Brazilian Access Broker Targeting Latin America: Mapping BraZetsu Infrastructure Beyond the Published IOCs

Brazilian Access Broker Targeting Latin America: Mapping BraZetsu Infrastructure Beyond the Published IOCs

Published on

Disclosure note: Before publishing, we shared the new infrastructure identified in this research with the relevant national CERTs. This research did not recover victim data.


On 31 August 2026 Group-IB described BraZetsu, a Python framework for Windows compiled with Nuitka, and attributed it with high confidence to the Brazilian actor Exilware. The same paper ties the binary to the Infected Marketplace (Banco de Infects), a shop that inventories compromised Windows hosts and sells the access after a deposit of about $5.80 (BRL 30), settled through NowPayments.

The published network indicators are three Pastebin raw URLs, the hostnames c2.installscenter.com, infect.online and infectonline.store, and one IPv4 address: 38.242.246[.]176, a Contabo VPS already seen in the AgenteV2 lineage.

We didn't reverse the binary again. We took the published indicators and checked what our certificate inventory still shows. The premise is narrow. An operator who keeps a panel and a command channel under the same apex, with Let's Encrypt off port 443, leaves a more stable trail in the certificate inventory than the address of the month.

Key Observations

  • Published C2 hostname was live months earlier. The command hostname reported on 31 August, c2.installscenter[.]com, was already serving TLS on a second VPS (80.78.27[.]252) on port 2083 from 4 April 2026, almost five months before the disclosure.

  • Panel and C2 share one host. The same IP also presents painel.installscenter[.]com on ports 8083 and 8443, so a control panel hostname and the C2 hostname sit on the same apex and the same host. 8083 is the default Hestia Control Panel admin port; 8443 also matches the WebSocket port in the published sample analysis.

  • Seed IP switched to a Portuguese panel name. On 38.242.246[.]176 (Contabo), the certificate CN changed on 11 February, the same month the published reporting dates the first BraZetsu version. It went from the default Contabo hostname to a self-signed Hestia Control Panel certificate for painel.seu-dominio[.]com, a placeholder from Portuguese hosting tutorials, on the Hestia admin port 8083.

  • Repeated observations point to a long-running panel. Our inventory recorded painel.seu-dominio[.]com on the seed IP 17 times between 11 February and 17 March, every 2-4 days. That fits a panel left running, not a short-lived landing page.

  • Certificates existed before the move. CT logs show Let's Encrypt certificates for painel. and c2.installscenter[.]com issued on 21-22 March, about 13 days before our scans first saw them on the new IP. The c2 certificate was re-issued on 21 May.

  • C2 hostname moved behind Cloudflare. Passive DNS shows c2.installscenter[.]com on 80.78.27[.]252 between 22 and 26 March and on Cloudflare from 26 March on. The origin kept presenting the installscenter.com certificates to our scans until June.

  • Same operator habits, new provider. The cluster likely moved from Contabo (AS51167) to Njalla (AS39287). The seed IP went quiet on 20 March and the new host came up on 21 March, the day installscenter.com was registered and its first certificates were issued. Both ran the same Hestia Control Panel setup and used the painel. prefix. We rate operator continuity as medium.

  • Naming patterns outlast hashes. Hashes and Pastebin dead-drops rotated across five versions in four months. The painel. prefix on port 8083 held from February to June across both hosts, and four HuntSQL queries document the pattern.

Hunting the Certificates From the Seed IP

We ran four HuntSQL queries, starting from the published seed IP. The first two build its certificate timeline, the third expands by keyword, and the fourth profiles the new host.

What the queries returned

On the seed IP the inventory records two common names in sequence. From 4 January to 2 February 2026 the host presents the Contabo factory name vmi3003111.contaboserver.net, 80 observations. On 11 February, the same month the published reporting dates the first BraZetsu version, the CN became painel.seu-dominio.com. On 8083, and briefly on 443 from 11 to 13 February. Seventeen observations through 17 March, two to four days apart.

A lexical expansion on the CN, using tokens from the disclosure itself (installscenter, infectonline, inboxshop, caixaentrada) plus two terms from @akaclandestine's original query (nuevaprodeciencia, odaracani), which returned no rows, returns 80.78.27[.]252. On that address the inventory sees painel.installscenter.com on 8083 and 8443 and c2.installscenter.com on 2083. Earliest first-seen is 4 April, on port 2083, under the command hostname previous research had already named.

The PTR for 80.78.27[.]252 is 504e1bfc.host.njalla.net. The four octets in hex reproduce the label (50 4e 1b fc). Prefix 80.78.16.0/20 is announced by AS39287 (Materialism s.r.l.), netname NJALLA-AC-NET. A neighbour on the same /24, 80.78.27.237, resolves to 504e1bed.host.njalla.net, the same scheme. On crt.sh, checked on 26 September, painel.installscenter.com has Let's Encrypt R12 issuance on 21 March (notAfter 19 June, four certificates) and c2.installscenter.com has R13 from 22 March, with a re-issue on 21 May.

The hostname published in August was already speaking TLS on another VPS from early April. The panel took a name on the same apex. Port 8443, the WebSocket port in the sample analysis, appears on this second host under the panel CN.

What We Expected to Find

We went in with three expectations we could check against the certificate data. Attribution to Exilware is background here, not something this hunt tries to prove.

  • Panel and C2 on the same apex. If the malware finds its C2 through a Pastebin dead-drop and the shop needs a front end for buyers, installscenter.com should show up under both roles, panel and c2, on the same IP or on later ones, and not on port 443.

  • A panel that stays up. If the panel is a real shop and not a one-night landing page, its certificate should keep showing up over weeks, not hours.

  • Portuguese naming survives a move. If the operator changes VPS but keeps Portuguese naming, searching certificate names should find hosts that pivoting on the seed IP alone would miss.

How We Pivoted From the Seed IP

We ran the hunt in HuntSQL, our SQL interface over the certificate inventory and other scan data. We started from the public seed IP, built a timeline of the certificates it presented, grouped them by common name, and then widened the search by keyword to find new hosts. For each new IP we checked ASN, reverse DNS and Certificate Transparency logs.

A common name made it into our findings only if it passed two of three checks: it matches a reported hostname, it sits on the same IP as a published hostname in the same time window, or it uses a port already tied to the cluster (8083 on the seed IP, which is also the Hestia admin port, or 8443 from the sample analysis). Keywords that returned no rows stayed on the watchlist.

Query 1

We pulled every certificate our inventory recorded on the seed IP, 38.242.246[.]176, since 1 January 2026, newest first. This gives the raw timeline: which common names the host presented, on which ports, and when.

SELECT timestamp, ip, port, subject.common_name, issuer.organization
FROM certificates
WHERE ip == '38.242.246.176'
  AND timestamp.day gt '2026-01-01'
ORDER BY timestamp DESC
LIMIT 500;

                
Copy

Output example:

Figure 1. HuntSQL on 38.242.246[.]176 from 1 January 2026.


Query 2

Same IP, same window, but grouped by common name. For each CN we get the first and last time we saw it and how many times it showed up. This is where the switch from the Contabo default hostname to painel.seu-dominio.com shows up.

