Quantitative Security – Protective Intelligence / Threat Hunting Engagement
Executive Summary
This engagement originated as social engineering applied against a separate reconnaissance workflow. A masked IP geolocated to Iran visited Quantitative Security infrastructure. Through continued social engineering of that interaction, the operator successfully trapped and collected a substantial set of IP addresses and supporting infrastructure.
The trapped dataset was then expanded via a purpose-built website that harvested visitor IPs and associated infrastructure. That collection became the primary analytical set for the remainder of the engagement.
From this foundation the work progressed through systematic active reconnaissance (Nmap service and version detection, banner grabbing, certificate analysis, content probes), geographic and abuse correlation, cluster prioritization, and deep passive OSINT enrichment across Tencent Cloud ranges, commercial proxy infrastructure, administrative panels, RDP hosts, and multiple domain ecosystems.
Primary findings include active commercial authenticated proxy infrastructure operated by GoCodeIT Inc (Canada), exposed administrative interfaces (CloudPanel 2.5.2 and Nginx Proxy Manager), a Microsoft-style CodePushServer instance, an Indonesian real-money gambling platform and its scam ecosystem, multiple internet-facing Windows RDP hosts, Nigerian virtual-SIM connectivity infrastructure in wind-down, and a long-running Indian tech media/hosting operator with high-abuse IP space.
All residual technical scanning and passive enrichment have been completed. The dataset is closed at the reconnaissance and OSINT layers and forms one of the operational baselines for Quantitative Security through the remainder of 2026.
Scope and Methodology
Scope
Initial social-engineering-derived IP and infrastructure collection stemming from the masked Iranian visitor to Quantitative Security.
Expansion of that collection via a visitor-harvesting website.
Subsequent targeted expansion into Tencent Cloud ranges (43.x, 49.x, 150.x, 152.32.x), proxy pairs, RDP hosts, domain pivots (Laos cluster,
,
,
,
), and residual stragglers.
Methodology
Social engineering of the originating reconnaissance workflow and subsequent visitor-IP harvesting.
IP compilation, deduplication, and initial reputation/abuse correlation (web hacking, API abuse, brute-force).
Geographic and residential analysis with focus on Turkey, then Laos.
Systematic batch Nmap (-sV, -sC, -Pn, --top-ports 100, selective full-port, banner and service scripts).
TLS certificate inspection, HTTP header/content grabs, path probing, SSH hostkey collection, RDP NTLM extraction.
Domain-to-IP and certificate SAN pivoting.
Passive enrichment: WHOIS, dig, reverse DNS, public web searches, company records, abuse databases, app-store listings.
No active exploitation; all activity remained reconnaissance and open-source intelligence.
Early Reconnaissance – Abuse Correlation, Residential/Turkey Focus, Mail & rDNS, Zeus Admin, SOCKS5 & Banner Grabbing
Initial Abuse / Reputation Correlation
Immediately after the social-engineering-derived IP set was trapped and expanded via the visitor-harvesting website, a dedicated reputation pass was run across the full list. Known abuse was specifically pulled for web hacking, API abuse, and brute-force activity. This correlation shaped early prioritization and confirmed that a meaningful subset of the trapped addresses already carried documented histories in those three categories. The abuse framing remained a consistent reference point through the rest of the engagement.
Residential Expansion and Turkey Focus
Residential IPs within the dataset were deliberately expanded and analyzed in detail. A focused geographic pass was then performed on Turkey-linked addresses. This residential and Turkey-centric work established the first clear regional concentration before attention shifted to the Laos cluster and later Tencent ranges.
Mail Servers and Reverse DNS Discrepancies
Early enrichment identified mail servers attached to several hosts in the original set. Concurrent reverse-DNS monitoring revealed a notable timing discrepancy: a single subdomain would appear in resolution data, followed 5–10 minutes later by the appearance of two related subdomains. This delayed dual-subdomain behavior was flagged as anomalous and retained as an indicator during subsequent correlation.
SOCKS5 / Proxy Infrastructure
Multiple hosts in the 104.207.x.x range were examined for SOCKS5 and HTTP proxy services:
104.207.38.6
104.207.46.52
104.207.50.152
Key observations:
Port 1080 (SOCKS5) – authentication method checks and socks-auth-info scripting.
