Skip to content
Mapping BraZetsu Infrastructure via TLS Certificates

Mapping BraZetsu Infrastructure via TLS Certificates

hunt.io • October 8, 2026

SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia

SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia

SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia

Brazilian Access Broker Targeting Latin America: Mapping BraZetsu Infrastructure via TLS Certificates

Disclosure note: Before publishing, we shared the new infrastructure identified in this research with the relevant national CERTs. This research did not recover victim data.

On 31 August 2026 Group-IB described BraZetsu, a Python framework for Windows compiled with Nuitka, and attributed it with high confidence to the Brazilian actor Exilware. The same paper ties the binary to the Infected Marketplace (Banco de Infects), a shop that inventories compromised Windows hosts and sells the access after a deposit of $5.80 (BRL 30), settled through NowPayments.

The published network indicators are three Pastebin raw URLs, the hostnames c2.installscenter.com, infect.online and infectonline.store, and one IPv4 address: 38.242.246[.]176, a Contabo VPS already seen in the AgenteV2 lineage.

We didn't reverse the binary again. We took the published indicators and checked what our certificate inventory still shows. The premise is narrow. An operator who keeps a panel and a command channel under the same apex, with Let's Encrypt off port 443, leaves a more stable trail in the certificate inventory than the address of the month.

Published C2 hostname was live months earlier . The command hostname reported on 31 August, c2.installscenter[.]com, was already serving TLS on a second VPS (80.78.27[.]252) on port 2083 from 4 April 2026, almost five months before the disclosure.

Published C2 hostname was live months earlier . The command hostname reported on 31 August, c2.installscenter[.]com, was already serving TLS on a second VPS (80.78.27[.]252) on port 2083 from 4 April 2026, almost five months before the disclosure.

Panel and C2 one host . The same IP also presents painel.installscenter[.]com on ports 8083 and 8443, so a control panel hostname and the C2 hostname sit on the same apex and the same host. 8083 is the default Hestia Control Panel admin port; 8443 also matches the WebSocket port in the published sample analysis.

Panel and C2 one host . The same IP also presents painel.installscenter[.]com on ports 8083 and 8443, so a control panel hostname and the C2 hostname sit on the same apex and the same host. 8083 is the default Hestia Control Panel admin port; 8443 also matches the WebSocket port in the published sample analysis.

Seed IP switched to a Portuguese panel name . On 38.242.246[.]176 (Contabo), the certificate CN changed on 11 February, the same month the published reporting dates the first BraZetsu version. It went from the default Contabo hostname to a self-signed Hestia Control Panel certificate for painel.seu-dominio[.]com, a placeholder from Portuguese hosting tutorials, on the Hestia admin port 8083.

Seed IP switched to a Portuguese panel name . On 38.242.246[.]176 (Contabo), the certificate CN changed on 11 February, the same month the published reporting dates the first BraZetsu version. It went from the default Contabo hostname to a self-signed Hestia Control Panel certificate for painel.seu-dominio[.]com, a placeholder from Portuguese hosting tutorials, on the Hestia admin port 8083.

Repeated observations point to a long-running panel . Our inventory recorded painel.seu-dominio[.]com on the seed IP 17 times between 11 February and 17 March, every 2-4 days. That fits a panel left running, not a short-lived landing page.

Repeated observations point to a long-running panel . Our inventory recorded painel.seu-dominio[.]com on the seed IP 17 times between 11 February and 17 March, every 2-4 days. That fits a panel left running, not a short-lived landing page.

Certificates existed before the move . CT logs show Let's Encrypt certificates for painel. and c2.installscenter[.]com issued on 21-22 March, 13 days before our scans first saw them on the new IP. The c2 certificate was re-issued on 21 May.

Certificates existed before the move . CT logs show Let's Encrypt certificates for painel. and c2.installscenter[.]com issued on 21-22 March, 13 days before our scans first saw them on the new IP. The c2 certificate was re-issued on 21 May.

C2 hostname moved behind Cloudflare . Passive DNS shows c2.installscenter[.]com on 80.78.27[.]252 between 22 and 26 March and on Cloudflare from 26 March on. The origin kept presenting the installscenter.com certificates to our scans until June.

C2 hostname moved behind Cloudflare . Passive DNS shows c2.installscenter[.]com on 80.78.27[.]252 between 22 and 26 March and on Cloudflare from 26 March on. The origin kept presenting the installscenter.com certificates to our scans until June.

Same operator habits, new provider . The cluster likely moved from Contabo (AS51167) to Njalla (AS39287). The seed IP went quiet on 20 March and the new host came up on 21 March, the day installscenter.com was registered and its first certificates were issued. Both ran the same Hestia Control Panel setup and used the painel. prefix. We rate operator continuity as medium.

Same operator habits, new provider . The cluster likely moved from Contabo (AS51167) to Njalla (AS39287). The seed IP went quiet on 20 March and the new host came up on 21 March, the day installscenter.com was registered and its first certificates were issued. Both ran the same Hestia Control Panel setup and used the painel. prefix. We rate operator continuity as medium.

Naming patterns outlast hashes . Hashes and Pastebin dead-drops rotated across five versions in four months. The painel. prefix on port 8083 held from February to June across both hosts, and four HuntSQL queries document the pattern.

Naming patterns outlast hashes . Hashes and Pastebin dead-drops rotated across five versions in four months. The painel. prefix on port 8083 held from February to June across both hosts, and four HuntSQL queries document the pattern.

Hunting the Certificates From the Seed IP

We ran four HuntSQL queries, starting from the published seed IP. The first two build its certificate timeline, the third expands by keyword, and the fourth profiles the new host.