SELECT subject.common_name,
      min(timestamp) AS first_seen,
      max(timestamp) AS last_seen,
      count(*) AS cert_count
FROM certificates
WHERE ip == '38.242.246.176'
  AND timestamp.day gt '2026-01-01'
GROUP BY subject.common_name
ORDER BY cert_count DESC
LIMIT 200;

                
Copy

Output example:

Figure 2. Aggregation by subject.common_name on the same IP.

Query 3

Here we left the seed IP and searched the last 180 days of certificates for common names containing tokens from the disclosure (installscenter, infectonline, inboxshop, caixaentrada), matched case-insensitive with a regex. This is the query that returned 80.78.27[.]252.

SELECT ip, port, subject.common_name, issuer.organization, timestamp
FROM certificates
WHERE timestamp > NOW - 180 DAY
  AND subject.common_name RLIKE
    '(?i)(infectonline|installscenter|inboxshop|caixaentrada|nuevaprodeciencia|odaracani)'
LIMIT 200;

                
Copy

Output example:

Figure 3. RLIKE expansion. Cut: 80.78.27[.]252, painel.installscenter.com, port 8083, June 2026. Card by @akaclandestine, 5 September.

Query 4

With the new IP in hand, we grouped every certificate on 80.78.27[.]252 by port, common name and issuer, with first and last seen for each combination. That gives three rows: the panel on 8083 and 8443, and the c2 hostname on 2083.

SELECT
  ip,
  port,
  subject.common_name,
  issuer.organization,
  min(timestamp) AS first_seen,
  max(timestamp) AS last_seen
FROM
  certificates
WHERE
  ip == '80.78.27.252'
  AND timestamp.day gt '2026-03-01'
GROUP BY
  ip, port, subject.common_name, issuer.organization

                
Copy

Output example:

Figure 4. Three tuples on 80.78.27[.]252. Earliest first-seen: 4 April 2026.

We ran these queries on 5 September. We haven't seen these certificates on 80.78.27[.]252 in the last 30 days, so running Query 4 with a short time window today may return nothing.

BraZetsu Background: What Was Already Public

BraZetsu is the name Group-IB gave the framework. Their report describes five generations between February and May 2026, Portuguese debug strings, and the shift from a RAT with Run key MonitorSystem (v1) to an IAB platform with 27 functions, most of them enumeration (v5). The count is in the paper and in their 1 September post.

Attribution to Exilware, in the source text, rests on C2 overlap with the shop login panel, reuse of 38.242.246[.]176 with AgenteV2, the Pastebin XOR dead-drop, and distribution filenames (msedge[0-9].exe, wifi_driver.exe). The published reporting rates this attribution as high confidence. We take it as a starting point, not something this hunt tests.

The model described is an initial-access broker. The agent profiles ERP (TOTVS, SAP, Senior, Conta Azul, Sankhya), SCADA traces (WinCC, RSLogix, FactoryTalk), EDR, .pfx/.p12 certificates and CNAB files, and returns a dossier. The buyer drops the payload. The paper describes the scope as Latin America and the Iberian Peninsula, but its evidence points mainly to Brazil, with v2 also targeting Mercado Libre and Mercado Pago domains in Argentina, Mexico and Chile. In April the shop advertised two hosts in the United States; the paper treats that as insufficient to call a change of theatre.

C2 is not hardcoded in the binary. get_server_config() fetches a Pastebin blob, Base64-decodes it and XOR-decrypts with p4st3_s3cr3t_k3y. The result is domain|port|token. The live channel is WebSocket over TLS on 8443. Published raw IDs: aF0WCxia, hM0nXNBP, 9ChwVzzw.

IndicatorRole in the source text
hxxps://pastebin[.]com/raw/aF0WCxiaDead-drop
hxxps://pastebin[.]com/raw/hM0nXNBPDead-drop
hxxps://pastebin[.]com/raw/9ChwVzzwDead-drop
c2[.]installscenter[.]comCommand; link to the shop panel
infectonline[.]storeDomain tied to the shop
infect[.]onlineOlder shop infrastructure
38[.]242[.]246[.]176Contabo VPS; AgenteV2 overlap

The report's IOC section also lists sixteen SHA-256 hashes, and the body names caixaentradas1inboxshop.site, port 8443, the XOR key and the Run key. They enter the detection pack. They did not go through HuntSQL: the inventory does not see hashes or Pastebin.

80.78.27[.]252, painel.installscenter.com, painel.seu-dominio.com and ports 8083 and 2083 are not on the original report's list. We found them in this hunt.

Infrastructure by Role and Confidence

ArtifactObservationRoleConf.
38.242.246[.]176Seed IP; two CNs in Q1Panel Q1High
painel.seu-dominio.com17 hits, 11 Feb - 17 Mar, :8083PanelMedium
80.78.27[.]252Three tuples from 4 AprPanel + C2 Q2High
c2.installscenter.comSeed hostname on :2083C2High
painel.installscenter.comSame apex, :8083 and :8443PanelHigh

The seed IP: from a Contabo default to a Portuguese panel name

Grouping the certificates on 38.242.246[.]176 by common name (Query 2) returns two CNs, one after the other, with no overlap.

Figure 5. Two CNs on the seed IP.

The first is vmi3003111.contaboserver.net, the default hostname Contabo assigns to its VPS. We saw it 80 times between 4 January and 2 February, which points to continuous TLS service on the host.

On 11 February the CN changed to painel.seu-dominio.com, on port 8083. "Seu domínio" is Portuguese for "your domain", the placeholder used in Portuguese-language hosting tutorials. We saw it 17 times through 17 March.

Figure 6. painel.seu-dominio.com on 8083, 18 February to 17 March.

The Figure 6 series (17 Mar, 14 Mar, 11 Mar, 8 Mar, 4 Mar, 1 Mar, 26 Feb twice, 22 Feb, 18 Feb) fits a panel left running, not a short-lived landing page.

On this IP, in this cut, the inventory does not return c2.installscenter.com. Two readings fit. The Contabo VPS hosted the panel (and, according to the published reporting, infect.online before that) while the named C2 had already left. Or C2 on this IP used a certificate whose CN does not carry "c2". The table does not decide. What it does show: from mid-February this address presents a Hestia Control Panel certificate with a Portuguese placeholder name on 8083, the same panel setup the second host runs later.

The new host: panel and C2 on 80.78.27[.]252

Query 3 is what took the hunt off the seed IP. Searching certificate common names for tokens from the disclosure returned 80.78.27[.]252, presenting painel.installscenter.com on port 8083 with a Let's Encrypt certificate on 9, 10 and 12 June (Figure 3).

The interface didn't return a total count for that query, so there may be more matches over the 180-day window than the page we captured.

Grouping every certificate on that IP by port and CN (Query 4) returns three combinations:

IPPortCNfirst_seen
80.78.27[.]2528083painel.installscenter.com2026-05-16 09:41:30
80.78.27[.]2528443painel.installscenter.com2026-04-06 23:14:31
80.78.27[.]2522083c2.installscenter.com2026-04-04 05:32:39

c2.installscenter.com is the C2 hostname from the published reporting. Finding it on a different IP means the name moved to a new address, which fits what was published and doesn't contradict it.