Port 3128 (HTTP proxy) – returned 407 Proxy Authentication Required with Basic realm.
Port 8081 – TLS services presenting short-lived Let’s Encrypt certificates (issuer CN=YE1). Certificates were valid for only ~7 days and used post-quantum hybrid key exchange (X25519MLKEM768).
Path probing on the 8081 HTTPS services (/login, /admin, /api, /status, /health, /metrics, /version, /info, /proxy, /socks) consistently returned 404 “page not found” responses with a minimal Go-style server fingerprint (x-content-type-options: nosniff). No functional administrative interface was exposed on these paths.
Zeus Admin & Related Panel Checks
Nmap service detection flagged port 9090 on several residual hosts as zeus-admin (filtered). Targeted banner grabbing and version detection were performed across the early set to identify any Zeus-style or similar remote administration panels. No live, unauthenticated Zeus admin interfaces were confirmed; most instances remained filtered or returned no response under the prevailing cloud security groups.
Banner Grabbing Highlights
Pure-FTPd, Exim 4.99.4, Dovecot, LiteSpeed, and MySQL 8.0.46 banners recovered from
(104.247.165.210).
OpenSSH hostkeys and version strings collected across multiple early hosts.
HTTP/HTTPS server headers (Sws, OpenResty, nginx, Golang net/http) documented for later correlation.
This early phase established documented abuse patterns, a clear residential/Turkey concentration, anomalous reverse-DNS timing behavior, the presence of commercial-grade authenticated proxy infrastructure, and the absence of readily accessible classic Zeus admin panels — setting the technical baseline for the subsequent Tencent Cloud and domain pivots.
Banner Grabbing Highlights
Pure-FTPd, Exim 4.99.4, Dovecot, LiteSpeed, and MySQL 8.0.46 banners recovered from
(104.247.165.210).
OpenSSH hostkeys and version strings collected across multiple early hosts.
HTTP/HTTPS server headers (Sws, OpenResty, nginx, Golang net/http) documented for later correlation.
This early phase established the presence of commercial-grade authenticated proxy infrastructure and the absence of readily accessible classic Zeus admin panels, setting the technical baseline for the subsequent Tencent Cloud and domain pivots.
Original Dataset and Early Clusters
Early processing included reputation pulls focused on web-hacking, API abuse, and brute-force patterns, residential expansion, and Turkey-focused analysis.
Notable Early Hosts
(104.247.165.210) – LiteSpeed, Pure-FTPd, Exim, Dovecot, MySQL 8.0.46 full mail + web stack.
Commercial proxy pair 65.111.5.29 / 74.119.149.79 – SOCKS5, HTTP proxy, TLS; GoCodeIT Inc (Canada).
103.255.134.61:8443 – CloudPanel 2.5.2 (TFAQ /
).
38.107.237.68 – Windows Server 2022 RDP (hostname RDX60301).
195.2.78.89 (
) – hostile response; blocked.
Confirmed legitimate bot traffic (Applebot, Googlebot, MSNbot) filtered as expected.
Laos / Southeast Asia Cluster
/
/
/
Chinese-language medical tourism and used-car platform content; recent registrations via Todaynic / DNSPod.
Tencent Cloud Reconnaissance
Hundreds of IPs across sequential batches under heavy security-group filtering. Standout live services included Nginx Proxy Manager, Next.js applications, authenticated proxies, CodePushServer,
, multiple Windows RDP hosts (Server 2016/2022), OpenSSH variants, legacy Jetty, Sws, Golang net/http, and rpcbind.
High-Interest Tencent Hosts:
152.32.146.77,80/81/443 OpenResty + Nginx Proxy Manager,NPM login on :81 (“In The Office Planner” branding)
152.32.150.88,3000 Next.js,/arena path – modern frontend
152.32.153.101,10000,Authenticated HTTP proxy (407 Basic)
152.32.154.55,443 nginx,
– Indonesian game development / interactive entertainment site
152.32.169.33,"80 OpenResty 1.27.1.2, 8888/9999 ssl/http","CodePushServer on :8888. Cert SANs include other Tencent IPs. Full CORS, strong security headers"
152.32.174.88,80/443 nginx,Previously served
(domain later moved)
152.32.173.44,"22 OpenSSH 9.6p1, 80/443 nginx",Long-lived self-signed cert (to 2036)
Multiple,3389 RDP,"Windows Server 2016 (10.0.14393) and 2022 (10.0.20348). Internal-style hostnames (10-x-x-x, 172_19_32_10, etc.)"