What the queries returned

On the seed IP the inventory records two common names in sequence. From 4 January to 2 February 2026 the host presents the Contabo factory name vmi3003111.contaboserver.net, 80 observations. On 11 February, the same month the published reporting dates the first BraZetsu version, the CN became painel.seu-dominio.com. On 8083, and briefly on 443 from 11 to 13 February. Seventeen observations through 17 March, two to four days apart.

A lexical expansion on the CN, using tokens from the disclosure itself (installscenter, infectonline, inboxshop, caixaentrada) plus two terms from @akaclandestine's original query (nuevaprodeciencia, odaracani), which returned no rows, returns 80.78.27[.]252. On that address the inventory sees painel.installscenter.com on 8083 and 8443 and c2.installscenter.com on 2083. Earliest first-seen is 4 April, on port 2083, under the command hostname research had already named.

The PTR for 80.78.27[.]252 is 504e1bfc.host.njalla.net. The four octets in hex reproduce the label (50 4e 1b fc). Prefix 80.78.16.0/20 is announced by AS39287 (Materialism s.r.l.), netname NJALLA-AC-NET. A neighbour on the same /24, 80.78.27.237, resolves to 504e1bed.host.njalla.net, the same scheme. On crt.sh, checked on 26 September, painel.installscenter.com has Let's Encrypt R12 issuance on 21 March (notAfter 19 June, four certificates) and c2.installscenter.com has R13 from 22 March, with a re-issue on 21 May.

The hostname published in August was already speaking TLS on another VPS from early April. The panel took a name on the same apex. Port 8443, the WebSocket port in the sample analysis, appears on this second host under the panel CN.

What We Expected to Find

We went in with three expectations we could check against the certificate data. Attribution to Exilware is background here, not something this hunt tries to prove.

Panel and C2 on the same apex . If the malware finds its C2 through a Pastebin dead-drop and the shop needs a front end for buyers, installscenter.com should show up under both roles, panel and c2, on the same IP or on later ones, and not on port 443.

Panel and C2 on the same apex . If the malware finds its C2 through a Pastebin dead-drop and the shop needs a front end for buyers, installscenter.com should show up under both roles, panel and c2, on the same IP or on later ones, and not on port 443.

A panel that stays up . If the panel is a real shop and not a one-night landing page, its certificate should keep showing up over weeks, not hours.

A panel that stays up . If the panel is a real shop and not a one-night landing page, its certificate should keep showing up over weeks, not hours.

Portuguese naming survives a move . If the operator changes VPS but keeps Portuguese naming, searching certificate names should find hosts that pivoting on the seed IP alone would miss.

Portuguese naming survives a move . If the operator changes VPS but keeps Portuguese naming, searching certificate names should find hosts that pivoting on the seed IP alone would miss.

How We Pivoted From the Seed IP

We ran the hunt in HuntSQL, our SQL interface over the certificate inventory and other scan data. We started from the public seed IP, built a timeline of the certificates it presented, grouped them by common name, and then widened the by keyword to find new hosts. For each new IP we checked ASN, reverse DNS and Certificate Transparency logs.

A common name made it into our findings only if it passed two of three checks: it matches a reported hostname, it sits on the same IP as a published hostname in the same time window, or it uses a port already tied to the cluster (8083 on the seed IP, which is also the Hestia admin port, or 8443 from the sample analysis). Keywords that returned no rows stayed on the watchlist.

We pulled every certificate our inventory recorded on the seed IP, 38.242.246[.]176, since 1 January 2026, newest first. This gives the raw timeline: which common names the host presented, on which ports, and when.

Same IP, same window, but grouped by common name. For each CN we get the first and last time we saw it and how many times it showed up. This is where the switch from the Contabo default hostname to painel.seu-dominio.com shows up.

Here we left the seed IP and searched the last 180 days of certificates for common names containing tokens from the disclosure (installscenter, infectonline, inboxshop, caixaentrada), matched case-insensitive with a regex. This is the query that returned 80.78.27[.]252.

With the new IP in hand, we grouped every certificate on 80.78.27[.]252 by port, common name and issuer, with first and last seen for each combination. That gives three rows: the panel on 8083 and 8443, and the c2 hostname on 2083.

We ran these queries on 5 September. We haven't seen these certificates on 80.78.27[.]252 in the last 30 days, so running Query 4 with a short time window today may return nothing.

BraZetsu Background: What Was Already Public

BraZetsu is the name Group-IB gave the framework. Their report describes five generations between February and May 2026, Portuguese debug strings, and the shift from a RAT with Run key MonitorSystem (v1) to an IAB platform with 27 functions, most of them enumeration (v5). The count is in the paper and in their 1 September post.

Attribution to Exilware, in the source text, rests on C2 overlap with the shop login panel, reuse of 38.242.246[.]176 with AgenteV2, the Pastebin XOR dead-drop, and distribution filenames (msedge[0-9].exe, wifi_driver.exe). The published reporting rates this attribution as high confidence. We take it as a starting point, not something this hunt tests.

The model described is an initial-access broker. The agent profiles ERP (TOTVS, SAP, Senior, Conta Azul, Sankhya), SCADA traces (WinCC, RSLogix, FactoryTalk), EDR, .pfx/.p12 certificates and CNAB files, and returns a dossier. The buyer drops the payload. The paper describes the scope as Latin America and the Iberian Peninsula, but its evidence points mainly to Brazil, with v2 also targeting Mercado Libre and Mercado Pago domains in Argentina, Mexico and Chile. In April the shop advertised two hosts in the United States; the paper treats that as insufficient to call a change of theatre.