What's new is painel.installscenter.com on the same IP and the same apex. It puts a Hestia Control Panel hostname and the C2 hostname side by side on one host. The ports are split by role too: 2083 under the c2 name, 8083 and 8443 under the panel name. 8443 matches the WebSocket port from the sample analysis.

Our SSL history on the IP shows two different certificates for the c2 hostname on 2083: the first, issued by Let's Encrypt R13 on 22 March, was seen from 4 April to 17 May. The second, issued on 21 May, was seen from 22 May to 4 June. The panel presented a single certificate on 8083 and 8443, seen from 6 April to 18 June.

Figure 7. SSL history on 80.78.27[.]252: two c2 certificates on 2083, one panel certificate on 8083 and 8443.

Pivot on 80.78.27[.]252

FieldValue
IPv480.78.27[.]252
PTR504e1bfc.host.njalla.net
ASNAS39287 - Materialism s.r.l.
Prefix80.78.16.0/20 (NJALLA-AC-NET)
Announced geo of the blockSweden
/24 gateway80.78.27.1 - r.njalla.net

Njalla is a privacy-focused hosting provider. The reverse DNS name, 504e1bfc.host.njalla.net, is just the IP written in hex (50 4e 1b fc), and every host in the block gets one built the same way. It doesn't tell us anything specific about this server.

The same goes for the provider. Landing on Njalla tells us what kind of hosting the operator chose, not who the operator is.

CT identityIssuernotBefore
painel.installscenter.comLet's Encrypt R122026-03-21 (notAfter 2026-06-19)
c2.installscenter.comLet's Encrypt R132026-03-22 (re-issue 2026-05-21)

The c2 certificate was issued about 13 days before our scans first saw it on this IP.

WHOIS records the creation of installscenter.com on 21 March 2026, through Tucows. The hostname resolves to Cloudflare today.

Figure 8. Domain summary for c2.installscenter.com, with the apex registered on 21 March.

Why the IP wasn't on the published list

Passive DNS helps explain it. Our records show c2.installscenter[.]com resolving to 80.78.27[.]252 between 22 and 26 March, and to Cloudflare (104.21.78.246, 172.67.138.224) from 26 March on. The only A record we have for painel.installscenter[.]com is Cloudflare, from 21 March.

Figure 9. A record history for c2.installscenter.com: four days on 80.78.27[.]252, then Cloudflare. The passive DNS source labels the origin's hosting as "ab stract"; our IP record places 80.78.27[.]252 in AS39287 (Materialism s.r.l.).

From late March, resolving these names returned Cloudflare addresses. The origin IP kept presenting the installscenter.com certificates to our scans until June.

2083 and 8443 are on Cloudflare's list of proxied HTTPS ports; 8083 is not. That is consistent with C2 and the WebSocket channel going through Cloudflare while the Hestia admin port was reached directly. We didn't observe the agent's traffic, so this is a reading of the port choice, not a finding.

Timeline

Dates combine our scan data, CT logs and the published reporting.

DateHostEvent
4 Jan 202638.242.246[.]176Contabo default certificate (vmi3003111.contaboserver.net)
4 Feb38.242.246[.]176SSH host key changes
Febn/aFirst BraZetsu version, per the published reporting
11 Feb38.242.246[.]176Hestia certificate painel.seu-dominio.com appears, on 8083
17 Mar38.242.246[.]176Last observation of painel.seu-dominio.com
20 Mar38.242.246[.]176Host goes quiet on 443
21 Marn/ainstallscenter.com registered (Tucows)
21-22 MarCT logsLet's Encrypt certificates issued for painel. and c2.installscenter.com
21 Mar80.78.27[.]252New host comes up on 443 (Njalla, AS39287)
22 MarDNSc2.installscenter.com resolves to 80.78.27[.]252
26 MarDNSc2.installscenter.com moves behind Cloudflare
30 Mar80.78.27[.]252SSH key set first seen
4 Apr80.78.27[.]252c2.installscenter.com on 2083
6 Apr80.78.27[.]252painel.installscenter.com on 8443
16 May80.78.27[.]252painel.installscenter.com on 8083
21 MayCT logsc2.installscenter.com certificate re-issued
16-20 Jun80.78.27[.]252All TLS ports go quiet
20 Jun80.78.27[.]252SSH key set last seen
24 Jul80.78.27[.]252Different SSH key appears
31 Augn/aGroup-IB publishes BraZetsu
5 Sepn/aHuntSQL queries shared by @akaclandestine
2 OctCT logsLatest wildcard certificate for *.installscenter.com

80.78.27[.]252 does not resolve caixaentradas1inboxshop.site. That delivery domain sits in the body of the paper and belongs to another phase of the chain (the report links it to an Ousaban sample delivered from the same domain). It is also not the historical A record of infect.online; previous research places that role on 38.242.246[.]176. Our scan history shows this IP was used by others before, including a 2024 certificate unrelated to this cluster. The operator window runs from 21 March to 20 June, and all TLS ports went quiet between 16 and 20 June.

SSH host keys follow the same window. One key set is first seen on 30 March and last seen on 20 June, the day the TLS services went quiet. A different key set appears from 24 July. We can't tie these keys to an operator; the overlap in dates is the only link.

On the seed IP the host key changed on 4 February and that key was last seen on 20 March. The Contabo default certificate was already served on 8083 and 8443 in January, so the Hestia setup predates that change.

Figure 10. SSH key history on 80.78.27[.]252. The key set seen from 30 March to 20 June matches the operator window.

Today the IP serves an nginx Laravel login on port 80 and a different SSH key. We see no installscenter.com certificates on it.

Figure 11. Current state of 80.78.27[.]252.

Operational reading, medium confidence: the cluster likely left a Contabo VPS already described in public reporting for a Njalla VPS, kept the same Hestia Control Panel setup, and gave the panel a name on the same apex as the C2 instead of the seu-dominio.com placeholder. That does not identify the operator, does not assign the whole /24 to the shop, and does not claim a marketplace code change.

Why the Hostnames Outlast the Binaries

BraZetsu changed its version. Five generations in four months. The binary changes, the hash changes, the Pastebin drop can be swapped in a commit. What does not change at the same rate is the name the buyer uses to reach the panel and the name the agent uses to reach the server. Those names need a certificate.

The buyer needs a URL that still exists the next day. The agent needs a hostname the dead-drop still points at. Both incentives push toward apex reuse. Rotation stays on the IPv4. That is what Figures 5 and 4 show in sequence.

painel.seu-dominio.com is the self-signed certificate Hestia Control Panel generated for the hostname set at install, likely copied from a Portuguese tutorial. Seventeen observations on the same IP suggest the panel stayed up for weeks. Query 3, in the photographed cut, did not return it to another address. It remains a hunt clause. It is not proof of migration.

TokenLayerStatus
installscenterC2 and panelTelemetry and seed
infectonline / infect.onlineShopSeed; no CN in the tables
inboxshop / caixaentradaDeliveryNarrative seed
nuevaprodeciencia / odaracaniOperational regexNo row - watchlist
painel.PrefixTwo apexes, same 8083
c2.PrefixOne apex, 2083 in this cut

The arrow between painel.seu-dominio.com and installscenter.com is habit plus sequence. It is not a shared certificate.

