From a GitHub LB to a Multi-Year Brazilian Health-Plan Brand Farm: Infrastructure & Identity
Executive Summary
On 2026-08-07 a recon session (phone hotspot + QuantumGuard + packet capture) led from curiosity about a GitHub pull request to reverse-IP of GitHub’s Seattle load-balancer 140.82.116.3. That IP co-hosted
(web on GitHub, mail SPF pointing to UltaHost cp5 159.100.6.5). Reverse-IP and subsequent pivots revealed two dense shared-hosting environments: UltaHost cp5 (mixed tenants including a Shell Eastern Petroleum lookalike registered to Christian von Langermann) and especially qloudhost 45.87.42.74.
The qloud node hosted a multi-year (2017–2025) Brazilian “planos de saúde” sales farm using brand names Bradesco, Amil, Unimed and SulAmérica, offering 50–60 % first-month discounts. WHOIS attributes the core portfolio to Fabiola Silva Souza (FASSO283) using the email
. That email domain is a live HostGator-hosted brokerage-style WordPress site (
) owned by Roger Oliveira of Agência Unit, with tech contact and WP author Leonildo (“nildo”). Additional registrants Tiago Ferreira Pena and Leonildo share the same qloud nameservers. Public records confirm a matching CNPJ (Fabiola Silva Souza Seguros Ltda / Nf Seguros Saude, Mococa-SP, active since 2021).
The same qloud shared node also carried classic brand-abuse and typo-squatting content: fake online banks (
, registrant Williams Smith), casino registration pages, Paysafe/Neosurf converters, and various ticketmaster/kaiserpermanente-style stubs. QloudHost explicitly markets casino hosting.
(another Brazilian shared box) exposed a full mail/panel stack plus public MariaDB 10.11.18. UltaHost later filtered web ports; aggressive scanning rate-limited qloud 443.
The case is an identity-and-infrastructure map of a multi-year Brazilian health-plan sales/brand ecosystem entered via a GitHub reverse-IP curiosity, sitting on privacy/DMCA-ignored shared hosting that also densifies fake-bank and casino lookalikes. Shared NS and email domain link the health-plan operators; co-tenancy alone does not prove the financial/gambling tenants share the same operators. No credential attacks or exploit development were performed. Several items remain open (full
portfolio, qloud WP users while blackholed, von Langermann secondary pivots, original GitHub PR URL).
Passive reconnaissance on 2026-08-07 mapped a long-running “planos de saúde” sales cluster under Fabiola Silva Souza (FASSO283), a registered seguros company, shared nameservers, and a HostGator brokerage front—while the same qloud node densified fake banks, casino lookalikes, and payment converters. Entry was a reverse-IP curiosity during a recon session that began with a GitHub pull-request investigation.
Origin – The GitHub Edge
The operator and tools reached
(140.82.116.4) and the Seattle load-balancer hostname
lb-140-82-116-3-sea.github.com
(140.82.116.3). A reverse-IP lookup on 140.82.116.3 returned the expected GitHub marketing host plus an unexpected set of
and bakkta* subdomains (cpanel, webmail, mail, autodiscover,
,
, etc.).
ARIN confirmed the block as GITHU / GitHub, Inc. wget/curl of the LB hostname produced the standard 301 chain to
. Nmap fingerprints matched public GitHub behavior. The pcap later re-parse confirmed the origin trail—Grok, GitHub—while containing zero packets to the later case IPs 45.87.42.74, 159.100.6.5 or 187.33.241.58. The stated intent was investigation of a GitHub pull request; the PR URL itself was never supplied and remains an open, user-only item.
Pivot 1 –
(Split Architecture)
Live DNS for
showed:
A record (apex and all cPanel-style hostnames) → 140.82.116.3 (GitHub)
NS → dns1/dns2.registrar-servers.com (Namecheap BasicDNS)
MX → Namecheap eforward[1–5]
TXT/SPF → v=spf1 +a +mx +ip4:159.100.6.5 include:
~all
Created 2026-01-23, updated 2026-02-01, privacy registrant (Withheld for Privacy ehf, Iceland), clientTransferProhibited, DNSSEC unsigned.