C2 is not hardcoded in the binary. get_server_config() fetches a Pastebin blob, Base64-decodes it and XOR-decrypts with p4st3_s3cr3t_k3y. The result is domain|port|token. The live channel is WebSocket over TLS on 8443. Published raw IDs: aF0WCxia, hM0nXNBP, 9ChwVzzw.

The report's IOC section also lists sixteen SHA-256 hashes, and the body names caixaentradas1inboxshop.site, port 8443, the XOR key and the Run key. They enter the detection pack. They did not go through HuntSQL: the inventory does not see hashes or Pastebin.

80.78.27[.]252, painel.installscenter.com, painel.seu-dominio.com and ports 8083 and 2083 are not on the original report's list. We found them in this hunt.

Infrastructure by Role and Confidence

The seed IP: from a Contabo default to a Portuguese panel name

Grouping the certificates on 38.242.246[.]176 by common name (Query 2) returns two CNs, one after the other, with no overlap.

The first is vmi3003111.contaboserver.net, the default hostname Contabo assigns to its VPS. We saw it 80 times between 4 January and 2 February, which points to continuous TLS service on the host.

On 11 February the CN changed to painel.seu-dominio.com, on port 8083. "Seu domínio" is Portuguese for "your domain", the placeholder used in Portuguese-language hosting tutorials. We saw it 17 times through 17 March.

The Figure 6 series (17 Mar, 14 Mar, 11 Mar, 8 Mar, 4 Mar, 1 Mar, 26 Feb twice, 22 Feb, 18 Feb) fits a panel left running, not a short-lived landing page.

On this IP, in this cut, the inventory does not return c2.installscenter.com. Two readings fit. The Contabo VPS hosted the panel (and, according to the published reporting, infect.online before that) while the named C2 had already left. Or C2 on this IP used a certificate whose CN does not carry "c2". The table does not decide. What it does show: from mid-February this address presents a Hestia Control Panel certificate with a Portuguese placeholder name on 8083, the same panel setup the second host runs later.

The new host: panel and C2 on 80.78.27[.]252

Query 3 is what took the hunt off the seed IP. Searching certificate common names for tokens from the disclosure returned 80.78.27[.]252, presenting painel.installscenter.com on port 8083 with a Let's Encrypt certificate on 9, 10 and 12 June (Figure 3).

The interface didn't return a total count for that query, so there may be more matches over the 180-day window than the page we captured.

Grouping every certificate on that IP by port and CN (Query 4) returns three combinations:

c2.installscenter.com is the C2 hostname from the published reporting. Finding it on a different IP means the name moved to a new address, which fits what was published and doesn't contradict it.

What's new is painel.installscenter.com on the same IP and the same apex. It puts a Hestia Control Panel hostname and the C2 hostname side by side on one host. The ports are split by role too: 2083 under the c2 name, 8083 and 8443 under the panel name. 8443 matches the WebSocket port from the sample analysis.

Our SSL history on the IP shows two different certificates for the c2 hostname on 2083: the first, issued by Let's Encrypt R13 on 22 March, was seen from 4 April to 17 May. The second, issued on 21 May, was seen from 22 May to 4 June. The panel presented a single certificate on 8083 and 8443, seen from 6 April to 18 June.

Pivot on 80.78.27[.]252

Njalla is a privacy-focused hosting provider. The reverse DNS name, 504e1bfc.host.njalla.net, is just the IP written in hex (50 4e 1b fc), and every host in the block gets one built the same way. It doesn't tell us anything specific this server.

The same goes for the provider. Landing on Njalla tells us what kind of hosting the operator chose, not who the operator is.

The c2 certificate was issued 13 days before our scans first saw it on this IP.

WHOIS records the creation of installscenter.com on 21 March 2026, through Tucows. The hostname resolves to Cloudflare today.

Passive DNS helps explain it. Our records show c2.installscenter[.]com resolving to 80.78.27[.]252 between 22 and 26 March, and to Cloudflare (104.21.78.246, 172.67.138.224) from 26 March on. The only A record we have for painel.installscenter[.]com is Cloudflare, from 21 March.

From late March, resolving these names returned Cloudflare addresses. The origin IP kept presenting the installscenter.com certificates to our scans until June.

2083 and 8443 are on Cloudflare's list of proxied HTTPS ports; 8083 is not. That is consistent with C2 and the WebSocket channel going through Cloudflare while the Hestia admin port was reached directly. We didn't observe the agent's traffic, so this is a reading of the port choice, not a finding.

Dates combine our scan data, CT logs and the published reporting.

80.78.27[.]252 does not resolve caixaentradas1inboxshop.site. That delivery domain sits in the body of the paper and belongs to another phase of the chain (the report links it to an Ousaban sample delivered from the same domain). It is also not the historical A record of infect.online; research places that role on 38.242.246[.]176. Our scan history shows this IP was used by others before, including a 2024 certificate unrelated to this cluster. The operator window runs from 21 March to 20 June, and all TLS ports went quiet between 16 and 20 June.

SSH host keys follow the same window. One key set is first seen on 30 March and last seen on 20 June, the day the TLS services went quiet. A different key set appears from 24 July. We can't tie these keys to an operator; the overlap in dates is the only link.

On the seed IP the host key changed on 4 February and that key was last seen on 20 March. The Contabo default certificate was already served on 8083 and 8443 in January, so the Hestia setup predates that change.

Today the IP serves an nginx Laravel login on port 80 and a different SSH key. We see no installscenter.com certificates on it.