The shop sells the foothold. Ransomware, banking fraud, CNAB remittance rewriting and stolen A1-certificate use can be run by someone who never touched the BraZetsu code. v5 profiles EDR: the incentive is to avoid the already-monitored machine. The two U.S. hosts in April do not authorize writing that the victim perimeter matches the operator's language. They also do not authorize declaring a change of theatre.

Limitations

  • We didn't access the panels, so we have no page content from ports 8083 or 8443.

  • The certificates on both hosts share a JA4X, but it's the generic Let's Encrypt profile, so it doesn't link them. The pivot view shows why: the JA4X value has a count of about 13 million, and the R12 and R13 issuers counts in the hundreds of thousands. Both hosts also share JARM fingerprints on 8083 and 8443, which points to the same Hestia Control Panel setup, not necessarily the same operator.

Figure 12. Pivots on 80.78.27[.]252. Generic fingerprints with very high counts.

Indicators of Compromise

Defanged. Table 1 is the seed from the published reporting. Table 2 is what our inventory added. Table 3 and the sample hashes come from the body of the report.

Table 1: Seed (published indicators)

TypeValue
IPv438.242.246[.]176
Hostc2.installscenter[.]com
Hostinfect[.]online
Hostinfectonline[.]store
URLhxxps://pastebin[.]com/raw/aF0WCxia
URLhxxps://pastebin[.]com/raw/hM0nXNBP
URLhxxps://pastebin[.]com/raw/9ChwVzzw

Table 2: Added by our inventory

TypeValueNote
IPv480.78.27[.]252C2 hostname + Hestia panel, 4 Apr to 20 Jun. Different service and SSH key since July; check before blocking
Hostpainel.installscenter[.]com8083 and 8443
Hostpainel.seu-dominio[.]comCertificate CN only, placeholder name. Do not block as a domain
Cert SHA-2560C65D06ECD5A4BCD214128CC5AE2FD48F449A7B0E4002C6F0E127486B90DF1B5c2.installscenter[.]com, :2083, 4 Apr to 17 May
Cert SHA-256731F269E44E3372E214E48EBAF0A05A892E914422A1FA664FB25A0FE2200528Ac2.installscenter[.]com, :2083, 22 May to 4 Jun
Cert SHA-256473ADE701A602A14D50A869762DF72D1A1CA7CD395BF26B9E090D9116A447726painel.installscenter[.]com, :8083 and :8443
Cert SHA-256AB5C83564A38A035819A601E2E2F40C4AD07D0C12625BBB196AB4E915B087F86painel.seu-dominio[.]com, seed IP
Port8083 / 2083 / 8443Panel / C2 / panel and WebSocket

Table 3: From the report body

TypeValue
Hostcaixaentradas1inboxshop[.]site
Filenamemsedge[0-9].exe (e.g. msedge04.exe), wifi_driver.exe, temp_agente.dll
v1 persistenceHKCU Run \ MonitorSystem
XORp4st3_s3cr3t_k3y
Sample hashes (SHA-256, from the published reporting)
f775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17
54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700
91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0
cd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78
d881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99
0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf
1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246
96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042
0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d
30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe
10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c
bc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8
93bb4a4812e77ddc17c2722340d915bd5c8387316bbdbc394c201a28cb9b7c88
67fcfbdaab397ad1273135a3c6aa1d220ab76491cf945df081503401cc9732d2
c4dd46e5b450349fd9fbf686a5a22f55f8371123b098104db663a3980646e138
3f2f48525cf082672e38808480e214775e03dd943ff2df86172665aad96a5eaa

MITRE ATT&CK Mapping and Detection

TacticTechniqueID
Resource DevelopmentVPS / Domains / MalwareT1583.003 / T1583.001 / T1588.001
Initial AccessUnknown (social engineering suspected in the published reporting)n/a
Execution / PersistenceInterpreter / Run keyT1059 / T1547.001
Defense EvasionObfuscated / MasqueradingT1027 / T1036
Credential AccessPrivate KeysT1552.004
Discovery / CollectionSoftware, browser, screenT1518 / T1217 / T1113
Command and ControlWebSocket, TLS, dead-dropT1071.001 / T1573 / T1102.001
ExfiltrationOver C2 ChannelT1041

Hashes from this cluster changed across five versions in four months, so they won't hold for long. What held from February to June was the naming and hosting pattern: a painel. or c2. prefix, a non-standard port, a Hestia Control Panel setup on a VPS, and sometimes a request to pastebin.com/raw/ right before.

The logic below is generic. Adapt the field names to your SIEM.

dns.qname in {c2.installscenter.com, painel.installscenter.com,
              infect.online, infectonline.store}
or dest.ip in {38.242.246.176, 80.78.27.252}
or (dest.port in {2083, 8083, 8443}
    and dest.asn in {51167, 39287}
    and (tls.sni startswith "painel." or tls.sni startswith "c2."))

                
Copy

Hestia Control Panel uses 8083 as its admin port by default, and many legitimate Portuguese-language servers name it painel.*. Expect false positives on the SNI condition and review hits before blocking.

Since late March c2.installscenter.com resolves to Cloudflare, so connections through it go to Cloudflare addresses (AS13335). The ASN condition only catches direct connections to the origin; the hostname and SNI conditions still apply.

Network and hunting

  • Re-run Query 3 weekly and alert on any new painel.* or c2.* certificate on ports 2083, 8083 or 8443.

  • Pivot on the installscenter.com certificate hashes in the IOC table to look for other hosts.

  • Add IPs to blocklists with a first-seen date and a review date. This infrastructure rotates.

Endpoint

  • Look for unsigned executables compiled with Nuitka, Chromium History files copied into %TEMP%, enumeration of .pfx files, and a Run key value named MonitorSystem.

If you get a hit

  • Isolate the host and preserve %TEMP% and the Run key before cleanup.

  • Assume the access may already have been sold, and check for follow-on activity from other actors.

Conclusion

The public reporting gave us three things to work from: the C2 hostname, the IP tied to it early in the year, and the shop both of them served. Our certificate inventory showed what happened to that hostname after the first VPS went quiet. It showed up on a new host in a different provider, with a control panel on the same apex.

The TLS services on 80.78.27[.]252 went quiet after 20 June. The pattern is more stable: a painel. or c2. prefix on a port that isn't 443, on a VPS running Hestia Control Panel. It held from February to June across two providers, and that's what we'd build detection on, not the IP.

CT logs show wildcard certificates for *.installscenter.com from Let's Encrypt and Google Trust Services, the latest issued on 2 October. With Cloudflare nameservers on the domain, that is consistent with the zone still being active on Cloudflare. It doesn't show the C2 is live, but the hostnames are worth keeping on blocklists.

If you want to run these queries against your own seeds, or set up alerts for new painel.* and c2.* certificates on those ports, book a demo and we'll walk through the HuntSQL workflow with your team.

Disclosure note: Before publishing, we shared the new infrastructure identified in this research with the relevant national CERTs. This research did not recover victim data.


On 31 August 2026 Group-IB described BraZetsu, a Python framework for Windows compiled with Nuitka, and attributed it with high confidence to the Brazilian actor Exilware. The same paper ties the binary to the Infected Marketplace (Banco de Infects), a shop that inventories compromised Windows hosts and sells the access after a deposit of about $5.80 (BRL 30), settled through NowPayments.

