Threat Actor Fully Identified & Reported
Your entire operation has been forensically analyzed, documented, and reported to the relevant authorities and hosting providers. Every backdoor, every binary, every cron job, every IP address — we have it all. This page now sits where your malware used to be.
| IP Address | Location | Type | ISP / Organization |
|---|---|---|---|
| 157.66.54.26 | Bogor, West Java, Indonesia | ★ REAL IP | CV Andhika Pratama Sanggoro |
| 157.66.54.6 | Bogor, West Java, Indonesia | Same Network | CV Mico Digital Indonesia |
| 157.66.54.30 | Bogor, West Java, Indonesia | Same Network | CV Mico Digital Indonesia |
| 157.66.54.106 | Bogor, West Java, Indonesia | Hosting | webhostingindonesia.co.id |
| 157.66.54.162 | Bogor, West Java, Indonesia | Proxy | CV Mico Digital Indonesia |
| 45.80.187.39 | Hong Kong / Vietnam (VPN exit) | VPN — PacketHub | Identified in 19 seconds flat |
| 45.132.255.10 | Moscow, Russia | cPanel Intrusion | First Server Limited • AS205090 |
45.132.255.10 (Moscow) — initial compromiseP1p1.php in sodium_compatlib-update deployed to 49 serversweb.log deployed — Vietnamese gambling redirectsmega@DESKTOP-2OII6D4 planted after first cleanup attemptgs-dbus reverse shell deployed (timestomped to 2012)[kstrp] GSSocket. All malware removed. This page deployed.All evidence has been preserved and submitted to CERT teams, hosting abuse departments, and law enforcement channels. Your infrastructure fingerprints (C2 domains, binary hashes, SSH keys, IP addresses, operational patterns) are now in shared threat intelligence feeds.
If you attempt to re-compromise these systems, you will be providing additional evidence that strengthens the case against you. Walk away.
Seluruh operasi Anda telah dianalisis secara forensik, didokumentasikan, dan dilaporkan kepada pihak berwenang dan penyedia hosting terkait. Setiap backdoor, setiap binary, setiap cron job, setiap alamat IP — kami memiliki semuanya.
Bukti digital yang kami kumpulkan meliputi: server C2 Anda (j.sjzgyw.com, jump.app-test.cc, aagame.fun), binary cryptominer (lib-update, [kstrp]), kunci SSH yang Anda tanam (mega@DESKTOP-2OII6D4), dan alamat IP asli Anda:
★ 157.66.54.26 — IP Asli — Bogor, Jawa Barat, Indonesia — CV Andhika Pratama Sanggoro
• 157.66.54.6 / 157.66.54.30 / 157.66.54.162 — Jaringan yang sama — CV Mico Digital Indonesia
• 157.66.54.106 — Hosting — webhostingindonesia.co.id
• 45.80.187.39 — VPN (PacketHub, Hong Kong) — teridentifikasi dalam 19 detik
• 45.132.255.10 — Proxy Rusia — First Server Limited, Moskow
Jika Anda mencoba menyerang sistem ini lagi, Anda hanya akan menambah bukti yang memperkuat kasus hukum terhadap Anda. Berhentilah sekarang.