The architecture is deliberately split: web presence on a GitHub edge that simply redirects to
, while mail authorization points at an UltaHost cPanel node. Forced Host:
against 159.100.6.5 (when web was still open) returned the classic 163-byte cPanel defaultwebpage meta-refresh. bakkta / bakktat / bakktatr naming is lookalike noise relative to the public Bakkt trading brand; no evidence of compromise of the legitimate entity was found.
Pivot 2 – UltaHost cp5 (159.100.6.5)
Reverse-IP of 159.100.6.5 returned approximately 500 hostnames and an early extract of ~78 unique apexes. Almost every tenant carried the full cPanel kit (cpanel., webmail., webdisk., cpcalendars., cpcontacts., mail., autodiscover.,
.). Early-session 80/443 were LiteSpeed open; by late-session nmap (18:50) they were filtered, leaving only 2082/2083 (OpenResty 1.31.1.1 cPanel) open. TLS certificates belonged to the
family (Let’s Encrypt). Unauthenticated paths on :2083 later returned a ~12 KB “One moment, please...” bot-check page with headless/bytespider challenges.
High-interest content harvested while HTTPS still answered included:
– Shell Eastern Petroleum template, Let’s Encrypt certificate, WHOIS registrant/tech Christian von Langermann (DURRAQ-R138206K / DURRAQ-T138206K), NS ns1/2/3.ultahost.com, A → 159.100.6.5.
and certificates.* – “KGC – Certificates” typo-commission theme.
– AR-style “verify before transfer” PHP application with PHPSESSID and CSP.
– “Gar T – Online Banking Platform”.
– Pin-Up casino clone (~169 kB body).
Various markets/trading and suspendedpage.cgi accounts.
– large unique body (~173 kB) in vhost ffuf.
Directory-listing Index of / on several tenants.
ffuf vhost run (Host: FUZZ @
, -fs 163) produced 202 hits: 147×200, 50×403 (shared deny), 4×302, 1×301. Size signatures cleanly separated cPanel login UI (~40 kB), service pages (~12 kB), and the large unique site.
Threat Nmap – Three IPs Side-by-Side
159.100.6.5 (cp5) – only 2082/2083 open (panel-only from this path).
187.33.241.58 (
) – full surface: Pure-FTPd 21, PowerDNS Auth 4.9.16 on 53, LiteSpeed 80/443, full Dovecot, Exim 4.99.5, cPanel/OpenResty, WHM (pt_br, whostmgrsession), Roundcube webmail, MariaDB 10.11.18 listening on public 3306 (banner 5.5.5-10.11.18-MariaDB-cll-lve). Hostname banners confirmed
. Reverse-IP showed ~500 Brazilian SME tenants (advocacia, shops, academias) with lower brand-abuse density than qloud. Panels later returned the same OpenResty bot wall.
45.87.42.74 (
) – Pure-FTPd, OpenSSH 8.0 (RHEL 8), BIND 9.11.36, LiteSpeed, DirectAdmin + Exim mail stack, MariaDB 10.6.27 (historically open), no external cPanel ports. This became the primary brand-abuse host.
Comparative surface at nmap time showed qloud and pro114 as full-stack boxes with public databases; cp5 had already retreated to panel-only.
The Qloud Brand-Abuse Farm (45.87.42.74)
Reverse-IP produced ~499 hostnames / ~207 apexes. A strict brand-abuse extraction listed 23 domains. Successful header/title harvest while 443 still answered revealed a coherent set of WordPress “X% Desconto” health-plan sales sites:
– “Plano de Saúde Bradesco Empresarial 60%”
– “Bradesco Saúde 60%” (~1.9 MB WP)
– same Bradesco theme
– Bradesco Dental from R$ 29,90
– Bradesco Saúde 50%
– Amil Brasília 50%
– SulAmérica 50%
planodesaudeempresariais.com.br
– Empresarial 60%
– Unimed 50%
– Sulamérica 50%
– compare planos
Adjacent non-health tenants on the identical shared node included
(fake online banking),
(casino registration),
and
(payment converters), plus numerous stubs and intermittent titles (casinoradar365, kaiserpermanenteinc, trustdigitalbank, produbancoecu, ticketmastercolombiaonline, neosurf-remboursement, etc.).
ffuf path discovery after failed autocalibration produced large volumes of soft-404 (200/words≈1498/size≈119xx or 500/2431/words=168). The operational lesson was explicit: after calibration failure, filter aggressively (-fw 1498 -fs 2431) and do not treat admin/phpMyAdmin/log paths as real. Aggressive scanning subsequently rate-limited / blackholed 45.87.42.74:443 for extended periods (QLOUD_DOWN), while DNS continued to point the brand domains at the IP. Live recon of the Fabiola sales sites therefore became blocked until cooldown.