The published network indicators are three Pastebin raw URLs, the hostnames c2.installscenter.com, infect.online and infectonline.store, and one IPv4 address: 38.242.246[.]176, a Contabo VPS already seen in the AgenteV2 lineage.

We didn't reverse the binary again. We took the published indicators and checked what our certificate inventory still shows. The premise is narrow. An operator who keeps a panel and a command channel under the same apex, with Let's Encrypt off port 443, leaves a more stable trail in the certificate inventory than the address of the month.

Key Observations

  • Published C2 hostname was live months earlier. The command hostname reported on 31 August, c2.installscenter[.]com, was already serving TLS on a second VPS (80.78.27[.]252) on port 2083 from 4 April 2026, almost five months before the disclosure.

  • Panel and C2 share one host. The same IP also presents painel.installscenter[.]com on ports 8083 and 8443, so a control panel hostname and the C2 hostname sit on the same apex and the same host. 8083 is the default Hestia Control Panel admin port; 8443 also matches the WebSocket port in the published sample analysis.

  • Seed IP switched to a Portuguese panel name. On 38.242.246[.]176 (Contabo), the certificate CN changed on 11 February, the same month the published reporting dates the first BraZetsu version. It went from the default Contabo hostname to a self-signed Hestia Control Panel certificate for painel.seu-dominio[.]com, a placeholder from Portuguese hosting tutorials, on the Hestia admin port 8083.

  • Repeated observations point to a long-running panel. Our inventory recorded painel.seu-dominio[.]com on the seed IP 17 times between 11 February and 17 March, every 2-4 days. That fits a panel left running, not a short-lived landing page.

  • Certificates existed before the move. CT logs show Let's Encrypt certificates for painel. and c2.installscenter[.]com issued on 21-22 March, about 13 days before our scans first saw them on the new IP. The c2 certificate was re-issued on 21 May.

  • C2 hostname moved behind Cloudflare. Passive DNS shows c2.installscenter[.]com on 80.78.27[.]252 between 22 and 26 March and on Cloudflare from 26 March on. The origin kept presenting the installscenter.com certificates to our scans until June.

  • Same operator habits, new provider. The cluster likely moved from Contabo (AS51167) to Njalla (AS39287). The seed IP went quiet on 20 March and the new host came up on 21 March, the day installscenter.com was registered and its first certificates were issued. Both ran the same Hestia Control Panel setup and used the painel. prefix. We rate operator continuity as medium.

  • Naming patterns outlast hashes. Hashes and Pastebin dead-drops rotated across five versions in four months. The painel. prefix on port 8083 held from February to June across both hosts, and four HuntSQL queries document the pattern.

Hunting the Certificates From the Seed IP

We ran four HuntSQL queries, starting from the published seed IP. The first two build its certificate timeline, the third expands by keyword, and the fourth profiles the new host.

What the queries returned

On the seed IP the inventory records two common names in sequence. From 4 January to 2 February 2026 the host presents the Contabo factory name vmi3003111.contaboserver.net, 80 observations. On 11 February, the same month the published reporting dates the first BraZetsu version, the CN became painel.seu-dominio.com. On 8083, and briefly on 443 from 11 to 13 February. Seventeen observations through 17 March, two to four days apart.

A lexical expansion on the CN, using tokens from the disclosure itself (installscenter, infectonline, inboxshop, caixaentrada) plus two terms from @akaclandestine's original query (nuevaprodeciencia, odaracani), which returned no rows, returns 80.78.27[.]252. On that address the inventory sees painel.installscenter.com on 8083 and 8443 and c2.installscenter.com on 2083. Earliest first-seen is 4 April, on port 2083, under the command hostname previous research had already named.

The PTR for 80.78.27[.]252 is 504e1bfc.host.njalla.net. The four octets in hex reproduce the label (50 4e 1b fc). Prefix 80.78.16.0/20 is announced by AS39287 (Materialism s.r.l.), netname NJALLA-AC-NET. A neighbour on the same /24, 80.78.27.237, resolves to 504e1bed.host.njalla.net, the same scheme. On crt.sh, checked on 26 September, painel.installscenter.com has Let's Encrypt R12 issuance on 21 March (notAfter 19 June, four certificates) and c2.installscenter.com has R13 from 22 March, with a re-issue on 21 May.

The hostname published in August was already speaking TLS on another VPS from early April. The panel took a name on the same apex. Port 8443, the WebSocket port in the sample analysis, appears on this second host under the panel CN.

What We Expected to Find

We went in with three expectations we could check against the certificate data. Attribution to Exilware is background here, not something this hunt tries to prove.

  • Panel and C2 on the same apex. If the malware finds its C2 through a Pastebin dead-drop and the shop needs a front end for buyers, installscenter.com should show up under both roles, panel and c2, on the same IP or on later ones, and not on port 443.

  • A panel that stays up. If the panel is a real shop and not a one-night landing page, its certificate should keep showing up over weeks, not hours.

  • Portuguese naming survives a move. If the operator changes VPS but keeps Portuguese naming, searching certificate names should find hosts that pivoting on the seed IP alone would miss.

How We Pivoted From the Seed IP

We ran the hunt in HuntSQL, our SQL interface over the certificate inventory and other scan data. We started from the public seed IP, built a timeline of the certificates it presented, grouped them by common name, and then widened the search by keyword to find new hosts. For each new IP we checked ASN, reverse DNS and Certificate Transparency logs.

A common name made it into our findings only if it passed two of three checks: it matches a reported hostname, it sits on the same IP as a published hostname in the same time window, or it uses a port already tied to the cluster (8083 on the seed IP, which is also the Hestia admin port, or 8443 from the sample analysis). Keywords that returned no rows stayed on the watchlist.

Query 1

We pulled every certificate our inventory recorded on the seed IP, 38.242.246[.]176, since 1 January 2026, newest first. This gives the raw timeline: which common names the host presented, on which ports, and when.

SELECT timestamp, ip, port, subject.common_name, issuer.organization
FROM certificates
WHERE ip == '38.242.246.176'
  AND timestamp.day gt '2026-01-01'
ORDER BY timestamp DESC
LIMIT 500;

                
Copy

Output example:

Figure 1. HuntSQL on 38.242.246[.]176 from 1 January 2026.


Query 2

Same IP, same window, but grouped by common name. For each CN we get the first and last time we saw it and how many times it showed up. This is where the switch from the Contabo default hostname to painel.seu-dominio.com shows up.

SELECT subject.common_name,
      min(timestamp) AS first_seen,
      max(timestamp) AS last_seen,
      count(*) AS cert_count
FROM certificates
WHERE ip == '38.242.246.176'
  AND timestamp.day gt '2026-01-01'
GROUP BY subject.common_name
ORDER BY cert_count DESC
LIMIT 200;

                
Copy

Output example:

Figure 2. Aggregation by subject.common_name on the same IP.

Query 3

Here we left the seed IP and searched the last 180 days of certificates for common names containing tokens from the disclosure (installscenter, infectonline, inboxshop, caixaentrada), matched case-insensitive with a regex. This is the query that returned 80.78.27[.]252.