Operational reading, medium confidence: the cluster likely left a Contabo VPS already described in public reporting for a Njalla VPS, kept the same Hestia Control Panel setup, and gave the panel a name on the same apex as the C2 instead of the seu-dominio.com placeholder. That does not identify the operator, does not assign the whole /24 to the shop, and does not claim a marketplace code change.

Why the Hostnames Outlast the Binaries

BraZetsu changed its version. Five generations in four months. The binary changes, the hash changes, the Pastebin drop can be swapped in a commit. What does not change at the same rate is the name the buyer uses to reach the panel and the name the agent uses to reach the server. Those names need a certificate.

The buyer needs a URL that still exists the day. The agent needs a hostname the dead-drop still points at. Both incentives push toward apex reuse. Rotation stays on the IPv4. That is what Figures 5 and 4 show in sequence.

painel.seu-dominio.com is the self-signed certificate Hestia Control Panel generated for the hostname set at install, likely copied from a Portuguese tutorial. Seventeen observations on the same IP suggest the panel stayed up for weeks. Query 3, in the photographed cut, did not return it to another address. It remains a hunt clause. It is not proof of migration.

The arrow between painel.seu-dominio.com and installscenter.com is habit plus sequence. It is not a shared certificate.

The shop sells the foothold. Ransomware, banking fraud, CNAB remittance rewriting and stolen A1-certificate use can be run by someone who never touched the BraZetsu code. v5 profiles EDR: the incentive is to avoid the already-monitored machine. The two U.S. hosts in April do not authorize writing that the victim perimeter matches the operator's language. They also do not authorize declaring a change of theatre.

We didn't access the panels, so we have no page content from ports 8083 or 8443.

We didn't access the panels, so we have no page content from ports 8083 or 8443.

The certificates on both hosts a JA4X, but it's the generic Let's Encrypt profile, so it doesn't link them. The pivot view shows why: the JA4X value has a count of 13 million, and the R12 and R13 issuers counts in the hundreds of thousands. Both hosts also JARM fingerprints on 8083 and 8443, which points to the same Hestia Control Panel setup, not necessarily the same operator.

The certificates on both hosts a JA4X, but it's the generic Let's Encrypt profile, so it doesn't link them. The pivot view shows why: the JA4X value has a count of 13 million, and the R12 and R13 issuers counts in the hundreds of thousands. Both hosts also JARM fingerprints on 8083 and 8443, which points to the same Hestia Control Panel setup, not necessarily the same operator.

Indicators of Compromise

Defanged. Table 1 is the seed from the published reporting. Table 2 is what our inventory added. Table 3 and the sample hashes come from the body of the report.

Table 1: Seed (published indicators)

Table 2: Added by our inventory

Table 3: From the report body

MITRE ATT&CK Mapping and Detection

Hashes from this cluster changed across five versions in four months, so they won't hold for long. What held from February to June was the naming and hosting pattern: a painel. or c2. prefix, a non-standard port, a Hestia Control Panel setup on a VPS, and sometimes a request to pastebin.com/raw/ right before.

The logic below is generic. Adapt the field names to your SIEM.

Hestia Control Panel uses 8083 as its admin port by default, and many legitimate Portuguese-language servers name it painel.*. Expect false positives on the SNI condition and review hits before blocking.

Since late March c2.installscenter.com resolves to Cloudflare, so connections through it go to Cloudflare addresses (AS13335). The ASN condition only catches direct connections to the origin; the hostname and SNI conditions still apply.

Re-run Query 3 weekly and alert on any new painel.* or c2.* certificate on ports 2083, 8083 or 8443.

Re-run Query 3 weekly and alert on any new painel.* or c2.* certificate on ports 2083, 8083 or 8443.

Pivot on the installscenter.com certificate hashes in the IOC table to look for other hosts.

Pivot on the installscenter.com certificate hashes in the IOC table to look for other hosts.

Add IPs to blocklists with a first-seen date and a review date. This infrastructure rotates.

Add IPs to blocklists with a first-seen date and a review date. This infrastructure rotates.

Look for unsigned executables compiled with Nuitka, Chromium History files copied into %TEMP%, enumeration of .pfx files, and a Run key value named MonitorSystem.

Look for unsigned executables compiled with Nuitka, Chromium History files copied into %TEMP%, enumeration of .pfx files, and a Run key value named MonitorSystem.

Isolate the host and preserve %TEMP% and the Run key before cleanup.

Isolate the host and preserve %TEMP% and the Run key before cleanup.

Assume the access may already have been sold, and check for follow-on activity from other actors.

Assume the access may already have been sold, and check for follow-on activity from other actors.

The public reporting gave us three things to work from: the C2 hostname, the IP tied to it early in the year, and the shop both of them served. Our certificate inventory showed what happened to that hostname after the first VPS went quiet. It showed up on a new host in a different provider, with a control panel on the same apex.

The TLS services on 80.78.27[.]252 went quiet after 20 June. The pattern is more stable: a painel. or c2. prefix on a port that isn't 443, on a VPS running Hestia Control Panel. It held from February to June across two providers, and that's what we'd build detection on, not the IP.

CT logs show wildcard certificates for *.installscenter.com from Let's Encrypt and Google Trust Services, the latest issued on 2 October. With Cloudflare nameservers on the domain, that is consistent with the zone still being active on Cloudflare. It doesn't show the C2 is live, but the hostnames are worth keeping on blocklists.

If you want to run these queries against your own seeds, or set up alerts for new painel.* and c2.* certificates on those ports, book a demo and we'll walk through the HuntSQL workflow with your team.

