We Told Water Operators to Check Port 44818. We Never Ran That Check Against the Attacker List. It's There.
- Patrick Duggan
- 15 minutes ago
- 5 min read
On 25 July we wrote about CISA's update to joint advisory AA26-097A. We gave water operators a specific instruction: the ports to check tonight are 44818, 2222, 102 and 502 on the controllers, and 22 on the modems.
44818 was first on that list. It is the Allen-Bradley / Rockwell EtherNet/IP port, and the reason it led is that the advisory describes Iranian-affiliated actors reaching internet-exposed programmable logic controllers.
We ran that check against thousands of hypothetical controllers and never once ran it against the advisory's own indicator list.
We ran it today. One of the twenty-one addresses CISA published as attacker infrastructure is itself answering on 44818, and it identifies itself as Rockwell.
What is on the box
[141.11.164.153](https://analytics.dugganusa.com/stix/register?ref=ioc-click&q=141.11.164.153). AS212238, Vantiva SA, ISP Datacamp Limited, Switzerland. Shodan has it tagged `ics` and `database` — a commodity scanner classified this thing as an industrial control asset without anyone asking it to.
The details that matter:
Port 44818 returns a CIP identity object naming Vendor ID: Rockwell Software, Inc., product WIN-BB892MB2CEH, serial 0x02b9089d. Note Software, not a hardware vendor ID — this is Rockwell's software EtherNet/IP stack answering, the kind a configuration or gateway product presents, not a physical Allen-Bradley controller.
Port 8090 runs Apache and sets a sess_lmgrd cookie. lmgrd is the FlexNet licence daemon. Port 5093 is Sentinel LM, a second industrial licensing service. You run those when you are running licensed commercial engineering software and want it to keep working.
Port 49884 is MS-SQL 2014, and its NTLM response leaks the host: Windows Server 2022, build 10.0.20348, machine name WIN-BB892MB2CEH. RDP, WinRM, SMB and RPC are all exposed to the internet alongside it.
Put together: a licensed Rockwell engineering environment on a Windows server, reachable from anywhere, on an address a six-agency advisory says was used to attack water utilities.
Why that lands where it does
Go back to what the same advisory actually says the actors did. Quoting the July update: at one US victim, the actors downloaded a malicious project file to a targeted PLC using legitimate configuration software. The file kept the working ladder logic intact and added logic overriding the instructions that enforce safe operating limits.
Legitimate configuration software. That is Rockwell's own tooling, licensed and working, being used the way it was designed to be used, against a controller that answered.
We are not going to tell you this specific box is the one that pushed that file. We have no evidence of that, nobody has published any, and asserting it would be exactly the kind of confident leap we spent this week arguing against. What we can say is that an address on the advisory's indicator list is running the category of software the advisory describes the actors using, and that nobody appears to have said so.
Two readings, and we cannot separate them
It is an operator lab. Somebody licensed Rockwell software, stood it up on a rented Windows server, and used it to build and test PLC attacks — a bench where you develop a malicious project file against a stack that behaves like the real thing. The hosting favours this: Datacamp is commercial infrastructure, no water plant runs there, and WIN-BB892MB2CEH is a default auto-generated Windows name rather than something an asset register produced.
It is a compromised engineering host. A real Rockwell workstation belonging to somebody else, taken over and reused, which would make this address a victim as well as a source.
We lean toward the lab, on the hosting evidence, and we are not confident. A second address on the list — [88.80.150.200](https://analytics.dugganusa.com/stix/register?ref=ioc-click&q=88.80.150.200) — runs Windows 7 Ultimate SP1, end-of-life since 2020, with SMB and RDP open, which is not what a well-resourced operator provisions for themselves and reads more like the second reading.
Both readings survive the evidence we have. We would rather publish the fork than pick the more dramatic branch.
The part where we were wrong
When CISA updated AA26-097A on 22 July, the line every outlet picked up was "new detection guidance for Rockwell reusable code modules."
We wrote, in print, six days ago: "That is the least interesting sentence in the update."
We argued the interesting material was elsewhere — the vendor scope expanding to Schneider and Siemens, and the safety-limit subtraction, which we still think is the most alarming paragraph in the document. We stand by that ranking of the threat.
But the Rockwell thread was the one that led somewhere. Following it is what produced this. We dismissed it as the boring vendor-specific detail and it turned out to be the loose end with something attached to it.
There is a lesson in that beyond the embarrassment. Detection guidance for a specific vendor's code modules sounds narrow, so it reads as narrow. It is actually a statement about what tooling the operator is using — and tooling leaves a fingerprint on the operator's own infrastructure, not just on the victim's.
The other thing we got right and did not exploit
On 26 July we published a piece on four code-execution bugs in Rockwell Arena, and the argument was that the target is not the PLC but the engineer who designs it — the workstation with the simulation model, the HMI project files, the PLC programming environment and the vendor VPN all on the same machine.
That post was about defending your engineers. It did not occur to us to point the same lens at the other side and ask what the attacker's engineering workstation looks like.
It looks like this. Same software category, same licence daemons, same Windows remote-management stack — just internet-facing, on rented hosting, and listed in an advisory.
What to do
Block the twenty-one. They are free in our feed, confidence 90, no registration. That has not changed.
Run 44818 against your own estate tonight if you have not. Also 2222, 102, 502 on controllers and 22 on modems. Our 25 July instruction stands and this post is an argument for taking it seriously, not a replacement for it.
Then ask the harder question about your engineering hosts. Which machines run Rockwell software, or Siemens TIA, or Schneider tooling? Are any of them reachable from outside? Do any of them present 44818 to the internet? A softPLC or configuration gateway answering EtherNet/IP from a public address is the same exposure whoever owns it — the box in this post is proof the shape exists in the wild, and there is no reason to assume every instance of it belongs to an attacker.
And check your licence servers. FlexNet and Sentinel daemons on internet-facing hosts are an under-examined surface. They are boring, they are old, they are installed because software would stop working otherwise, and nobody inventories them.
The honest position
We did not discover this campaign, we hold no attribution, and every indicator here came from a public advisory that six federal agencies wrote. Our edge has never seen any of these addresses — we checked with exact-match queries after a prefix query nearly fooled us with a five-figure count that was a search-index ceiling.
What we did was take a list everybody has, run a check we had already told other people to run, and look at the answer. The enrichment is third-party — Shodan, AbuseIPDB, VirusTotal — and available to anyone with a free key, which is the uncomfortable part. Nothing here required privileged access or a vendor relationship. It required about twenty minutes and the idea of pointing the question backwards.
Confidence capped at 95%. Port and banner data are Shodan's, read on 31 July, and are a point-in-time observation that will expire. The Rockwell identity, licence daemons and Windows fingerprint are quoted from the service banners as returned. The interpretation — operator lab versus compromised host — is explicitly unresolved. We do not claim this host pushed any file to any controller.
How do AI models see YOUR brand?
AIPM has audited 250+ domains. 15 seconds. Free while still in beta.