SELECT ip, port, subject.common_name, issuer.organization, timestamp
FROM certificates
WHERE timestamp > NOW - 180 DAY
  AND subject.common_name RLIKE
    '(?i)(infectonline|installscenter|inboxshop|caixaentrada|nuevaprodeciencia|odaracani)'
LIMIT 200;

                
Copy

Output example:

Figure 3. RLIKE expansion. Cut: 80.78.27[.]252, painel.installscenter.com, port 8083, June 2026. Card by @akaclandestine, 5 September.

Query 4

With the new IP in hand, we grouped every certificate on 80.78.27[.]252 by port, common name and issuer, with first and last seen for each combination. That gives three rows: the panel on 8083 and 8443, and the c2 hostname on 2083.

SELECT
  ip,
  port,
  subject.common_name,
  issuer.organization,
  min(timestamp) AS first_seen,
  max(timestamp) AS last_seen
FROM
  certificates
WHERE
  ip == '80.78.27.252'
  AND timestamp.day gt '2026-03-01'
GROUP BY
  ip, port, subject.common_name, issuer.organization

                
Copy

Output example:

Figure 4. Three tuples on 80.78.27[.]252. Earliest first-seen: 4 April 2026.

We ran these queries on 5 September. We haven't seen these certificates on 80.78.27[.]252 in the last 30 days, so running Query 4 with a short time window today may return nothing.

BraZetsu Background: What Was Already Public

BraZetsu is the name Group-IB gave the framework. Their report describes five generations between February and May 2026, Portuguese debug strings, and the shift from a RAT with Run key MonitorSystem (v1) to an IAB platform with 27 functions, most of them enumeration (v5). The count is in the paper and in their 1 September post.

Attribution to Exilware, in the source text, rests on C2 overlap with the shop login panel, reuse of 38.242.246[.]176 with AgenteV2, the Pastebin XOR dead-drop, and distribution filenames (msedge[0-9].exe, wifi_driver.exe). The published reporting rates this attribution as high confidence. We take it as a starting point, not something this hunt tests.

The model described is an initial-access broker. The agent profiles ERP (TOTVS, SAP, Senior, Conta Azul, Sankhya), SCADA traces (WinCC, RSLogix, FactoryTalk), EDR, .pfx/.p12 certificates and CNAB files, and returns a dossier. The buyer drops the payload. The paper describes the scope as Latin America and the Iberian Peninsula, but its evidence points mainly to Brazil, with v2 also targeting Mercado Libre and Mercado Pago domains in Argentina, Mexico and Chile. In April the shop advertised two hosts in the United States; the paper treats that as insufficient to call a change of theatre.

C2 is not hardcoded in the binary. get_server_config() fetches a Pastebin blob, Base64-decodes it and XOR-decrypts with p4st3_s3cr3t_k3y. The result is domain|port|token. The live channel is WebSocket over TLS on 8443. Published raw IDs: aF0WCxia, hM0nXNBP, 9ChwVzzw.

IndicatorRole in the source text
hxxps://pastebin[.]com/raw/aF0WCxiaDead-drop
hxxps://pastebin[.]com/raw/hM0nXNBPDead-drop
hxxps://pastebin[.]com/raw/9ChwVzzwDead-drop
c2[.]installscenter[.]comCommand; link to the shop panel
infectonline[.]storeDomain tied to the shop
infect[.]onlineOlder shop infrastructure
38[.]242[.]246[.]176Contabo VPS; AgenteV2 overlap

The report's IOC section also lists sixteen SHA-256 hashes, and the body names caixaentradas1inboxshop.site, port 8443, the XOR key and the Run key. They enter the detection pack. They did not go through HuntSQL: the inventory does not see hashes or Pastebin.

80.78.27[.]252, painel.installscenter.com, painel.seu-dominio.com and ports 8083 and 2083 are not on the original report's list. We found them in this hunt.

Infrastructure by Role and Confidence

ArtifactObservationRoleConf.
38.242.246[.]176Seed IP; two CNs in Q1Panel Q1High
painel.seu-dominio.com17 hits, 11 Feb - 17 Mar, :8083PanelMedium
80.78.27[.]252Three tuples from 4 AprPanel + C2 Q2High
c2.installscenter.comSeed hostname on :2083C2High
painel.installscenter.comSame apex, :8083 and :8443PanelHigh

The seed IP: from a Contabo default to a Portuguese panel name

Grouping the certificates on 38.242.246[.]176 by common name (Query 2) returns two CNs, one after the other, with no overlap.

Figure 5. Two CNs on the seed IP.

The first is vmi3003111.contaboserver.net, the default hostname Contabo assigns to its VPS. We saw it 80 times between 4 January and 2 February, which points to continuous TLS service on the host.

On 11 February the CN changed to painel.seu-dominio.com, on port 8083. "Seu domínio" is Portuguese for "your domain", the placeholder used in Portuguese-language hosting tutorials. We saw it 17 times through 17 March.

Figure 6. painel.seu-dominio.com on 8083, 18 February to 17 March.

The Figure 6 series (17 Mar, 14 Mar, 11 Mar, 8 Mar, 4 Mar, 1 Mar, 26 Feb twice, 22 Feb, 18 Feb) fits a panel left running, not a short-lived landing page.

On this IP, in this cut, the inventory does not return c2.installscenter.com. Two readings fit. The Contabo VPS hosted the panel (and, according to the published reporting, infect.online before that) while the named C2 had already left. Or C2 on this IP used a certificate whose CN does not carry "c2". The table does not decide. What it does show: from mid-February this address presents a Hestia Control Panel certificate with a Portuguese placeholder name on 8083, the same panel setup the second host runs later.

The new host: panel and C2 on 80.78.27[.]252

Query 3 is what took the hunt off the seed IP. Searching certificate common names for tokens from the disclosure returned 80.78.27[.]252, presenting painel.installscenter.com on port 8083 with a Let's Encrypt certificate on 9, 10 and 12 June (Figure 3).

The interface didn't return a total count for that query, so there may be more matches over the 180-day window than the page we captured.

Grouping every certificate on that IP by port and CN (Query 4) returns three combinations:

IPPortCNfirst_seen
80.78.27[.]2528083painel.installscenter.com2026-05-16 09:41:30
80.78.27[.]2528443painel.installscenter.com2026-04-06 23:14:31
80.78.27[.]2522083c2.installscenter.com2026-04-04 05:32:39

c2.installscenter.com is the C2 hostname from the published reporting. Finding it on a different IP means the name moved to a new address, which fits what was published and doesn't contradict it.

What's new is painel.installscenter.com on the same IP and the same apex. It puts a Hestia Control Panel hostname and the C2 hostname side by side on one host. The ports are split by role too: 2083 under the c2 name, 8083 and 8443 under the panel name. 8443 matches the WebSocket port from the sample analysis.

Our SSL history on the IP shows two different certificates for the c2 hostname on 2083: the first, issued by Let's Encrypt R13 on 22 March, was seen from 4 April to 17 May. The second, issued on 21 May, was seen from 22 May to 4 June. The panel presented a single certificate on 8083 and 8443, seen from 6 April to 18 June.

Figure 7. SSL history on 80.78.27[.]252: two c2 certificates on 2083, one panel certificate on 8083 and 8443.

