Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Hunt.io says it first observed the hostname c2.installscenter.com presenting TLS on a second VPS on April 4, 2026—nearly five months before Group-IB published its BraZetsu analysis on August 31. The finding came from correlating certificates, hostnames, ports, DNS history and hosting details, not from a new reverse-engineering analysis of the malware. It expands the historical infrastructure picture; it does not prove who operated the servers or that they remain active.

How Hunt.io found the additional infrastructure

Group-IB’s August 31, 2026 analysis supplied the starting indicators. Hunt.io’s investigation, published October 6, says it used the published seed IP and hostnames to build certificate timelines in its own inventory, then widened the search through hostname tokens and newly identified IP addresses. It checked those addresses against ASN information, reverse DNS and Certificate Transparency records.

Hunt.io says it did not reverse-engineer BraZetsu again. Its method was infrastructure correlation: looking for related services and names across time rather than treating a published IP or file indicator as the whole cluster.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How candidate hostnames were assessed

For a common name to qualify for inclusion, Hunt.io required at least two of three conditions: it matched a reported hostname; it shared an IP with a published hostname during the same time window; or it used a port already associated with the cluster. That threshold provides a reproducible basis for expanding the set, but it is not proof that every correlated server had the same operator.

What the infrastructure timeline shows

Date Observation reported by Hunt.io What it establishes
January 4–February 2, 2026 Hunt.io’s inventory recorded the Contabo default hostname on seed IP 38.242.246[.]176 80 times. A recurring certificate-inventory observation on the published seed IP.
February 11–March 17 The certificate common name changed to painel.seu-dominio.com on port 8083. Hunt.io recorded 17 observations at intervals of two to four days. Repeated sightings are consistent with a control panel left running, rather than a brief landing page; that is Hunt.io’s interpretation of the pattern.
March 21–22 Hunt.io places registration of installscenter.com and Let’s Encrypt certificate issuance for painel.installscenter.com and c2.installscenter.com on these dates. It associates the new host, 80.78.27[.]252, with Njalla. A new domain and host appeared in the investigation’s infrastructure timeline.
March 22–26 Hunt.io’s passive-DNS data shows c2.installscenter.com resolving to 80.78.27[.]252 before it moved behind Cloudflare. The DNS history links the hostname to that IP during the stated window; it does not establish the hostname’s current destination.
April 4 Hunt.io first observed c2.installscenter.com presenting TLS on port 2083 at 80.78.27[.]252. This is the key early observation: it predates Group-IB’s public analysis on August 31 by nearly five months.
April 6 onward Hunt.io identified painel.installscenter.com on ports 8443 and 8083 at the same IP. The C2 and panel hostnames were observed on one host and apex domain. Hunt.io notes that 8083 is Hestia Control Panel’s default admin port and that 8443 also matches the WebSocket port described in Group-IB’s sample analysis.
June 16–20 Hunt.io says TLS services at the second IP went quiet by June 20. Its report also notes wildcard certificates for the domain issued as recently as October 2. A later certificate alone does not show that the C2 was live; Hunt.io says the old TLS services had gone quiet.

The sequence matters because the April observation is a dated, direct infrastructure observation by Hunt.io—not evidence that the company knew the malware’s full role before Group-IB’s report. Hunt.io describes the relationship between the earlier and later infrastructure as a migration or continuity interpretation with medium confidence.

What the pattern can—and cannot—tell defenders

Hunt.io’s proposed durable clue is a combination: a painel. or c2. hostname prefix, a service on a port other than 443, and a VPS running Hestia Control Panel. It says this pattern held from February to June across two providers and is a better detection basis than one IP address. That is a case-specific analytical recommendation, not a claim that the pattern uniquely identifies BraZetsu.