Disclosure note: Before publishing, we shared the new infrastructure identified in this research with the relevant national CERTs. This research did not recover victim data.

On 31 August 2026 Group-IB described BraZetsu, a Python framework for Windows compiled with Nuitka, and attributed it with high confidence to the Brazilian actor Exilware. The same paper ties the binary to the Infected Marketplace (Banco de Infects), a shop that inventories compromised Windows hosts and sells the access after a deposit of $5.80 (BRL 30), settled through NowPayments.

The published network indicators are three Pastebin raw URLs, the hostnames c2.installscenter.com, infect.online and infectonline.store, and one IPv4 address: 38.242.246[.]176, a Contabo VPS already seen in the AgenteV2 lineage.

We didn't reverse the binary again. We took the published indicators and checked what our certificate inventory still shows. The premise is narrow. An operator who keeps a panel and a command channel under the same apex, with Let's Encrypt off port 443, leaves a more stable trail in the certificate inventory than the address of the month.

Published C2 hostname was live months earlier . The command hostname reported on 31 August, c2.installscenter[.]com, was already serving TLS on a second VPS (80.78.27[.]252) on port 2083 from 4 April 2026, almost five months before the disclosure.

Published C2 hostname was live months earlier . The command hostname reported on 31 August, c2.installscenter[.]com, was already serving TLS on a second VPS (80.78.27[.]252) on port 2083 from 4 April 2026, almost five months before the disclosure.

Panel and C2 one host . The same IP also presents painel.installscenter[.]com on ports 8083 and 8443, so a control panel hostname and the C2 hostname sit on the same apex and the same host. 8083 is the default Hestia Control Panel admin port; 8443 also matches the WebSocket port in the published sample analysis.

Panel and C2 one host . The same IP also presents painel.installscenter[.]com on ports 8083 and 8443, so a control panel hostname and the C2 hostname sit on the same apex and the same host. 8083 is the default Hestia Control Panel admin port; 8443 also matches the WebSocket port in the published sample analysis.

Seed IP switched to a Portuguese panel name . On 38.242.246[.]176 (Contabo), the certificate CN changed on 11 February, the same month the published reporting dates the first BraZetsu version. It went from the default Contabo hostname to a self-signed Hestia Control Panel certificate for painel.seu-dominio[.]com, a placeholder from Portuguese hosting tutorials, on the Hestia admin port 8083.

Seed IP switched to a Portuguese panel name . On 38.242.246[.]176 (Contabo), the certificate CN changed on 11 February, the same month the published reporting dates the first BraZetsu version. It went from the default Contabo hostname to a self-signed Hestia Control Panel certificate for painel.seu-dominio[.]com, a placeholder from Portuguese hosting tutorials, on the Hestia admin port 8083.

Repeated observations point to a long-running panel . Our inventory recorded painel.seu-dominio[.]com on the seed IP 17 times between 11 February and 17 March, every 2-4 days. That fits a panel left running, not a short-lived landing page.

Repeated observations point to a long-running panel . Our inventory recorded painel.seu-dominio[.]com on the seed IP 17 times between 11 February and 17 March, every 2-4 days. That fits a panel left running, not a short-lived landing page.

Certificates existed before the move . CT logs show Let's Encrypt certificates for painel. and c2.installscenter[.]com issued on 21-22 March, 13 days before our scans first saw them on the new IP. The c2 certificate was re-issued on 21 May.

Certificates existed before the move . CT logs show Let's Encrypt certificates for painel. and c2.installscenter[.]com issued on 21-22 March, 13 days before our scans first saw them on the new IP. The c2 certificate was re-issued on 21 May.

C2 hostname moved behind Cloudflare . Passive DNS shows c2.installscenter[.]com on 80.78.27[.]252 between 22 and 26 March and on Cloudflare from 26 March on. The origin kept presenting the installscenter.com certificates to our scans until June.

C2 hostname moved behind Cloudflare . Passive DNS shows c2.installscenter[.]com on 80.78.27[.]252 between 22 and 26 March and on Cloudflare from 26 March on. The origin kept presenting the installscenter.com certificates to our scans until June.

Same operator habits, new provider . The cluster likely moved from Contabo (AS51167) to Njalla (AS39287). The seed IP went quiet on 20 March and the new host came up on 21 March, the day installscenter.com was registered and its first certificates were issued. Both ran the same Hestia Control Panel setup and used the painel. prefix. We rate operator continuity as medium.

Same operator habits, new provider . The cluster likely moved from Contabo (AS51167) to Njalla (AS39287). The seed IP went quiet on 20 March and the new host came up on 21 March, the day installscenter.com was registered and its first certificates were issued. Both ran the same Hestia Control Panel setup and used the painel. prefix. We rate operator continuity as medium.

Naming patterns outlast hashes . Hashes and Pastebin dead-drops rotated across five versions in four months. The painel. prefix on port 8083 held from February to June across both hosts, and four HuntSQL queries document the pattern.

Naming patterns outlast hashes . Hashes and Pastebin dead-drops rotated across five versions in four months. The painel. prefix on port 8083 held from February to June across both hosts, and four HuntSQL queries document the pattern.

Hunting the Certificates From the Seed IP

We ran four HuntSQL queries, starting from the published seed IP. The first two build its certificate timeline, the third expands by keyword, and the fourth profiles the new host.

What the queries returned

On the seed IP the inventory records two common names in sequence. From 4 January to 2 February 2026 the host presents the Contabo factory name vmi3003111.contaboserver.net, 80 observations. On 11 February, the same month the published reporting dates the first BraZetsu version, the CN became painel.seu-dominio.com. On 8083, and briefly on 443 from 11 to 13 February. Seventeen observations through 17 March, two to four days apart.