Multiple,22 OpenSSH,Versions 7.4 → 10.0 (Ubuntu/Debian). Modern post-quantum KEX on newer hosts
Various,"Jetty 8.1.17 (legacy), Sws, Golang net/http, rpcbind, FTP (often tcpwrapped)",Mixed stacks
subdomains (git, jump, gx-api, data-api, vsim-cms, merchant, bosslog, staging, admin, etc.) pivoted into the residual Tencent ranges. All residual Tencent, infrastructure-leftover, bot/crawler, and straggler sets were completed and closed.
High-Value Assets – Detailed Analysis
GoCodeIT Commercial Proxy Pair65.111.5.29 / 74.119.149.79 – authenticated SOCKS5 and HTTP proxy services operated by GoCodeIT Inc (Thornhill, Ontario; director Sepehr Ahmadi). Multiple ASNs; ranges commonly appear in proxy detection databases.
EcosystemIndonesian real-money gaming platform with heavy Telegram/APK distribution. Online gambling is illegal in Indonesia; large-scale enforcement actions occurred throughout 2026. Multiple scam clones and crypto-drainer sites exist around the brand.
CloudPanel (103.255.134.61)Exposed CloudPanel 2.5.2 instance belonging to TECHNO FAQ DIGITAL MEDIA (TFAQ /
), IIT Guwahati-based Indian tech media and hosting operator. The IP carries very high AbuseIPDB volume consistent with shared or poorly secured hosting.
CodePushServer (152.32.169.33)OpenResty front-end with dedicated Microsoft-style CodePushServer on port 8888; certificate SANs reference additional Tencent infrastructure.
/ GENIEX-TECH NIGERIA LIMITEDNigerian virtual-SIM / data connectivity app (Tecno/Infinix/Itel focus) with 1M+ downloads. Official 2026 communications indicated service wind-down. Domain itself dates to 2004 and currently resolves to AWS.
acmmanufacturer.comPreviously on residual Tencent infrastructure; migrated to Zenlayer via
(Chinese export platform CNAME).
Additional internet-facing Windows RDP hosts and management interfaces (Nginx Proxy Manager and others) were identified across residual ranges.
Domains Identified
Primary / High-Interest
(and associated subdomains: git, jump, gx-api, data-api, vsim-cms, merchant, bosslog, staging, admin, etc.)
/
/
/
Supporting / Infrastructure
(GoCodeIT)
Additional short-lived and Cloudflare-fronted domains observed during certificate and passive DNS review.
Threat Assessment and Priority Ranking
GoCodeIT proxy pair (65.111.5.29 / 74.119.149.79),High,Active commercial proxy infrastructure with clear ownership
ecosystem,Medium-High,Illegal gambling + active scam clones in Indonesia
103.255.134.61 CloudPanel,Medium,High abuse volume on the IP; exposed admin panel
,Low-Medium,Nigerian app winding down
,Low,Migrated; limited intelligence value
Highest-value indicators remain the GoCodeIT commercial proxy infrastructure, exposed administrative panels (CloudPanel and Nginx Proxy Manager), the CodePushServer instance, the
gambling and scam ecosystem, and internet-facing RDP hosts.
Observed patterns include commercial proxy-as-a-service activity, possible traffic-proxy or C2 networks, regional business infrastructure (Laos medical tourism, Indonesian gaming, Chinese-language services, Nigerian connectivity), and one confirmed hostile response. Heavy cloud filtering limited further live surface on residual Tencent ranges. Early abuse correlations (web hacking, API abuse, brute-force) remained consistent with later observations.
Conclusion
The intelligence produced in this engagement now stands as a finished, prioritized body of work. Commercial proxy infrastructure, exposed administrative surfaces, regional gambling and connectivity platforms, and residual cloud assets have been fully mapped and ranked.
With every residual scan and enrichment task closed, Quantitative Security carries a clean, actionable baseline into the second half of 2026. This dataset will directly support protective intelligence production, threat-hunting operations for a start to Q3 and Q4 of 2026.