From a GitHub LB to a Multi-Year Brazilian Health-Plan Brand Farm: Infrastructure & Identity

Executive Summary

On 2026-08-07 a recon session (phone hotspot + QuantumGuard + packet capture) led from curiosity about a GitHub pull request to reverse-IP of GitHub’s Seattle load-balancer 140.82.116.3. That IP co-hosted

coindream.site

(web on GitHub, mail SPF pointing to UltaHost cp5 159.100.6.5). Reverse-IP and subsequent pivots revealed two dense shared-hosting environments: UltaHost cp5 (mixed tenants including a Shell Eastern Petroleum lookalike registered to Christian von Langermann) and especially qloudhost 45.87.42.74.

The qloud node hosted a multi-year (2017–2025) Brazilian “planos de saúde” sales farm using brand names Bradesco, Amil, Unimed and SulAmérica, offering 50–60 % first-month discounts. WHOIS attributes the core portfolio to Fabiola Silva Souza (FASSO283) using the email

fabiola@saudeperfeita.com.br

. That email domain is a live HostGator-hosted brokerage-style WordPress site (

saudeperfeita.com.br

) owned by Roger Oliveira of Agência Unit, with tech contact and WP author Leonildo (“nildo”). Additional registrants Tiago Ferreira Pena and Leonildo share the same qloud nameservers. Public records confirm a matching CNPJ (Fabiola Silva Souza Seguros Ltda / Nf Seguros Saude, Mococa-SP, active since 2021).

The same qloud shared node also carried classic brand-abuse and typo-squatting content: fake online banks (

bridgecorebank.com

, registrant Williams Smith), casino registration pages, Paysafe/Neosurf converters, and various ticketmaster/kaiserpermanente-style stubs. QloudHost explicitly markets casino hosting.

pro114.dnspro.com.br

(another Brazilian shared box) exposed a full mail/panel stack plus public MariaDB 10.11.18. UltaHost later filtered web ports; aggressive scanning rate-limited qloud 443.

The case is an identity-and-infrastructure map of a multi-year Brazilian health-plan sales/brand ecosystem entered via a GitHub reverse-IP curiosity, sitting on privacy/DMCA-ignored shared hosting that also densifies fake-bank and casino lookalikes. Shared NS and email domain link the health-plan operators; co-tenancy alone does not prove the financial/gambling tenants share the same operators. No credential attacks or exploit development were performed. Several items remain open (full

registro.br

portfolio, qloud WP users while blackholed, von Langermann secondary pivots, original GitHub PR URL).

Passive reconnaissance on 2026-08-07 mapped a long-running “planos de saúde” sales cluster under Fabiola Silva Souza (FASSO283), a registered seguros company, shared nameservers, and a HostGator brokerage front—while the same qloud node densified fake banks, casino lookalikes, and payment converters. Entry was a reverse-IP curiosity during a recon session that began with a GitHub pull-request investigation.

Origin – The GitHub Edge

The operator and tools reached

github.com

(140.82.116.4) and the Seattle load-balancer hostname

lb-140-82-116-3-sea.github.com

(140.82.116.3). A reverse-IP lookup on 140.82.116.3 returned the expected GitHub marketing host plus an unexpected set of

coindream.site

and bakkta* subdomains (cpanel, webmail, mail, autodiscover,

bakkta.support

,

bakktat.website

, etc.).

ARIN confirmed the block as GITHU / GitHub, Inc. wget/curl of the LB hostname produced the standard 301 chain to

github.com

. Nmap fingerprints matched public GitHub behavior. The pcap later re-parse confirmed the origin trail—Grok, GitHub—while containing zero packets to the later case IPs 45.87.42.74, 159.100.6.5 or 187.33.241.58. The stated intent was investigation of a GitHub pull request; the PR URL itself was never supplied and remains an open, user-only item.