A lexical expansion on the CN, using tokens from the disclosure itself (installscenter, infectonline, inboxshop, caixaentrada) plus two terms from @akaclandestine's original query (nuevaprodeciencia, odaracani), which returned no rows, returns 80.78.27[.]252. On that address the inventory sees painel.installscenter.com on 8083 and 8443 and c2.installscenter.com on 2083. Earliest first-seen is 4 April, on port 2083, under the command hostname research had already named.

The PTR for 80.78.27[.]252 is 504e1bfc.host.njalla.net. The four octets in hex reproduce the label (50 4e 1b fc). Prefix 80.78.16.0/20 is announced by AS39287 (Materialism s.r.l.), netname NJALLA-AC-NET. A neighbour on the same /24, 80.78.27.237, resolves to 504e1bed.host.njalla.net, the same scheme. On crt.sh, checked on 26 September, painel.installscenter.com has Let's Encrypt R12 issuance on 21 March (notAfter 19 June, four certificates) and c2.installscenter.com has R13 from 22 March, with a re-issue on 21 May.

The hostname published in August was already speaking TLS on another VPS from early April. The panel took a name on the same apex. Port 8443, the WebSocket port in the sample analysis, appears on this second host under the panel CN.

What We Expected to Find

We went in with three expectations we could check against the certificate data. Attribution to Exilware is background here, not something this hunt tries to prove.

Panel and C2 on the same apex . If the malware finds its C2 through a Pastebin dead-drop and the shop needs a front end for buyers, installscenter.com should show up under both roles, panel and c2, on the same IP or on later ones, and not on port 443.

Panel and C2 on the same apex . If the malware finds its C2 through a Pastebin dead-drop and the shop needs a front end for buyers, installscenter.com should show up under both roles, panel and c2, on the same IP or on later ones, and not on port 443.

A panel that stays up . If the panel is a real shop and not a one-night landing page, its certificate should keep showing up over weeks, not hours.

A panel that stays up . If the panel is a real shop and not a one-night landing page, its certificate should keep showing up over weeks, not hours.

Portuguese naming survives a move . If the operator changes VPS but keeps Portuguese naming, searching certificate names should find hosts that pivoting on the seed IP alone would miss.

Portuguese naming survives a move . If the operator changes VPS but keeps Portuguese naming, searching certificate names should find hosts that pivoting on the seed IP alone would miss.

How We Pivoted From the Seed IP

We ran the hunt in HuntSQL, our SQL interface over the certificate inventory and other scan data. We started from the public seed IP, built a timeline of the certificates it presented, grouped them by common name, and then widened the by keyword to find new hosts. For each new IP we checked ASN, reverse DNS and Certificate Transparency logs.

A common name made it into our findings only if it passed two of three checks: it matches a reported hostname, it sits on the same IP as a published hostname in the same time window, or it uses a port already tied to the cluster (8083 on the seed IP, which is also the Hestia admin port, or 8443 from the sample analysis). Keywords that returned no rows stayed on the watchlist.

We pulled every certificate our inventory recorded on the seed IP, 38.242.246[.]176, since 1 January 2026, newest first. This gives the raw timeline: which common names the host presented, on which ports, and when.

Same IP, same window, but grouped by common name. For each CN we get the first and last time we saw it and how many times it showed up. This is where the switch from the Contabo default hostname to painel.seu-dominio.com shows up.

Here we left the seed IP and searched the last 180 days of certificates for common names containing tokens from the disclosure (installscenter, infectonline, inboxshop, caixaentrada), matched case-insensitive with a regex. This is the query that returned 80.78.27[.]252.

With the new IP in hand, we grouped every certificate on 80.78.27[.]252 by port, common name and issuer, with first and last seen for each combination. That gives three rows: the panel on 8083 and 8443, and the c2 hostname on 2083.

We ran these queries on 5 September. We haven't seen these certificates on 80.78.27[.]252 in the last 30 days, so running Query 4 with a short time window today may return nothing.

BraZetsu Background: What Was Already Public

BraZetsu is the name Group-IB gave the framework. Their report describes five generations between February and May 2026, Portuguese debug strings, and the shift from a RAT with Run key MonitorSystem (v1) to an IAB platform with 27 functions, most of them enumeration (v5). The count is in the paper and in their 1 September post.

Attribution to Exilware, in the source text, rests on C2 overlap with the shop login panel, reuse of 38.242.246[.]176 with AgenteV2, the Pastebin XOR dead-drop, and distribution filenames (msedge[0-9].exe, wifi_driver.exe). The published reporting rates this attribution as high confidence. We take it as a starting point, not something this hunt tests.

The model described is an initial-access broker. The agent profiles ERP (TOTVS, SAP, Senior, Conta Azul, Sankhya), SCADA traces (WinCC, RSLogix, FactoryTalk), EDR, .pfx/.p12 certificates and CNAB files, and returns a dossier. The buyer drops the payload. The paper describes the scope as Latin America and the Iberian Peninsula, but its evidence points mainly to Brazil, with v2 also targeting Mercado Libre and Mercado Pago domains in Argentina, Mexico and Chile. In April the shop advertised two hosts in the United States; the paper treats that as insufficient to call a change of theatre.

C2 is not hardcoded in the binary. get_server_config() fetches a Pastebin blob, Base64-decodes it and XOR-decrypts with p4st3_s3cr3t_k3y. The result is domain|port|token. The live channel is WebSocket over TLS on 8443. Published raw IDs: aF0WCxia, hM0nXNBP, 9ChwVzzw.

