From a residential firewall log to attributed infrastructure: QNAX, Tamatiya, Pfcloud, and TopDNS
Executive Summary
This engagement originated as a random pull of an AT&T residential gateway firewall log. The file contains 296 events across 26 minutes and 38 seconds. Unique addresses in the dump set: 188 (169 public). The internet did not suddenly notice this house. The gateway was sampled. Almost every packet in the file is the background radiation of a public IPv4 address: research census, DROP-listed spray, cheap-VPS VNC/Mirai, a Bulgarian bulletproof neighborhood, and ordinary Apple / Spotify / Mozilla sessions already on the LAN.
The 31 August cards already named QNAX, Recyber, Infrawatch, Xpanse, Censys, Pfcloud, and CHINANET. After the source files landed on 2 September those names were run through PTR, live headers, Spamhaus DROP, GreenSnow, AbuseIPDB public pages, and org-domain subfinder. Publicly available information was used only to cross-reference and background targets already present in the dump — the same enrichment path described for this series: noisy telemetry → attributed, prioritized, actionable infrastructure.
Three findings were not on the cards.
QNAX 45.140.193.187 hit the WAN ten times across 21 minutes. AbuseIPDB is 408 reports / 100% / 170 sources. OpenCanary and a mirai-detector logged VNC brute force on tcp/5900, RFB 003.008, security type 2. qnax.sh sells VPS, Cloud Linux, Windows Cloud “RDP rápido,” browser desktop, and console VNC for emergency access. The product they advertise is the protocol the honeypots logged.
First inbound in the file is Pfcloud DROP 176.65.149.233 at 11:58:25. That address sits in Spamhaus DROP 176.65.148.0/22. The same /22 still answers n8n.pfcloud.io on 176.65.148.168 (AbuseIPDB 12,088 historical reports, 0% current confidence, old VNC :5900/:5902). The provider’s own automation host lives inside a listing meant for “do not route.” sso.pfcloud.io returns X-Powered-By: authentik.
Tamatiya / 4vendeta spray from 79.124.58/49 and 78.128.114 includes 79.124.58.90, PTR ip-58-90.superbit.host. www.superbit.host CNAMEs onto Internet.bs urlforward.topdns.com, same DigitalOcean address as ns-usa.topdns.com. Subfinder on topdns.com produced 517 names. That set is a typo-squat and brand-collision surface (citrix, okta, sslvpn, awsdashboard, Schwab Advisor concatenations). Most labels answered NODATA this pass. Empty A is not a reason to drop them from a watchlist. The NS IPs must not be blocked..
Scope, clocks, and what this file is
This is not an incident that “happened at 11:58.”
Minute buckets stay busy the entire window — 6 to 18 events most minutes, 24 at 12:22. That is steady carpet, not a spike.
Story of the slice (dump-source only)
11:58:02 — log opens on link-local mDNS.
11:58:25 — first named DROP inbound: Pfcloud 176.65.149.233 → WAN, generic discard.
12:00:10–12:21:40 — loudest hostile: QNAX 45.140.193.187, 10 discards across 21 minutes.
12:01:49 / 12:14:08 / 12:23:31 — Recyber census 89.248.163.168.
12:03:30–12:15:55 — Tamatiya / 4vendeta / superbit spray on 78.128.114.* and 79.124.58/49.
Throughout — Infrawatch/Hydra, Cortex Xpanse, Censys, CriminalIP, CHINANET and residential noise. All discarded.
12:07:36 — Pfcloud DROP 204.76.203.7, later shown to sit in the same /24 as live protect2.pfcloud.io.
12:09:52 — LAN .77 in the firewall stream as Invalid IP Packet toward AWS. NAT (clockless) also has .77 to 34.221.227.255:2350 and Plex :8060.
12:24:23–37 — LAN .94, eight WAN-side management denies. Last named actor in the file.
