Quantitative Security – Protective Intelligence / Threat Hunting Engagement

Executive Summary

This engagement originated as social engineering applied against a separate reconnaissance workflow. A masked IP geolocated to Iran visited Quantitative Security infrastructure. Through continued social engineering of that interaction, the operator successfully trapped and collected a substantial set of IP addresses and supporting infrastructure.

The trapped dataset was then expanded via a purpose-built website that harvested visitor IPs and associated infrastructure. That collection became the primary analytical set for the remainder of the engagement.

From this foundation the work progressed through systematic active reconnaissance (Nmap service and version detection, banner grabbing, certificate analysis, content probes), geographic and abuse correlation, cluster prioritization, and deep passive OSINT enrichment across Tencent Cloud ranges, commercial proxy infrastructure, administrative panels, RDP hosts, and multiple domain ecosystems.

Primary findings include active commercial authenticated proxy infrastructure operated by GoCodeIT Inc (Canada), exposed administrative interfaces (CloudPanel 2.5.2 and Nginx Proxy Manager), a Microsoft-style CodePushServer instance, an Indonesian real-money gambling platform and its scam ecosystem, multiple internet-facing Windows RDP hosts, Nigerian virtual-SIM connectivity infrastructure in wind-down, and a long-running Indian tech media/hosting operator with high-abuse IP space.

All residual technical scanning and passive enrichment have been completed. The dataset is closed at the reconnaissance and OSINT layers and forms one of the operational baselines for Quantitative Security through the remainder of 2026.

Scope and Methodology

Scope

  • Initial social-engineering-derived IP and infrastructure collection stemming from the masked Iranian visitor to Quantitative Security.

  • Expansion of that collection via a visitor-harvesting website.

  • Subsequent targeted expansion into Tencent Cloud ranges (43.x, 49.x, 150.x, 152.32.x), proxy pairs, RDP hosts, domain pivots (Laos cluster,

    geniex.com

    ,

    acmmanufacturer.com

    ,

    rejekibet.com

    ,

    technofaq.org

    ), and residual stragglers.

Methodology

  1. Social engineering of the originating reconnaissance workflow and subsequent visitor-IP harvesting.

  2. IP compilation, deduplication, and initial reputation/abuse correlation (web hacking, API abuse, brute-force).

  3. Geographic and residential analysis with focus on Turkey, then Laos.

  4. Systematic batch Nmap (-sV, -sC, -Pn, --top-ports 100, selective full-port, banner and service scripts).

  5. TLS certificate inspection, HTTP header/content grabs, path probing, SSH hostkey collection, RDP NTLM extraction.

  6. Domain-to-IP and certificate SAN pivoting.

  7. Passive enrichment: WHOIS, dig, reverse DNS, public web searches, company records, abuse databases, app-store listings.

  8. No active exploitation; all activity remained reconnaissance and open-source intelligence.

Early Reconnaissance – Abuse Correlation, Residential/Turkey Focus, Mail & rDNS, Zeus Admin, SOCKS5 & Banner Grabbing

Initial Abuse / Reputation Correlation

Immediately after the social-engineering-derived IP set was trapped and expanded via the visitor-harvesting website, a dedicated reputation pass was run across the full list. Known abuse was specifically pulled for web hacking, API abuse, and brute-force activity. This correlation shaped early prioritization and confirmed that a meaningful subset of the trapped addresses already carried documented histories in those three categories. The abuse framing remained a consistent reference point through the rest of the engagement.

Residential Expansion and Turkey Focus

Residential IPs within the dataset were deliberately expanded and analyzed in detail. A focused geographic pass was then performed on Turkey-linked addresses. This residential and Turkey-centric work established the first clear regional concentration before attention shifted to the Laos cluster and later Tencent ranges.

Mail Servers and Reverse DNS Discrepancies

Early enrichment identified mail servers attached to several hosts in the original set. Concurrent reverse-DNS monitoring revealed a notable timing discrepancy: a single subdomain would appear in resolution data, followed 5–10 minutes later by the appearance of two related subdomains. This delayed dual-subdomain behavior was flagged as anomalous and retained as an indicator during subsequent correlation.

SOCKS5 / Proxy Infrastructure

Multiple hosts in the 104.207.x.x range were examined for SOCKS5 and HTTP proxy services:

  • 104.207.38.6

  • 104.207.46.52

  • 104.207.50.152

Key observations:

  • Port 1080 (SOCKS5) – authentication method checks and socks-auth-info scripting.

  • Port 3128 (HTTP proxy) – returned 407 Proxy Authentication Required with Basic realm.