The report's IOC section also lists sixteen SHA-256 hashes, and the body names caixaentradas1inboxshop.site, port 8443, the XOR key and the Run key. They enter the detection pack. They did not go through HuntSQL: the inventory does not see hashes or Pastebin.

80.78.27[.]252, painel.installscenter.com, painel.seu-dominio.com and ports 8083 and 2083 are not on the original report's list. We found them in this hunt.

Infrastructure by Role and Confidence

The seed IP: from a Contabo default to a Portuguese panel name

Grouping the certificates on 38.242.246[.]176 by common name (Query 2) returns two CNs, one after the other, with no overlap.

The first is vmi3003111.contaboserver.net, the default hostname Contabo assigns to its VPS. We saw it 80 times between 4 January and 2 February, which points to continuous TLS service on the host.

On 11 February the CN changed to painel.seu-dominio.com, on port 8083. "Seu domínio" is Portuguese for "your domain", the placeholder used in Portuguese-language hosting tutorials. We saw it 17 times through 17 March.

The Figure 6 series (17 Mar, 14 Mar, 11 Mar, 8 Mar, 4 Mar, 1 Mar, 26 Feb twice, 22 Feb, 18 Feb) fits a panel left running, not a short-lived landing page.

On this IP, in this cut, the inventory does not return c2.installscenter.com. Two readings fit. The Contabo VPS hosted the panel (and, according to the published reporting, infect.online before that) while the named C2 had already left. Or C2 on this IP used a certificate whose CN does not carry "c2". The table does not decide. What it does show: from mid-February this address presents a Hestia Control Panel certificate with a Portuguese placeholder name on 8083, the same panel setup the second host runs later.

The new host: panel and C2 on 80.78.27[.]252

Query 3 is what took the hunt off the seed IP. Searching certificate common names for tokens from the disclosure returned 80.78.27[.]252, presenting painel.installscenter.com on port 8083 with a Let's Encrypt certificate on 9, 10 and 12 June (Figure 3).

The interface didn't return a total count for that query, so there may be more matches over the 180-day window than the page we captured.

Grouping every certificate on that IP by port and CN (Query 4) returns three combinations:

c2.installscenter.com is the C2 hostname from the published reporting. Finding it on a different IP means the name moved to a new address, which fits what was published and doesn't contradict it.

What's new is painel.installscenter.com on the same IP and the same apex. It puts a Hestia Control Panel hostname and the C2 hostname side by side on one host. The ports are split by role too: 2083 under the c2 name, 8083 and 8443 under the panel name. 8443 matches the WebSocket port from the sample analysis.

Our SSL history on the IP shows two different certificates for the c2 hostname on 2083: the first, issued by Let's Encrypt R13 on 22 March, was seen from 4 April to 17 May. The second, issued on 21 May, was seen from 22 May to 4 June. The panel presented a single certificate on 8083 and 8443, seen from 6 April to 18 June.

Pivot on 80.78.27[.]252

Njalla is a privacy-focused hosting provider. The reverse DNS name, 504e1bfc.host.njalla.net, is just the IP written in hex (50 4e 1b fc), and every host in the block gets one built the same way. It doesn't tell us anything specific this server.

The same goes for the provider. Landing on Njalla tells us what kind of hosting the operator chose, not who the operator is.

The c2 certificate was issued 13 days before our scans first saw it on this IP.

WHOIS records the creation of installscenter.com on 21 March 2026, through Tucows. The hostname resolves to Cloudflare today.

Passive DNS helps explain it. Our records show c2.installscenter[.]com resolving to 80.78.27[.]252 between 22 and 26 March, and to Cloudflare (104.21.78.246, 172.67.138.224) from 26 March on. The only A record we have for painel.installscenter[.]com is Cloudflare, from 21 March.

From late March, resolving these names returned Cloudflare addresses. The origin IP kept presenting the installscenter.com certificates to our scans until June.

2083 and 8443 are on Cloudflare's list of proxied HTTPS ports; 8083 is not. That is consistent with C2 and the WebSocket channel going through Cloudflare while the Hestia admin port was reached directly. We didn't observe the agent's traffic, so this is a reading of the port choice, not a finding.

Dates combine our scan data, CT logs and the published reporting.

80.78.27[.]252 does not resolve caixaentradas1inboxshop.site. That delivery domain sits in the body of the paper and belongs to another phase of the chain (the report links it to an Ousaban sample delivered from the same domain). It is also not the historical A record of infect.online; research places that role on 38.242.246[.]176. Our scan history shows this IP was used by others before, including a 2024 certificate unrelated to this cluster. The operator window runs from 21 March to 20 June, and all TLS ports went quiet between 16 and 20 June.

SSH host keys follow the same window. One key set is first seen on 30 March and last seen on 20 June, the day the TLS services went quiet. A different key set appears from 24 July. We can't tie these keys to an operator; the overlap in dates is the only link.

On the seed IP the host key changed on 4 February and that key was last seen on 20 March. The Contabo default certificate was already served on 8083 and 8443 in January, so the Hestia setup predates that change.

Today the IP serves an nginx Laravel login on port 80 and a different SSH key. We see no installscenter.com certificates on it.

Operational reading, medium confidence: the cluster likely left a Contabo VPS already described in public reporting for a Njalla VPS, kept the same Hestia Control Panel setup, and gave the panel a name on the same apex as the C2 instead of the seu-dominio.com placeholder. That does not identify the operator, does not assign the whole /24 to the shop, and does not claim a marketplace code change.