Pivot 1 –

coindream.site

(Split Architecture)

Live DNS for

coindream.site

showed:

  • A record (apex and all cPanel-style hostnames) → 140.82.116.3 (GitHub)

  • NS → dns1/dns2.registrar-servers.com (Namecheap BasicDNS)

  • MX → Namecheap eforward[1–5]

  • TXT/SPF → v=spf1 +a +mx +ip4:159.100.6.5 include:

    relay.mailchannels.net

    ~all

  • Created 2026-01-23, updated 2026-02-01, privacy registrant (Withheld for Privacy ehf, Iceland), clientTransferProhibited, DNSSEC unsigned.

The architecture is deliberately split: web presence on a GitHub edge that simply redirects to

github.com

, while mail authorization points at an UltaHost cPanel node. Forced Host:

coindream.site

against 159.100.6.5 (when web was still open) returned the classic 163-byte cPanel defaultwebpage meta-refresh. bakkta / bakktat / bakktatr naming is lookalike noise relative to the public Bakkt trading brand; no evidence of compromise of the legitimate entity was found.

Pivot 2 – UltaHost cp5 (159.100.6.5)

Reverse-IP of 159.100.6.5 returned approximately 500 hostnames and an early extract of ~78 unique apexes. Almost every tenant carried the full cPanel kit (cpanel., webmail., webdisk., cpcalendars., cpcontacts., mail., autodiscover.,

www

.). Early-session 80/443 were LiteSpeed open; by late-session nmap (18:50) they were filtered, leaving only 2082/2083 (OpenResty 1.31.1.1 cPanel) open. TLS certificates belonged to the

cp5.fra1.ultacp.com

family (Let’s Encrypt). Unauthenticated paths on :2083 later returned a ~12 KB “One moment, please...” bot-check page with headless/bytespider challenges.

High-interest content harvested while HTTPS still answered included:

  • shelleasternpetroleum.ae

    – Shell Eastern Petroleum template, Let’s Encrypt certificate, WHOIS registrant/tech Christian von Langermann (DURRAQ-R138206K / DURRAQ-T138206K), NS ns1/2/3.ultahost.com, A → 159.100.6.5.

  • gamingcomission.co

    and certificates.* – “KGC – Certificates” typo-commission theme.

  • antifraud.click

    – AR-style “verify before transfer” PHP application with PHPSESSID and CSP.

  • aranttru.com

    – “Gar T – Online Banking Platform”.

  • pinupcasinorussia.click

    – Pin-Up casino clone (~169 kB body).

  • Various markets/trading and suspendedpage.cgi accounts.

  • 7secondsoflove.com

    – large unique body (~173 kB) in vhost ffuf.

  • Directory-listing Index of / on several tenants.

ffuf vhost run (Host: FUZZ @

https://159.100.6.5/

, -fs 163) produced 202 hits: 147×200, 50×403 (shared deny), 4×302, 1×301. Size signatures cleanly separated cPanel login UI (~40 kB), service pages (~12 kB), and the large unique site.

Threat Nmap – Three IPs Side-by-Side

  • 159.100.6.5 (cp5) – only 2082/2083 open (panel-only from this path).

  • 187.33.241.58 (

    pro114.dnspro.com.br

    ) – full surface: Pure-FTPd 21, PowerDNS Auth 4.9.16 on 53, LiteSpeed 80/443, full Dovecot, Exim 4.99.5, cPanel/OpenResty, WHM (pt_br, whostmgrsession), Roundcube webmail, MariaDB 10.11.18 listening on public 3306 (banner 5.5.5-10.11.18-MariaDB-cll-lve). Hostname banners confirmed

    pro114.dnspro.com.br

    . Reverse-IP showed ~500 Brazilian SME tenants (advocacia, shops, academias) with lower brand-abuse density than qloud. Panels later returned the same OpenResty bot wall.

  • 45.87.42.74 (

    shared.qloudhost.com

    ) – Pure-FTPd, OpenSSH 8.0 (RHEL 8), BIND 9.11.36, LiteSpeed, DirectAdmin + Exim mail stack, MariaDB 10.6.27 (historically open), no external cPanel ports. This became the primary brand-abuse host.