12:24:40 — pull ends. Tools start after
High-risk dump sources — T1 HOSTILE
Six IPs. Block /32.
Same /24 as dump T1 is not subtle on AbuseIPDB. These are neighborhood reports, not a claim that the neighbor IPs were in this file:
79.124.58.142 — 19,314 / 100%
79.124.49.102 — 29,478 / 100% SSH / 8443
79.124.40.174 — 32,722 / 100% including Docker API :2375
78.128.114.166 — 12,071 / 100% same /24 as dump .46/.162
79.124.56.238 — 1,356 / 100% on the ops /24
79.124.56.162 — historical VNC 5900/5901
RIPE: Tamatiya EOOD, Sopot, Bulgaria. Downstream includes VENDETA4-LTD.
QNAX origin: dump prefix 45.140.192.0/23; origin panels 45.162.228/230, 209.14.68/70; control-node.qnax.app PTR rdp-10.qnax.com.br; live n8n.qnax.app, Chatwoot cw.qnax.app. Different prefix than the dump box. Same product line.
DROP co-residence — T2 / O3 Pfcloud
T2 is 22 IPs, Spamhaus DROP, never established. Highest-signal dump members:
176.65.149.233 at 11:58:25 — PTR *.ptr.pfcloud.network. Public card 2,133+ / 100%.
204.76.203.7 at 12:07:36 — same /24 as live protect2.pfcloud.io .4.
Remainder of T2 is Infrawatch members of DROP (*.infrawat.ch) plus Limited Network / Ghosty / Cloudie / TechTies / XIATIAN / Meowcore / SS-Net / FOP Danik. Inbound and discarded.
Pfcloud overlay on the same DROP /22 (176.65.148.0/22):
Same /22 is not quiet: .4 ~15,388 / 100%; .10 ~23,590; .173 ~10,237 / 100% still scanning late August. One address in the /22 is tagged Tor exit.
Census already discarded — T3 / T5
A log that only prints “China” or “scanner” is the wrong headline. Most of the 296 events are research census the gateway already dropped.
Do not panic-block T3 unless the goal is a quieter log.
Org headers after the dump — not inbound
Tamatiya / 4vendeta / Fibernet (O1)
Dump scanners live on customer /24s. Billing, KVM, Nagios, Cacti, and Mattermost live on .56/.59/.60 and 195.230.24/25. Same neighborhood. Different packets.
Do not merge Telepoint 78.128.42.0/24 into AS50360.
QNAX origin (O2)
control-node.qnax.app PTR rdp-10.qnax.com.br. Live n8n.qnax.app. Chatwoot cw.qnax.app. Prefixes 45.162.228/230, 209.14.68/70. Not the dump /23.
TopDNS / Internet.bs product (O5)
TopDNS — squat surface and Tamatiya FWD
Internet.bs default nameservers are ns-uk.topdns.com, ns-canada.topdns.com, ns-usa.topdns.com. ns-canada carries on the order of 31,000 customer zones. That is why subfinder topdns.com returned 517 names. Most of those names are glue and customer-zone leftovers, not a clone of www.topdns.com.
Dump bridge. T1 79.124.58.90 → ip-58-90.superbit.host → www.superbit.host CNAME urlforward.topdns.com on DigitalOcean 143.198.68.197 = ns-usa.topdns.com. A Bulgarian FWD box in the dump is parked on the registrar’s own urlforward product.
Typo-squat / brand-collision labels (most NODATA this pass — still published names):
Schwab glue: schwabadvisorcenns-canada.topdns.com plus dev. / magento. / store. variants. Cert-SAN smash: dns.l4x.orgns-uk.topdns.com.
www2.topdns.com itself is NODATA. The squat is the brand set plus Tamatiya-on-urlforward, not a live www2 clone. Do not block the NS IPs. Watch the labels for new A / AAAA.
LAN close — last 14 seconds were the house
NAT snapshot this.txt has no clock. Combined with the dump close:
Recon box was on a hotspot. LAN nmap was not run. Device identify is still open.