QloudHost itself markets “Casino Web Hosting” as a product line—DMCA-ignored, crypto-friendly, privacy-focused, high-traffic gambling and betting platforms—providing an explicit commercial rationale for the density of casino and payment lookalikes observed on the same box.
Identity Investigation
Primary: FABIOLA SILVA SOUZA / FASSO283
Person: FABIOLA SILVA SOUZA
nic-hdl-br: FASSO283
Email:
CPF mask: *.809.878-
Handle created: 2017-07-21
NS for the sales portfolio: shared1/2.qloudhost.com
Confirmed owner domains (creation dates span 2017–2025):
(2017-03-17) – oldest Bradesco-named, long-running
(2017-07-11)
(2017-10-02)
(2021-01-26)
(2022-11-11)
(2023-05-31)
planodesaudeempresariais.com.br
(2025-02-13)
(2025-04-15)
(2025-04-29)
(2025-05-05)
CLI whois FASSO283 fails (“No whois server is known for this kind of object”). Full portfolio expansion requires the
web UI (still open item).
Public corporate records confirm a matching legal entity: Fabiola Silva Souza Seguros Ltda (nome fantasia Nf Seguros Saude), CNPJ 40.950.276/0001-55, opened 23 February 2021, active, address Rua Julio de Oliveira 199, Mococa-SP, capital R$50.000, CNAE for insurance/plan auxiliaries, sole administrador Fabiola Silva Souza. The CNPJ post-dates the oldest domains but supplies a formal corretora-style wrapper for the later portfolio.
Adjacent registrants on the same farm
LEONILDO QUINTILIANO / LEQUI21 /
owns
(2019, qloud NS) and appears as tech-c on
. Strong name match to the WordPress user “nildo” (id=2).
ROGER OLIVEIRA DA SILVA / ROOSI28 owns
(since 2010, HostGator ns918/919) and is associated with Agência Unit (
).
TIAGO FERREIRA PENA / TIFPE13 /
owns
(2025); handle carries a saci:yes flag in the
complaint system; same qloud NS.
– the identity bridge Hosted at 162.241.2.92 (HostGator), Apache, WordPress + Yoast 27.2, Flatsome theme, FormCraft 3.8.7 (form.min.js last-modified 2020). Login /wp-login.php returns 200 with wordpress_test_cookie; users API is open and returns:
id=1, slug admin – “admin, Autor em Plano de Saúde”
id=2, slug nildo – “nildo, Autor em Plano de Saúde”
Content is a full planos-de-saúde brokerage (São Cristóvão Saúde, Prevent Senior, Trasmontano, Amil logos, individual/family/elderly/pregnant/children/company plans, /valores-planos-de-saude/, /cotacao/). The cotacao page is authored by nildo; the FormCraft lead form captures Nome, Tel fixo, Celular, Email plus a honeypot. Public form REST namespaces are absent. Contacts recovered from the ecosystem include
and the WhatsApp number +55 11 96663-5659 (exact match to the live Agência Unit site). Agência Unit presents as a professional web/SEO agency with a public portfolio and privacy policy (CNPJ references 35.472.056/0001-10 / 15.702.183/0001-64 appear across pages).
Williams Smith /
Created 2026-02-24, registrar
, address 1020 SE Everett Mall Way, Everett WA 98208, country VI (privacy/proxy pattern). NS identical to the Fabiola qloud set. Same-host neighbors include trustdigitalbank, produbancoecu, ticketmastercolombiaonline and other payment-brand abuse domains. Public scanners give the domain a low trust score and classify it as suspicious; the title claims “Bridge Core Bank – Online Banking & Financial Services.” This is pure co-tenancy, not proven identity equivalence with Fabiola.
Christian von Langermann /shelleasternpetroleum.ae Registrant and technical contact of the Shell lookalike on Ultahost NS (early in the case). Confirmed A → 159.100.6.5. No secondary domains, email, phone, social or company filings were recovered in the available pass. The cluster remains partial and unlinked by identity to the Brazilian health-plan operators.