Comparative surface at nmap time showed qloud and pro114 as full-stack boxes with public databases; cp5 had already retreated to panel-only.

The Qloud Brand-Abuse Farm (45.87.42.74)

Reverse-IP produced ~499 hostnames / ~207 apexes. A strict brand-abuse extraction listed 23 domains. Successful header/title harvest while 443 still answered revealed a coherent set of WordPress “X% Desconto” health-plan sales sites:

Adjacent non-health tenants on the identical shared node included

bridgecorebank.com

(fake online banking),

betify4.com

(casino registration),

mypaysafe.eu

and

www-myneosurf.com

(payment converters), plus numerous stubs and intermittent titles (casinoradar365, kaiserpermanenteinc, trustdigitalbank, produbancoecu, ticketmastercolombiaonline, neosurf-remboursement, etc.).

ffuf path discovery after failed autocalibration produced large volumes of soft-404 (200/words≈1498/size≈119xx or 500/2431/words=168). The operational lesson was explicit: after calibration failure, filter aggressively (-fw 1498 -fs 2431) and do not treat admin/phpMyAdmin/log paths as real. Aggressive scanning subsequently rate-limited / blackholed 45.87.42.74:443 for extended periods (QLOUD_DOWN), while DNS continued to point the brand domains at the IP. Live recon of the Fabiola sales sites therefore became blocked until cooldown.

QloudHost itself markets “Casino Web Hosting” as a product line—DMCA-ignored, crypto-friendly, privacy-focused, high-traffic gambling and betting platforms—providing an explicit commercial rationale for the density of casino and payment lookalikes observed on the same box.

Identity Investigation

Primary: FABIOLA SILVA SOUZA / FASSO283

  • Person: FABIOLA SILVA SOUZA

  • nic-hdl-br: FASSO283

  • Email:

    fabiola@saudeperfeita.com.br

  • CPF mask: *.809.878-

  • Handle created: 2017-07-21

  • NS for the sales portfolio: shared1/2.qloudhost.com

Confirmed owner domains (creation dates span 2017–2025):

CLI whois FASSO283 fails (“No whois server is known for this kind of object”). Full portfolio expansion requires the

registro.br

web UI (still open item).

Public corporate records confirm a matching legal entity: Fabiola Silva Souza Seguros Ltda (nome fantasia Nf Seguros Saude), CNPJ 40.950.276/0001-55, opened 23 February 2021, active, address Rua Julio de Oliveira 199, Mococa-SP, capital R$50.000, CNAE for insurance/plan auxiliaries, sole administrador Fabiola Silva Souza. The CNPJ post-dates the oldest domains but supplies a formal corretora-style wrapper for the later portfolio.

Adjacent registrants on the same farm

saudeperfeita.com.br

– the identity bridge Hosted at 162.241.2.92 (HostGator), Apache, WordPress + Yoast 27.2, Flatsome theme, FormCraft 3.8.7 (form.min.js last-modified 2020). Login /wp-login.php returns 200 with wordpress_test_cookie; users API is open and returns:

  • id=1, slug admin – “admin, Autor em Plano de Saúde”

  • id=2, slug nildo – “nildo, Autor em Plano de Saúde”

Content is a full planos-de-saúde brokerage (São Cristóvão Saúde, Prevent Senior, Trasmontano, Amil logos, individual/family/elderly/pregnant/children/company plans, /valores-planos-de-saude/, /cotacao/). The cotacao page is authored by nildo; the FormCraft lead form captures Nome, Tel fixo, Celular, Email plus a honeypot. Public form REST namespaces are absent. Contacts recovered from the ecosystem include

contato@agenciaunit.com

and the WhatsApp number +55 11 96663-5659 (exact match to the live Agência Unit site). Agência Unit presents as a professional web/SEO agency with a public portfolio and privacy policy (CNPJ references 35.472.056/0001-10 / 15.702.183/0001-64 appear across pages).