Pivot on 80.78.27[.]252

FieldValue
IPv480.78.27[.]252
PTR504e1bfc.host.njalla.net
ASNAS39287 - Materialism s.r.l.
Prefix80.78.16.0/20 (NJALLA-AC-NET)
Announced geo of the blockSweden
/24 gateway80.78.27.1 - r.njalla.net

Njalla is a privacy-focused hosting provider. The reverse DNS name, 504e1bfc.host.njalla.net, is just the IP written in hex (50 4e 1b fc), and every host in the block gets one built the same way. It doesn't tell us anything specific about this server.

The same goes for the provider. Landing on Njalla tells us what kind of hosting the operator chose, not who the operator is.

CT identityIssuernotBefore
painel.installscenter.comLet's Encrypt R122026-03-21 (notAfter 2026-06-19)
c2.installscenter.comLet's Encrypt R132026-03-22 (re-issue 2026-05-21)

The c2 certificate was issued about 13 days before our scans first saw it on this IP.

WHOIS records the creation of installscenter.com on 21 March 2026, through Tucows. The hostname resolves to Cloudflare today.

Figure 8. Domain summary for c2.installscenter.com, with the apex registered on 21 March.

Why the IP wasn't on the published list

Passive DNS helps explain it. Our records show c2.installscenter[.]com resolving to 80.78.27[.]252 between 22 and 26 March, and to Cloudflare (104.21.78.246, 172.67.138.224) from 26 March on. The only A record we have for painel.installscenter[.]com is Cloudflare, from 21 March.

Figure 9. A record history for c2.installscenter.com: four days on 80.78.27[.]252, then Cloudflare. The passive DNS source labels the origin's hosting as "ab stract"; our IP record places 80.78.27[.]252 in AS39287 (Materialism s.r.l.).

From late March, resolving these names returned Cloudflare addresses. The origin IP kept presenting the installscenter.com certificates to our scans until June.

2083 and 8443 are on Cloudflare's list of proxied HTTPS ports; 8083 is not. That is consistent with C2 and the WebSocket channel going through Cloudflare while the Hestia admin port was reached directly. We didn't observe the agent's traffic, so this is a reading of the port choice, not a finding.

Timeline

Dates combine our scan data, CT logs and the published reporting.

DateHostEvent
4 Jan 202638.242.246[.]176Contabo default certificate (vmi3003111.contaboserver.net)
4 Feb38.242.246[.]176SSH host key changes
Febn/aFirst BraZetsu version, per the published reporting
11 Feb38.242.246[.]176Hestia certificate painel.seu-dominio.com appears, on 8083
17 Mar38.242.246[.]176Last observation of painel.seu-dominio.com
20 Mar38.242.246[.]176Host goes quiet on 443
21 Marn/ainstallscenter.com registered (Tucows)
21-22 MarCT logsLet's Encrypt certificates issued for painel. and c2.installscenter.com
21 Mar80.78.27[.]252New host comes up on 443 (Njalla, AS39287)
22 MarDNSc2.installscenter.com resolves to 80.78.27[.]252
26 MarDNSc2.installscenter.com moves behind Cloudflare
30 Mar80.78.27[.]252SSH key set first seen
4 Apr80.78.27[.]252c2.installscenter.com on 2083
6 Apr80.78.27[.]252painel.installscenter.com on 8443
16 May80.78.27[.]252painel.installscenter.com on 8083
21 MayCT logsc2.installscenter.com certificate re-issued
16-20 Jun80.78.27[.]252All TLS ports go quiet
20 Jun80.78.27[.]252SSH key set last seen
24 Jul80.78.27[.]252Different SSH key appears
31 Augn/aGroup-IB publishes BraZetsu
5 Sepn/aHuntSQL queries shared by @akaclandestine
2 OctCT logsLatest wildcard certificate for *.installscenter.com

80.78.27[.]252 does not resolve caixaentradas1inboxshop.site. That delivery domain sits in the body of the paper and belongs to another phase of the chain (the report links it to an Ousaban sample delivered from the same domain). It is also not the historical A record of infect.online; previous research places that role on 38.242.246[.]176. Our scan history shows this IP was used by others before, including a 2024 certificate unrelated to this cluster. The operator window runs from 21 March to 20 June, and all TLS ports went quiet between 16 and 20 June.

SSH host keys follow the same window. One key set is first seen on 30 March and last seen on 20 June, the day the TLS services went quiet. A different key set appears from 24 July. We can't tie these keys to an operator; the overlap in dates is the only link.

On the seed IP the host key changed on 4 February and that key was last seen on 20 March. The Contabo default certificate was already served on 8083 and 8443 in January, so the Hestia setup predates that change.

Figure 10. SSH key history on 80.78.27[.]252. The key set seen from 30 March to 20 June matches the operator window.

Today the IP serves an nginx Laravel login on port 80 and a different SSH key. We see no installscenter.com certificates on it.

Figure 11. Current state of 80.78.27[.]252.

Operational reading, medium confidence: the cluster likely left a Contabo VPS already described in public reporting for a Njalla VPS, kept the same Hestia Control Panel setup, and gave the panel a name on the same apex as the C2 instead of the seu-dominio.com placeholder. That does not identify the operator, does not assign the whole /24 to the shop, and does not claim a marketplace code change.

Why the Hostnames Outlast the Binaries

BraZetsu changed its version. Five generations in four months. The binary changes, the hash changes, the Pastebin drop can be swapped in a commit. What does not change at the same rate is the name the buyer uses to reach the panel and the name the agent uses to reach the server. Those names need a certificate.

The buyer needs a URL that still exists the next day. The agent needs a hostname the dead-drop still points at. Both incentives push toward apex reuse. Rotation stays on the IPv4. That is what Figures 5 and 4 show in sequence.

painel.seu-dominio.com is the self-signed certificate Hestia Control Panel generated for the hostname set at install, likely copied from a Portuguese tutorial. Seventeen observations on the same IP suggest the panel stayed up for weeks. Query 3, in the photographed cut, did not return it to another address. It remains a hunt clause. It is not proof of migration.

TokenLayerStatus
installscenterC2 and panelTelemetry and seed
infectonline / infect.onlineShopSeed; no CN in the tables
inboxshop / caixaentradaDeliveryNarrative seed
nuevaprodeciencia / odaracaniOperational regexNo row - watchlist
painel.PrefixTwo apexes, same 8083
c2.PrefixOne apex, 2083 in this cut

The arrow between painel.seu-dominio.com and installscenter.com is habit plus sequence. It is not a shared certificate.

The shop sells the foothold. Ransomware, banking fraud, CNAB remittance rewriting and stolen A1-certificate use can be run by someone who never touched the BraZetsu code. v5 profiles EDR: the incentive is to avoid the already-monitored machine. The two U.S. hosts in April do not authorize writing that the victim perimeter matches the operator's language. They also do not authorize declaring a change of theatre.

Limitations

  • We didn't access the panels, so we have no page content from ports 8083 or 8443.

  • The certificates on both hosts share a JA4X, but it's the generic Let's Encrypt profile, so it doesn't link them. The pivot view shows why: the JA4X value has a count of about 13 million, and the R12 and R13 issuers counts in the hundreds of thousands. Both hosts also share JARM fingerprints on 8083 and 8443, which points to the same Hestia Control Panel setup, not necessarily the same operator.