Signal Defensive value in this case Limit
IP address Useful for checking historical DNS, scan and connection records against the dated observations. Infrastructure can change, and Hunt.io says the second host’s TLS services went quiet by June. Do not treat a historical IP as proof of current activity.
Hostname convention Searching for related painel. and c2. names can expose infrastructure missed by an IP-only view. Prefixes such as painel. are not unique to malicious servers.
Ports and panel configuration Non-443 services and Hestia-related ports can add context when they coincide with matching names, time windows and other cluster indicators. Port 8083 and similar panel fingerprints can appear on unrelated systems; a match alone is insufficient.
Certificates and DNS history Time-stamped certificate inventory, Certificate Transparency and passive-DNS data can connect names and addresses across infrastructure changes. Common Let’s Encrypt fingerprints are generic. Hunt.io says those fingerprints do not link the two hosts to one operator.

Hunt.io also reports similar JARM fingerprints on ports 8083 and 8443. It interprets these as consistent with a similar Hestia setup, not as proof that the servers had the same operator. The company says it did not access the panels and recovered no victim data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What BraZetsu does, according to Group-IB

Group-IB describes BraZetsu as a Windows malware framework compiled from Python with Nuitka. Its researchers tracked five versions from February through May 2026, with capabilities progressing from basic remote access toward broader reconnaissance for initial-access-broker operations. Group-IB attributes the framework to the Brazilian actor Exilware with high confidence; that is Group-IB’s assessment, not an independently established identity.

Reconnaissance aimed at assessing compromised systems

Group-IB says the framework profiles systems for commercial value, including banking, ERP, e-commerce, industrial and SCADA environments, as well as security products. Reported discovery includes browser history, CNAB financial remittance files and digital certificates such as .pfx and .p12. Group-IB reports 27 distinct functions in the latest version it analyzed, most related to enumeration and reconnaissance.

Keep BraZetsu distinct from CNABHunter

Group-IB describes BraZetsu as an initial-access-broker framework, not a financial fraud tool. It reports a Pastebin dead drop used to retrieve a Base64-encoded, XOR-obfuscated C2 configuration and a WebSocket connection over TLS. CNABHunter is a separate fraud-oriented tool. Reported directory overlap does not mean BraZetsu itself autonomously edits payment instructions.

Group-IB describes the Infected Marketplace as a venue where customers can buy access to compromised hosts and may deploy secondary payloads. It reports a minimum BRL 30 deposit through NowPayments; that amount is a marketplace deposit, not a reported victim loss or a price for any one compromised host.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How defenders can apply the findings

  1. Start with dated indicators. Keep the relevant hostnames, defanged IPs, ports and observation dates together. Record whether each item is a direct scan, certificate, DNS observation or analytical inference.
  2. Enrich rather than block on one match. Review certificate and DNS histories alongside IP reputation, hosting details and any matching hostname or port pattern. Use Hunt.io’s stated two-of-three hostname qualification as an example of requiring multiple supporting conditions, not as a universal rule.
  3. Search for patterns in your telemetry. Where available, examine certificate-inventory results and historical DNS for related painel. and c2. names, then check whether relevant services use non-443 ports. Monitor unusual outbound connections to validated hostnames and ports.
  4. Correlate network findings with endpoint behavior. Group-IB’s reported BraZetsu behaviors—including software and registry enumeration, browser-history collection and certificate-file discovery—can help analysts assess whether a network lead is relevant. Group-IB’s published analysis does not provide detection rules or a validated signature for these behaviors, so treat them as investigation leads rather than a ready-made alert.
  5. Revalidate before taking action. Confirm that an indicator still resolves or responds and assess the service’s current context before blocking an IP. Hunt.io warns that legitimate Portuguese-language servers may use painel.* names or port 8083, creating false positives.

The practical lesson is to preserve the time dimension: an IP or hostname can become stale, while a cluster of naming, certificate, DNS and service clues may remain useful for finding related infrastructure. Every match still needs analyst review, especially when the evidence supports a shared setup more strongly than it supports a shared operator.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.