Attribution Model – What Is Strongly Supported vs. What Is Not Proven
Strongly supported:
Multi-year Brazilian domain portfolio under Fabiola Silva Souza using the saudeperfeita mailbox, hosted on qloud, marketing Bradesco/Amil/Unimed/SulAmérica discounts.
is a live brokerage-style site operated with admin/nildo, linked to Roger’s Agência Unit and Leonildo.
Shared industry + shared mail domain + shared hosting NS across multiple registrants constitutes an organized sales cluster.
Public CNPJ for Fabiola Silva Souza Seguros Ltda supplies a corporate wrapper.
The same qloud shared node densifies classic brand-abuse (fake banks, casino registration, payment converters); QloudHost markets casino hosting as a product.
GitHub LB / coindream is an entry artifact (possible mail SPF + web decoy); UltaHost/cp5 and qloud are where the abusive/sales content lived.
pro114 exposes a full mail/panel/MariaDB surface; qloud historically did likewise.
At least one core sales domain (
) has been classified phishing/malicious by major DNS filters (OpenDNS, Cloudflare, DNS4EU) while still resolving to the qloud IP.
Not proven:
Criminal intent versus aggressive (possibly non-compliant) affiliate marketing. Legal characterization is for investigators, ANS, registrars and counsel.
That Fabiola = nildo = Roger = Tiago (they are linked by infrastructure and contacts, not proven single person).
That Williams Smith or the casino/payment tenants are the same operators as Fabiola (same hoster and NS only).
Operational volume (traffic, leads closed, actual contracts).
Chronological Technical Timeline (Compressed)
boot / hotspot
+ reverse-IP of 140.82.116.3
coindream discovery → SPF pivot to 159.100.6.5
UltaHost reverse-IP (~500 hosts), headers, Shell WHOIS
cPanel bot-wall mapping
Threat nmap → pro114 + qloud full stacks + MariaDB exposure
Reverse-IP 187 + 45 → Bradesco farm on qloud
Live titles on qloud brands
Soft-404 ffuf lesson
Qloud rate-limit / blackhole
WHOIS identity → Fabiola / Leonildo / Tiago / Roger
saudeperfeita WP users + FormCraft / cotacao / author map
Agência Unit phone/email confirmation
Export package + rundown + open-items status
Public CNPJ and vendor-flag cross-reference
Technical Surface & Operational Observations
Public MariaDB on pro114 (live) and historically on qloud – documented for hardening/abuse reporting only; no authentication attempts.
OpenResty/Imunify-style bot walls and full-host blackholing after recon.
Soft-404 noise after failed ffuf calibration; size/word filters required.
CT reliability historically flaky (502s); one successful saudebradescobr dump (242 entries) recovered multi-label SANs and brand-adjacent names.
Tooling incidents during the session (NUL corruption in on_ip_now.txt, unbound variables under set -u, ffuf interactive pause) were noted and corrected in the working scripts.
Policy remains absolute: no credential attacks, no MySQL login, no exploit development.
Best Contacts & IOCs
PHONE: +55 11 96663-5659 (Agência Unit)
EMAIL : contato@agenciaunit.com
EMAIL : fabiola@saudeperfeita.com.br
EMAIL : leonildo_1@hotmail.com (+ WP nildo)
EMAIL: roger@agenciaunit.com
EMAIL : tiago.ferreira.pena@gmail.com
IP : 45.87.42.74
(brand farm + neighbors)
IP : 187.33.241.58
(cPanel full + MySQL)
IP : 159.100.6.5
(UltaHost; SPF/coindream)
IP : 162.241.2.92 HostGator (saudeperfeita)
IP: 140.82.116.3 GitHub SEA LB (entry)
SITE :
SITE :
WP: admin, nildo @ saudeperfeita
CNPJ : 40.950.276/0001-55 (Fabiola Silva Souza Seguros Ltda / Nf Seguros Saude)
Closing Assessment
The recon produced a high-resolution identity-and-infrastructure map of a multi-year Brazilian health-plan sales ecosystem that uses brand names of major operators, a registered seguros company, a HostGator brokerage front, and shared DMCA-ignored hosting that simultaneously densifies fake banks, casino lookalikes and payment converters. The entry path—from a GitHub load-balancer reverse-IP through a split-architecture façade into two dense shared nodes—is fully documented in packet capture and tooling output. Shared nameservers and the saudeperfeita email domain tightly link the health-plan operators; co-tenancy alone does not extend that identity claim to the financial or gambling tenants. All observations remain within passive and light-active reconnaissance boundaries. Several high-value open items (full
portfolio, qloud content recovery, von Langermann pivots) remain available for future passive work.