Versus the 31 August cards
Actions
Block /32 now
45.140.193.187
79.124.58.18
79.124.58.90
79.124.49.90
78.128.114.46
78.128.114.162
Optional org CIDRs
Tamatiya customer + ops: 79.124.58.0/24 79.124.49.0/24 78.128.114.0/24 79.124.56.0/24 79.124.59.0/24 79.124.60.0/24 195.230.24.0/24 195.230.25.0/24 Pfcloud: 176.65.148.0/22 204.76.203.0/24
Never
TopDNS NS and TMCH agent addresses. CriminalIP collectors. Cloudflare edges. T3 scanners unless the goal is a quieter log. Telepoint 78.128.42.0/24 is not Tamatiya ASN.
LAN
Identify .77, .94, .74. Treat WAN management exposure on the gateway as a separate finding from the inbound spray.
Watch
TopDNS brand labels for new A / AAAA. Pfcloud n8n.pfcloud.io if the /22 listing changes. QNAX origin prefixes if they ever appear on this WAN.
Abuse
abuse@qnax.com.br noc@4vendeta.com
What this relates to
This is the same pipeline described in the earlier Articles: large volumes of noisy telemetry — router logs, IP data, raw network observations — reduced to attributed, ranked targets. Public sources enter only after a dump IP already exists.
It also sits on a prior Tamatiya observation from the 24 July TLP:CLEAR protective-intelligence writeup (AS50360 as noisy Bulgarian hosting). This pass adds the dump /32s, the superbit → TopDNS FWD, the live headers on kvmrouter / Nagios / Cacti / Authentik, and the honest sensor-coverage fact: the inbound window closed two minutes before Quantum Guard’s menu.
What the cross-reference actually relates this to
Commodity IoT / remote-desktop abuse. QNAX sells VPS, Windows Cloud, RDP, and console VNC. The dump host 45.140.193.187 is independently reported as VNC :5900 brute and Mirai-family RFB. The /24 is a VPN-exit fabric (revhuntervpn / sockslite). That is the global VNC/Mirai background, riding a Brazilian host that markets the same protocols it is being reported for.
Bulgarian bulletproof neighborhood. Tamatiya EOOD AS50360 (4vendeta.com, Sopot / Sofia) is a long-running RIPE “OTHER” ASN with abuse at noc@4vendeta.com. Sibling /24s of the dump scanners are 10k–30k-report VNC/RDP/:2375 carpets. Behind them sit live KVM (login.php+PHPSESSID), Nagios Basic, Cacti cookies, Mattermost, Laravel 7.3 sensors, PHP 8.3 billing. Dump packets were the customer/VPS edge. The 2 September map is the DC.
DROP-listed hosting that still runs the provider’s own n8n. Pfcloud UG AS51396 puts looking glasses, Authentik SSO, protect panels, and n8n on space Spamhaus already lists. The dump’s first named inbound is one /22 neighbor of the live automation host. That is a policy finding about the hoster, not a unique packet to this house.
Internet census as a service. Recyber, Infrawatch/Hydra, Censys, Cortex Xpanse, CriminalIP, Recorded Future — all discarded, all expected on any public IPv4. Recyber 89.248.163.168 alone has 15k AbuseIPDB rows because every residential firewall on earth reports the same scanner.
Registrar NS as a squat telescope. TopDNS is not a threat actor in the dump. It is the Internet.bs default NS that Tamatiya FWD names already use, and it publishes a 517-name CT set that includes Schwab, Citrix, Okta, SSLVPN, and AWS-dashboard labels. That relates the case to brand collision and future phishing on registrar infrastructure, not to the 11:58 discards.
Local hygiene riding the same file. .94 WAN-mgmt denies and .77 on AWS :2350 + Plex would be in any random pull of this LAN. They are not caused by QNAX.
Quantitative Security