Williams Smith /

bridgecorebank.com

Created 2026-02-24, registrar

Name.com

, address 1020 SE Everett Mall Way, Everett WA 98208, country VI (privacy/proxy pattern). NS identical to the Fabiola qloud set. Same-host neighbors include trustdigitalbank, produbancoecu, ticketmastercolombiaonline and other payment-brand abuse domains. Public scanners give the domain a low trust score and classify it as suspicious; the title claims “Bridge Core Bank – Online Banking & Financial Services.” This is pure co-tenancy, not proven identity equivalence with Fabiola.

Christian von Langermann /shelleasternpetroleum.ae Registrant and technical contact of the Shell lookalike on Ultahost NS (early in the case). Confirmed A → 159.100.6.5. No secondary domains, email, phone, social or company filings were recovered in the available pass. The cluster remains partial and unlinked by identity to the Brazilian health-plan operators.

Attribution Model – What Is Strongly Supported vs. What Is Not Proven

Strongly supported:

  1. Multi-year Brazilian domain portfolio under Fabiola Silva Souza using the saudeperfeita mailbox, hosted on qloud, marketing Bradesco/Amil/Unimed/SulAmérica discounts.

  2. saudeperfeita.com.br

    is a live brokerage-style site operated with admin/nildo, linked to Roger’s Agência Unit and Leonildo.

  3. Shared industry + shared mail domain + shared hosting NS across multiple registrants constitutes an organized sales cluster.

  4. Public CNPJ for Fabiola Silva Souza Seguros Ltda supplies a corporate wrapper.

  5. The same qloud shared node densifies classic brand-abuse (fake banks, casino registration, payment converters); QloudHost markets casino hosting as a product.

  6. GitHub LB / coindream is an entry artifact (possible mail SPF + web decoy); UltaHost/cp5 and qloud are where the abusive/sales content lived.

  7. pro114 exposes a full mail/panel/MariaDB surface; qloud historically did likewise.

  8. At least one core sales domain (

    vendasbradescosaude.com.br

    ) has been classified phishing/malicious by major DNS filters (OpenDNS, Cloudflare, DNS4EU) while still resolving to the qloud IP.

Not proven:

  • Criminal intent versus aggressive (possibly non-compliant) affiliate marketing. Legal characterization is for investigators, ANS, registrars and counsel.

  • That Fabiola = nildo = Roger = Tiago (they are linked by infrastructure and contacts, not proven single person).

  • That Williams Smith or the casino/payment tenants are the same operators as Fabiola (same hoster and NS only).

  • Operational volume (traffic, leads closed, actual contracts).

Chronological Technical Timeline (Compressed)

  1. boot / hotspot

  2. github.com

    + reverse-IP of 140.82.116.3

  3. coindream discovery → SPF pivot to 159.100.6.5

  4. UltaHost reverse-IP (~500 hosts), headers, Shell WHOIS

  5. cPanel bot-wall mapping

  6. Threat nmap → pro114 + qloud full stacks + MariaDB exposure

  7. Reverse-IP 187 + 45 → Bradesco farm on qloud

  8. Live titles on qloud brands

  9. Soft-404 ffuf lesson

  10. Qloud rate-limit / blackhole

  11. WHOIS identity → Fabiola / Leonildo / Tiago / Roger

  12. saudeperfeita WP users + FormCraft / cotacao / author map

  13. Agência Unit phone/email confirmation

  14. Export package + rundown + open-items status

  15. Public CNPJ and vendor-flag cross-reference

Technical Surface & Operational Observations

  • Public MariaDB on pro114 (live) and historically on qloud – documented for hardening/abuse reporting only; no authentication attempts.

  • OpenResty/Imunify-style bot walls and full-host blackholing after recon.

  • Soft-404 noise after failed ffuf calibration; size/word filters required.

  • CT reliability historically flaky (502s); one successful saudebradescobr dump (242 entries) recovered multi-label SANs and brand-adjacent names.

  • Tooling incidents during the session (NUL corruption in on_ip_now.txt, unbound variables under set -u, ffuf interactive pause) were noted and corrected in the working scripts.