Complete Entity & Infrastructure Map
Entry / Origin
pcap,
(140.82.116.4),
lb-140-82-116-3-sea.github.com
(140.82.116.3),.
Reverse-IP 140.82.116.3 →
+ bakkta* subdomains + cPanel kit.
(bridge façade)
A: 140.82.116.3 (GitHub SEA LB)
NS: dns1/2.registrar-servers.com (Namecheap)
MX: Namecheap eforward
SPF: ip4:159.100.6.5 + MailChannels
Created 2026-01-23, privacy registrant (Withheld for Privacy ehf)
Forced Host on 159.100.6.5 previously returned cPanel defaultwebpage
UltaHost cp5 (159.100.6.5 /
)
~500 hostnames / ~78–395 live apexes
Early: 80/443 LiteSpeed open → later filtered; 2082/2083 OpenResty cPanel open; bot wall “One moment, please...”
High-interest:
(Christian von Langermann, DURRAQ IDs, Ultahost NS), gamingcomission,
,
,
, markets/trading,
, directory listings
(187.33.241.58)
Full stack: Pure-FTPd, PowerDNS, LiteSpeed, Dovecot, Exim, cPanel/WHM, Roundcube, MariaDB 10.11.18 public 3306
Host for
(left cp5); lower brand-abuse density (~500 BR SME tenants)
qloud /
(45.87.42.74) – primary brand-abuse host
Reverse-IP ~499 hostnames / ~207 apexes
Strict brand-abuse list: 23 domains
Live titles (when reachable):
,
,
,
,
,
,
,
planodesaudeempresariais.com.br
,
,
,
Adjacent abuse:
,
,
,
, casinoradar365, kaiserpermanenteinc stubs, trustdigitalbank, produbancoecu, ticketmastercolombiaonline, etc.
Historical: OpenSSH 8.0, BIND, LiteSpeed, DirectAdmin mail, MariaDB 10.6.27
Later: rate-limited / blackholed from recon path
Identity cluster (FASSO283 primary)
FABIOLA SILVA SOUZA / nic-hdl FASSO283 / email
/ CPF mask *.809.878- / handle created 2017-07-21
Domains (WHOIS-confirmed, all qloud NS):
(2017-03-17),
(2017-07-11),
(2017-10-02),
(2021-01-26),
(2022-11-11),
(2023-05-31),
planodesaudeempresariais.com.br
(2025-02-13),
(2025-04-15),
(2025-04-29),
(2025-05-05)
Public CNPJ: Fabiola Silva Souza Seguros Ltda (Nf Seguros Saude), 40.950.276/0001-55, Mococa-SP, opened 2021-02-23, active, capital R$50k
Adjacent registrants (same farm / same NS)
LEONILDO QUINTILIANO / LEQUI21 /
→
; tech-c on saudeperfeita; WP author “nildo”
ROGER OLIVEIRA DA SILVA / ROOSI28 /
→
(HostGator since 2010); Agência Unit
TIAGO FERREIRA PENA / TIFPE13 /
→
; saci:yes flag
(bridge site)
A: 162.241.2.92 (HostGator)
WP + Flatsome + FormCraft 3.8.7; users API open → admin (id=1), nildo (id=2)
Cotacao page authored by nildo; lead form (Nome/Tel/Celular/Email + honeypot)
Contacts:
, +55 11 96663-5659
Other
Williams Smith →
(same qloud NS, privacy/VI pattern, Everett WA address)
Christian von Langermann →
(Ultahost NS → cp5)
Public enrichment signals
flagged phishing/malicious by OpenDNS, Cloudflare, DNS4EU (Mar 2026)
QloudHost markets Casino Web Hosting as product line (DMCA-ignored, crypto, privacy)
low trust score, suspicious classification
No public evidence equating coindream operator or Williams Smith to Fabiola