  • Port 8081 – TLS services presenting short-lived Let’s Encrypt certificates (issuer CN=YE1). Certificates were valid for only ~7 days and used post-quantum hybrid key exchange (X25519MLKEM768).

Path probing on the 8081 HTTPS services (/login, /admin, /api, /status, /health, /metrics, /version, /info, /proxy, /socks) consistently returned 404 “page not found” responses with a minimal Go-style server fingerprint (x-content-type-options: nosniff). No functional administrative interface was exposed on these paths.

Zeus Admin & Related Panel Checks

Nmap service detection flagged port 9090 on several residual hosts as zeus-admin (filtered). Targeted banner grabbing and version detection were performed across the early set to identify any Zeus-style or similar remote administration panels. No live, unauthenticated Zeus admin interfaces were confirmed; most instances remained filtered or returned no response under the prevailing cloud security groups.

Banner Grabbing Highlights

  • Pure-FTPd, Exim 4.99.4, Dovecot, LiteSpeed, and MySQL 8.0.46 banners recovered from

    mt-rohan.guzelhosting.com

    (104.247.165.210).

  • OpenSSH hostkeys and version strings collected across multiple early hosts.

  • HTTP/HTTPS server headers (Sws, OpenResty, nginx, Golang net/http) documented for later correlation.

This early phase established documented abuse patterns, a clear residential/Turkey concentration, anomalous reverse-DNS timing behavior, the presence of commercial-grade authenticated proxy infrastructure, and the absence of readily accessible classic Zeus admin panels — setting the technical baseline for the subsequent Tencent Cloud and domain pivots.

Banner Grabbing Highlights

  • Pure-FTPd, Exim 4.99.4, Dovecot, LiteSpeed, and MySQL 8.0.46 banners recovered from

    mt-rohan.guzelhosting.com

    (104.247.165.210).

  • OpenSSH hostkeys and version strings collected across multiple early hosts.

  • HTTP/HTTPS server headers (Sws, OpenResty, nginx, Golang net/http) documented for later correlation.

This early phase established the presence of commercial-grade authenticated proxy infrastructure and the absence of readily accessible classic Zeus admin panels, setting the technical baseline for the subsequent Tencent Cloud and domain pivots.

Original Dataset and Early Clusters

Early processing included reputation pulls focused on web-hacking, API abuse, and brute-force patterns, residential expansion, and Turkey-focused analysis.

Notable Early Hosts

  • mt-rohan.guzelhosting.com

    (104.247.165.210) – LiteSpeed, Pure-FTPd, Exim, Dovecot, MySQL 8.0.46 full mail + web stack.

  • Commercial proxy pair 65.111.5.29 / 74.119.149.79 – SOCKS5, HTTP proxy, TLS; GoCodeIT Inc (Canada).

  • 103.255.134.61:8443 – CloudPanel 2.5.2 (TFAQ /

    technofaq.org

    ).

  • 38.107.237.68 – Windows Server 2022 RDP (hostname RDX60301).

  • 195.2.78.89 (

    VDSINA.ru

    ) – hostile response; blocked.

  • Confirmed legitimate bot traffic (Applebot, Googlebot, MSNbot) filtered as expected.

Laos / Southeast Asia Cluster

Chinese-language medical tourism and used-car platform content; recent registrations via Todaynic / DNSPod.

Tencent Cloud Reconnaissance

Hundreds of IPs across sequential batches under heavy security-group filtering. Standout live services included Nginx Proxy Manager, Next.js applications, authenticated proxies, CodePushServer,

rejekibet.com

, multiple Windows RDP hosts (Server 2016/2022), OpenSSH variants, legacy Jetty, Sws, Golang net/http, and rpcbind.

High-Interest Tencent Hosts:

  • 152.32.146.77,80/81/443 OpenResty + Nginx Proxy Manager,NPM login on :81 (“In The Office Planner” branding)

  • 152.32.150.88,3000 Next.js,/arena path – modern frontend

  • 152.32.153.101,10000,Authenticated HTTP proxy (407 Basic)

  • 152.32.154.55,443 nginx,

    rejekibet.com

    – Indonesian game development / interactive entertainment site

  • 152.32.169.33,"80 OpenResty 1.27.1.2, 8888/9999 ssl/http","CodePushServer on :8888. Cert SANs include other Tencent IPs. Full CORS, strong security headers"

  • 152.32.174.88,80/443 nginx,Previously served

    acmmanufacturer.com

    (domain later moved)

  • 152.32.173.44,"22 OpenSSH 9.6p1, 80/443 nginx",Long-lived self-signed cert (to 2036)

  • Multiple,3389 RDP,"Windows Server 2016 (10.0.14393) and 2022 (10.0.20348). Internal-style hostnames (10-x-x-x, 172_19_32_10, etc.)"