Why the Hostnames Outlast the Binaries

BraZetsu changed its version. Five generations in four months. The binary changes, the hash changes, the Pastebin drop can be swapped in a commit. What does not change at the same rate is the name the buyer uses to reach the panel and the name the agent uses to reach the server. Those names need a certificate.

The buyer needs a URL that still exists the day. The agent needs a hostname the dead-drop still points at. Both incentives push toward apex reuse. Rotation stays on the IPv4. That is what Figures 5 and 4 show in sequence.

painel.seu-dominio.com is the self-signed certificate Hestia Control Panel generated for the hostname set at install, likely copied from a Portuguese tutorial. Seventeen observations on the same IP suggest the panel stayed up for weeks. Query 3, in the photographed cut, did not return it to another address. It remains a hunt clause. It is not proof of migration.

The arrow between painel.seu-dominio.com and installscenter.com is habit plus sequence. It is not a shared certificate.

The shop sells the foothold. Ransomware, banking fraud, CNAB remittance rewriting and stolen A1-certificate use can be run by someone who never touched the BraZetsu code. v5 profiles EDR: the incentive is to avoid the already-monitored machine. The two U.S. hosts in April do not authorize writing that the victim perimeter matches the operator's language. They also do not authorize declaring a change of theatre.

We didn't access the panels, so we have no page content from ports 8083 or 8443.

We didn't access the panels, so we have no page content from ports 8083 or 8443.

The certificates on both hosts a JA4X, but it's the generic Let's Encrypt profile, so it doesn't link them. The pivot view shows why: the JA4X value has a count of 13 million, and the R12 and R13 issuers counts in the hundreds of thousands. Both hosts also JARM fingerprints on 8083 and 8443, which points to the same Hestia Control Panel setup, not necessarily the same operator.

The certificates on both hosts a JA4X, but it's the generic Let's Encrypt profile, so it doesn't link them. The pivot view shows why: the JA4X value has a count of 13 million, and the R12 and R13 issuers counts in the hundreds of thousands. Both hosts also JARM fingerprints on 8083 and 8443, which points to the same Hestia Control Panel setup, not necessarily the same operator.

Indicators of Compromise

Defanged. Table 1 is the seed from the published reporting. Table 2 is what our inventory added. Table 3 and the sample hashes come from the body of the report.

Table 1: Seed (published indicators)

Table 2: Added by our inventory

Table 3: From the report body

MITRE ATT&CK Mapping and Detection

Hashes from this cluster changed across five versions in four months, so they won't hold for long. What held from February to June was the naming and hosting pattern: a painel. or c2. prefix, a non-standard port, a Hestia Control Panel setup on a VPS, and sometimes a request to pastebin.com/raw/ right before.

The logic below is generic. Adapt the field names to your SIEM.

Hestia Control Panel uses 8083 as its admin port by default, and many legitimate Portuguese-language servers name it painel.*. Expect false positives on the SNI condition and review hits before blocking.

Since late March c2.installscenter.com resolves to Cloudflare, so connections through it go to Cloudflare addresses (AS13335). The ASN condition only catches direct connections to the origin; the hostname and SNI conditions still apply.

Re-run Query 3 weekly and alert on any new painel.* or c2.* certificate on ports 2083, 8083 or 8443.

Re-run Query 3 weekly and alert on any new painel.* or c2.* certificate on ports 2083, 8083 or 8443.

Pivot on the installscenter.com certificate hashes in the IOC table to look for other hosts.

Pivot on the installscenter.com certificate hashes in the IOC table to look for other hosts.

Add IPs to blocklists with a first-seen date and a review date. This infrastructure rotates.

Add IPs to blocklists with a first-seen date and a review date. This infrastructure rotates.

Look for unsigned executables compiled with Nuitka, Chromium History files copied into %TEMP%, enumeration of .pfx files, and a Run key value named MonitorSystem.

Look for unsigned executables compiled with Nuitka, Chromium History files copied into %TEMP%, enumeration of .pfx files, and a Run key value named MonitorSystem.

Isolate the host and preserve %TEMP% and the Run key before cleanup.

Isolate the host and preserve %TEMP% and the Run key before cleanup.

Assume the access may already have been sold, and check for follow-on activity from other actors.

Assume the access may already have been sold, and check for follow-on activity from other actors.

The public reporting gave us three things to work from: the C2 hostname, the IP tied to it early in the year, and the shop both of them served. Our certificate inventory showed what happened to that hostname after the first VPS went quiet. It showed up on a new host in a different provider, with a control panel on the same apex.

The TLS services on 80.78.27[.]252 went quiet after 20 June. The pattern is more stable: a painel. or c2. prefix on a port that isn't 443, on a VPS running Hestia Control Panel. It held from February to June across two providers, and that's what we'd build detection on, not the IP.

CT logs show wildcard certificates for *.installscenter.com from Let's Encrypt and Google Trust Services, the latest issued on 2 October. With Cloudflare nameservers on the domain, that is consistent with the zone still being active on Cloudflare. It doesn't show the C2 is live, but the hostnames are worth keeping on blocklists.

If you want to run these queries against your own seeds, or set up alerts for new painel.* and c2.* certificates on those ports, book a demo and we'll walk through the HuntSQL workflow with your team.

Hunting C2 Panels: Beginner’s Guide for Identifying Command and Control Dashboards

Hunt.io Exposes and Analyzes ERMAC V3.0 Banking Trojan Full Source Code Leak

How SSL Intelligence and SSL History Can Supercharge Threat Hunting

Threat Hunting Platform

Threat Hunting Platform

Threat Hunting Platform