Policy remains absolute: no credential attacks, no MySQL login, no exploit development.

Best Contacts & IOCs

  • PHONE: +55 11 96663-5659 (Agência Unit)

  • EMAIL : contato@agenciaunit.com

  • EMAIL : fabiola@saudeperfeita.com.br

  • EMAIL : leonildo_1@hotmail.com (+ WP nildo)

  • EMAIL: roger@agenciaunit.com

  • EMAIL : tiago.ferreira.pena@gmail.com

  • IP : 45.87.42.74

    shared.qloudhost.com

    (brand farm + neighbors)

  • IP : 187.33.241.58

    pro114.dnspro.com.br

    (cPanel full + MySQL)

  • IP : 159.100.6.5

    cp5.fra1.ultacp.com

    (UltaHost; SPF/coindream)

  • IP : 162.241.2.92 HostGator (saudeperfeita)

  • IP: 140.82.116.3 GitHub SEA LB (entry)

  • SITE :

    https://saudeperfeita.com.br/

  • SITE :

    https://agenciaunit.com/

  • WP: admin, nildo @ saudeperfeita

  • CNPJ : 40.950.276/0001-55 (Fabiola Silva Souza Seguros Ltda / Nf Seguros Saude)

Closing Assessment

The recon produced a high-resolution identity-and-infrastructure map of a multi-year Brazilian health-plan sales ecosystem that uses brand names of major operators, a registered seguros company, a HostGator brokerage front, and shared DMCA-ignored hosting that simultaneously densifies fake banks, casino lookalikes and payment converters. The entry path—from a GitHub load-balancer reverse-IP through a split-architecture façade into two dense shared nodes—is fully documented in packet capture and tooling output. Shared nameservers and the saudeperfeita email domain tightly link the health-plan operators; co-tenancy alone does not extend that identity claim to the financial or gambling tenants. All observations remain within passive and light-active reconnaissance boundaries. Several high-value open items (full

registro.br

portfolio, qloud content recovery, von Langermann pivots) remain available for future passive work.

Complete Entity & Infrastructure Map

Entry / Origin

coindream.site

(bridge façade)

  • A: 140.82.116.3 (GitHub SEA LB)

  • NS: dns1/2.registrar-servers.com (Namecheap)

  • MX: Namecheap eforward

  • SPF: ip4:159.100.6.5 + MailChannels

  • Created 2026-01-23, privacy registrant (Withheld for Privacy ehf)

  • Forced Host on 159.100.6.5 previously returned cPanel defaultwebpage

UltaHost cp5 (159.100.6.5 /

cp5.fra1.ultacp.com

)

pro114.dnspro.com.br

(187.33.241.58)

  • Full stack: Pure-FTPd, PowerDNS, LiteSpeed, Dovecot, Exim, cPanel/WHM, Roundcube, MariaDB 10.11.18 public 3306

  • Host for

    onlinebradescosaude.com.br

    (left cp5); lower brand-abuse density (~500 BR SME tenants)

qloud /

shared.qloudhost.com

(45.87.42.74) – primary brand-abuse host

Identity cluster (FASSO283 primary)

Adjacent registrants (same farm / same NS)

saudeperfeita.com.br

(bridge site)

  • A: 162.241.2.92 (HostGator)

  • WP + Flatsome + FormCraft 3.8.7; users API open → admin (id=1), nildo (id=2)

  • Cotacao page authored by nildo; lead form (Nome/Tel/Celular/Email + honeypot)

  • Contacts:

    contato@agenciaunit.com

    , +55 11 96663-5659

Other

Public enrichment signals

  • vendasbradescosaude.com.br

    flagged phishing/malicious by OpenDNS, Cloudflare, DNS4EU (Mar 2026)

  • QloudHost markets Casino Web Hosting as product line (DMCA-ignored, crypto, privacy)

  • bridgecorebank.com

    low trust score, suspicious classification

  • No public evidence equating coindream operator or Williams Smith to Fabiola

Next
Next

Quantitative Security – Protective Intelligence / Threat Hunting Engagement