Figure 12. Pivots on 80.78.27[.]252. Generic fingerprints with very high counts.

Indicators of Compromise

Defanged. Table 1 is the seed from the published reporting. Table 2 is what our inventory added. Table 3 and the sample hashes come from the body of the report.

Table 1: Seed (published indicators)

TypeValue
IPv438.242.246[.]176
Hostc2.installscenter[.]com
Hostinfect[.]online
Hostinfectonline[.]store
URLhxxps://pastebin[.]com/raw/aF0WCxia
URLhxxps://pastebin[.]com/raw/hM0nXNBP
URLhxxps://pastebin[.]com/raw/9ChwVzzw

Table 2: Added by our inventory

TypeValueNote
IPv480.78.27[.]252C2 hostname + Hestia panel, 4 Apr to 20 Jun. Different service and SSH key since July; check before blocking
Hostpainel.installscenter[.]com8083 and 8443
Hostpainel.seu-dominio[.]comCertificate CN only, placeholder name. Do not block as a domain
Cert SHA-2560C65D06ECD5A4BCD214128CC5AE2FD48F449A7B0E4002C6F0E127486B90DF1B5c2.installscenter[.]com, :2083, 4 Apr to 17 May
Cert SHA-256731F269E44E3372E214E48EBAF0A05A892E914422A1FA664FB25A0FE2200528Ac2.installscenter[.]com, :2083, 22 May to 4 Jun
Cert SHA-256473ADE701A602A14D50A869762DF72D1A1CA7CD395BF26B9E090D9116A447726painel.installscenter[.]com, :8083 and :8443
Cert SHA-256AB5C83564A38A035819A601E2E2F40C4AD07D0C12625BBB196AB4E915B087F86painel.seu-dominio[.]com, seed IP
Port8083 / 2083 / 8443Panel / C2 / panel and WebSocket

Table 3: From the report body

TypeValue
Hostcaixaentradas1inboxshop[.]site
Filenamemsedge[0-9].exe (e.g. msedge04.exe), wifi_driver.exe, temp_agente.dll
v1 persistenceHKCU Run \ MonitorSystem
XORp4st3_s3cr3t_k3y
Sample hashes (SHA-256, from the published reporting)
f775fe06a4c2563cb03e1aa42eb4e9532840cce9dc168ea2ca97cee7972e6b17
54e313434a7f3fa349e439857e23ab536a95c9927cf62f8358b5cdd9fabf2700
91f225dcc7a01f926b03e8540d8b5e2d6c8e3763cc30f57381d702ce638fa6b0
cd8fc8effea20d28e76c53f3386c783e55dcb309e1525b27f7a141d51b6f6c78
d881a60ccd03b5417a1eed184143a18a333e7e9e9e351596a7a765843643af99
0fa785bb9f95b113539bb909da88e6cac9a433a07935571d9bcd2d85746fc5bf
1510823e7c80b4db5333dd18cd5992881496da30032d6d69b2a82e1c5cf30246
96960409b6e1abf20eeb689d9e0a170008a15096de6a06ca5ae0d5aa56579042
0cd0cc49ea4ff48c675368f725e183608494f22fefa92d2f33577f70bb6c0d5d
30af2ec2437af0f4910d528440715540dbec6a5587f86f327316a7a781c1e2fe
10de6185e31539cf01c8b05d9559e65e8693efd695f315de54667ef8c04de39c
bc91f90a5677404cf9c8f4bed7b36c22027b1549ffefee129b41fab3db3108b8
93bb4a4812e77ddc17c2722340d915bd5c8387316bbdbc394c201a28cb9b7c88
67fcfbdaab397ad1273135a3c6aa1d220ab76491cf945df081503401cc9732d2
c4dd46e5b450349fd9fbf686a5a22f55f8371123b098104db663a3980646e138
3f2f48525cf082672e38808480e214775e03dd943ff2df86172665aad96a5eaa

MITRE ATT&CK Mapping and Detection

TacticTechniqueID
Resource DevelopmentVPS / Domains / MalwareT1583.003 / T1583.001 / T1588.001
Initial AccessUnknown (social engineering suspected in the published reporting)n/a
Execution / PersistenceInterpreter / Run keyT1059 / T1547.001
Defense EvasionObfuscated / MasqueradingT1027 / T1036
Credential AccessPrivate KeysT1552.004
Discovery / CollectionSoftware, browser, screenT1518 / T1217 / T1113
Command and ControlWebSocket, TLS, dead-dropT1071.001 / T1573 / T1102.001
ExfiltrationOver C2 ChannelT1041

Hashes from this cluster changed across five versions in four months, so they won't hold for long. What held from February to June was the naming and hosting pattern: a painel. or c2. prefix, a non-standard port, a Hestia Control Panel setup on a VPS, and sometimes a request to pastebin.com/raw/ right before.

The logic below is generic. Adapt the field names to your SIEM.

dns.qname in {c2.installscenter.com, painel.installscenter.com,
              infect.online, infectonline.store}
or dest.ip in {38.242.246.176, 80.78.27.252}
or (dest.port in {2083, 8083, 8443}
    and dest.asn in {51167, 39287}
    and (tls.sni startswith "painel." or tls.sni startswith "c2."))

                
Copy

Hestia Control Panel uses 8083 as its admin port by default, and many legitimate Portuguese-language servers name it painel.*. Expect false positives on the SNI condition and review hits before blocking.

Since late March c2.installscenter.com resolves to Cloudflare, so connections through it go to Cloudflare addresses (AS13335). The ASN condition only catches direct connections to the origin; the hostname and SNI conditions still apply.

Network and hunting

  • Re-run Query 3 weekly and alert on any new painel.* or c2.* certificate on ports 2083, 8083 or 8443.

  • Pivot on the installscenter.com certificate hashes in the IOC table to look for other hosts.

  • Add IPs to blocklists with a first-seen date and a review date. This infrastructure rotates.

Endpoint

  • Look for unsigned executables compiled with Nuitka, Chromium History files copied into %TEMP%, enumeration of .pfx files, and a Run key value named MonitorSystem.

If you get a hit

  • Isolate the host and preserve %TEMP% and the Run key before cleanup.

  • Assume the access may already have been sold, and check for follow-on activity from other actors.

Conclusion

The public reporting gave us three things to work from: the C2 hostname, the IP tied to it early in the year, and the shop both of them served. Our certificate inventory showed what happened to that hostname after the first VPS went quiet. It showed up on a new host in a different provider, with a control panel on the same apex.

The TLS services on 80.78.27[.]252 went quiet after 20 June. The pattern is more stable: a painel. or c2. prefix on a port that isn't 443, on a VPS running Hestia Control Panel. It held from February to June across two providers, and that's what we'd build detection on, not the IP.

CT logs show wildcard certificates for *.installscenter.com from Let's Encrypt and Google Trust Services, the latest issued on 2 October. With Cloudflare nameservers on the domain, that is consistent with the zone still being active on Cloudflare. It doesn't show the C2 is live, but the hostnames are worth keeping on blocklists.

If you want to run these queries against your own seeds, or set up alerts for new painel.* and c2.* certificates on those ports, book a demo and we'll walk through the HuntSQL workflow with your team.