  • Multiple,22 OpenSSH,Versions 7.4 → 10.0 (Ubuntu/Debian). Modern post-quantum KEX on newer hosts

  • Various,"Jetty 8.1.17 (legacy), Sws, Golang net/http, rpcbind, FTP (often tcpwrapped)",Mixed stacks

  • geniex.com

    subdomains (git, jump, gx-api, data-api, vsim-cms, merchant, bosslog, staging, admin, etc.) pivoted into the residual Tencent ranges. All residual Tencent, infrastructure-leftover, bot/crawler, and straggler sets were completed and closed.

High-Value Assets – Detailed Analysis

GoCodeIT Commercial Proxy Pair65.111.5.29 / 74.119.149.79 – authenticated SOCKS5 and HTTP proxy services operated by GoCodeIT Inc (Thornhill, Ontario; director Sepehr Ahmadi). Multiple ASNs; ranges commonly appear in proxy detection databases.

rejekibet.com

EcosystemIndonesian real-money gaming platform with heavy Telegram/APK distribution. Online gambling is illegal in Indonesia; large-scale enforcement actions occurred throughout 2026. Multiple scam clones and crypto-drainer sites exist around the brand.

CloudPanel (103.255.134.61)Exposed CloudPanel 2.5.2 instance belonging to TECHNO FAQ DIGITAL MEDIA (TFAQ /

technofaq.org

), IIT Guwahati-based Indian tech media and hosting operator. The IP carries very high AbuseIPDB volume consistent with shared or poorly secured hosting.

CodePushServer (152.32.169.33)OpenResty front-end with dedicated Microsoft-style CodePushServer on port 8888; certificate SANs reference additional Tencent infrastructure.

geniex.com

/ GENIEX-TECH NIGERIA LIMITEDNigerian virtual-SIM / data connectivity app (Tecno/Infinix/Itel focus) with 1M+ downloads. Official 2026 communications indicated service wind-down. Domain itself dates to 2004 and currently resolves to AWS.

acmmanufacturer.comPreviously on residual Tencent infrastructure; migrated to Zenlayer via

chukouplus.com

(Chinese export platform CNAME).

Additional internet-facing Windows RDP hosts and management interfaces (Nginx Proxy Manager and others) were identified across residual ranges.

Domains Identified

Primary / High-Interest

Supporting / Infrastructure

Threat Assessment and Priority Ranking

  • GoCodeIT proxy pair (65.111.5.29 / 74.119.149.79),High,Active commercial proxy infrastructure with clear ownership

  • rejekibet.com

    ecosystem,Medium-High,Illegal gambling + active scam clones in Indonesia

  • 103.255.134.61 CloudPanel,Medium,High abuse volume on the IP; exposed admin panel

  • geniex.com

    ,Low-Medium,Nigerian app winding down

  • acmmanufacturer.com

    ,Low,Migrated; limited intelligence value

Highest-value indicators remain the GoCodeIT commercial proxy infrastructure, exposed administrative panels (CloudPanel and Nginx Proxy Manager), the CodePushServer instance, the

rejekibet.com

gambling and scam ecosystem, and internet-facing RDP hosts.

Observed patterns include commercial proxy-as-a-service activity, possible traffic-proxy or C2 networks, regional business infrastructure (Laos medical tourism, Indonesian gaming, Chinese-language services, Nigerian connectivity), and one confirmed hostile response. Heavy cloud filtering limited further live surface on residual Tencent ranges. Early abuse correlations (web hacking, API abuse, brute-force) remained consistent with later observations.

Conclusion

The intelligence produced in this engagement now stands as a finished, prioritized body of work. Commercial proxy infrastructure, exposed administrative surfaces, regional gambling and connectivity platforms, and residual cloud assets have been fully mapped and ranked.

With every residual scan and enrichment task closed, Quantitative Security carries a clean, actionable baseline into the second half of 2026. This dataset will directly support protective intelligence production, threat-hunting operations for a start to Q3 and Q4 of 2026.

Previous
Previous

From a GitHub LB to a Multi-Year Brazilian Health-Plan Brand Farm: Infrastructure & Identity

Next
Next

Cloud Range Reconnaissance: Mapping Production, Staging, and Abandoned Assets