unrelated infected machines don't independently take the aforesaid disguises, target, and timing. These bots were each taking orders from the aforesaid place.
Obviously nary of this was sanctioned by Citigroup, Idaho, aliases Build-A-Bear. What almost surely happened is much mundane. An worker clicked a bad link, aliases brought an infected laptop onto the network, and a bot softly went to work. That bot is now sitting wrong a firm or authorities network, dialing retired to a fraud ring, and it presumably has entree to immoderate other is connected that network.
No harm was done to me. My SIP server is 1 of a group of honeypots that has now recorded over 11.5 cardinal protocol attacks, and it logs precisely what each attacker was trying to do. But if I were Citigroup, aliases the State of Idaho, aliases Build-A-Bear, I'd beryllium little concerned about showing up successful this dataset, and much concerned astir having a rogue instrumentality connected my network.
Check your ain network
The bully news is that it is trivial to find these rogue machines. Here is simply a free and easy API that lets you look up whether immoderate recorded attacks came from your network, providing unfastened access to immoderate of the honeypot's historical data. You tin cheque a full ASN, a group of CIDR ranges, aliases a azygous IP, pinch nary signup and nary API key.
The API is ungraded simple. You tin paste these into a browser, aliases curl them from the bid line:
https://api.knock-knock.net/check-asn?asn=<your web number> https://api.knock-knock.net/check-ranges?ranges=<your CIDRs> https://api.knock-knock.net/ip/<your IP address>Here's what came backmost erstwhile I checked Build-A-Bear's web (ASN 21811):
curl 'https://api.knock-knock.net/check-asn?asn=21811' { "list": "year", "generated_at": "2026-08-05T05:00:00Z", "asn": 21811, "isp": "Build-A-Bear Workshop, Inc.", "hit_count": 1, "total_matched": 1, "truncated": false, "hits": [ { "ip": "104.238.197.106", "hits": 11, "first_seen": "2026-08-01 21:44:56", "last_seen": "2026-08-03 06:01:49", "protocols": [ { "proto": "SIP", "hits": 11, "last_seen": "2026-08-03 06:01:49" } ] } ] }The consequence lists 1 IP, caught eleven times probing for SIP toll fraud. If that were your ASN, this is the instrumentality to find and isolate. This communicative is astir SIP, but the honeypot watches galore protocols, truthful the aforesaid telephone would study attacks via SSH, RDP, SMB, HTTP, and more.
I would dream that the Citigroup and Lockheed Martin information teams would drawback this benignant of point earlier a bot ever reaches extracurricular their walls. However, they did not, and moving a cheque for illustration this each day is inexpensive insurance. A rogue instrumentality that tin scope my server tin besides scope the remainder of your network, and that is the portion that should really interest you.
- More connected the API:api.knock-knock.net
- The honeypot itself:knock-knock.net
- The codification (MIT license):github.com/djkurlander/knock-knock
All portion of the attack
| Lockheed Martin Corporation | 6075 | Defense contractor |
| Citigroup Inc. | 1696 | Global bank |
| Build-A-Bear Workshop | 21811 | Toy retailer |
| Direccion General de la Guardia Civil | 212377 | Spanish nationalist police |
| State of Idaho | 54885 | US authorities government |
| State of Nebraska / Office of the CIO | 2769 | US authorities government |
| City and County of Denver | 18815 | US metropolis government |
| Los Angeles Superior Court of California | 33015 | US tribunal system |
| Etat du Valais | 214217 | Swiss cantonal government |
| YPF S.A. | 27655 | Argentine authorities lipid company |
| Kalpataru Power | 140154 | Indian powerfulness infrastructure |
| SoftBank Corp. | 17676 | Japanese conglomerate |
| LG CNS | 4668 | South Korean IT services |
| Marshall Wace Asset Management | 203818 | UK hedge fund |
| American University of Beirut | 12812 | University |
| The New School | 27616 | US assemblage (NYC) |
| Jisc Services | 786 | UK education/research backbone |
| Madison Co Memorial Hospital | 394139 | US hospital |
| Turkiye Garanti Bankasi | 12903 | Turkish bank |
| Cairo Amman Bank | 48701 | Jordanian bank |
| CSCBank SAL | 34370 | Lebanese bank |
English (US) ·
Indonesian (ID) ·