Division for Counter Threat Finance and Sanctions - United States Department of State
CIVHUB
52.245.219.198 gfmis government financial m system guam
Ports open: 443, 3389
Login va systems
206.165.69.189 weird russian voip system not related but interesting
Search Engine for the Internet of Things
Whistleblowers
This is what edward is using for gov emails mail-in-a-box/mailinabox: Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server in a box.
The components installed are:
SMTP (postfix), IMAP (Dovecot), CardDAV/CalDAV (Nextcloud), and Exchange ActiveSync (z-push) servers Webmail (Roundcube), mail filter rules (thanks to Roundcube and Dovecot), and email client autoconfig settings (served by nginx) Spam filtering (spamassassin) and greylisting (postgrey) DNS (nsd4) with SPF, DKIM (OpenDKIM), DMARC, DNSSEC, DANE TLSA, MTA-STS, and SSHFP policy records automatically set TLS certificates are automatically provisioned using Let's Encrypt for protecting https and all of the other services on the box Backups (duplicity), firewall (ufw), intrusion protection (fail2ban), and basic system monitoring (munin)
The components installed are:
SMTP (postfix), IMAP (Dovecot), CardDAV/CalDAV (Nextcloud), and Exchange ActiveSync (z-push) servers
Webmail (Roundcube), mail filter rules (thanks to Roundcube and Dovecot), and email client autoconfig settings (served by nginx)
Spam filtering (spamassassin) and greylisting (postgrey)
DNS (nsd4) with SPF, DKIM (OpenDKIM), DMARC, DNSSEC, DANE TLSA, MTA-STS, and SSHFP policy records automatically set
TLS certificates are automatically provisioned using Let's Encrypt for protecting https and all of the other services on the box
Backups (duplicity), firewall (ufw), intrusion protection (fail2ban), and basic system monitoring (munin)
cloudflare/cloudflared: Cloudflare Tunnel client (formerly Argo Tunnel)
Cloudflare Tunnel, a tunneling daemon that proxies traffic from the Cloudflare network to your origins. This daemon sits between Cloudflare network and your origin (e.g. a webserver). Cloudflare attracts client requests and sends them to you via this daemon, without requiring you to poke holes on your firewall --- your origin can remain as closed as possible.
Cloudflare Tunnel, a tunneling daemon that proxies traffic from the Cloudflare network to your origins.
This daemon sits between Cloudflare network and your origin (e.g. a webserver). Cloudflare attracts client requests and sends them to you
via this daemon, without requiring you to poke holes on your firewall --- your origin can remain as closed as possible.
GSA eLibrary Contractor Listing artificial intelligence approved contractors including chatbots
Fireworks Splice HTML
62.11.100.105 satods web app v2
Ports open: 3389
62.11.97.15 satods web app j19 - feb9 3389 rdp
Ports open: 3389
SATODS-WEB-APP-
History: 62.11.96.174 satods web
Search Engine for the Internet of Things
62.11.27.146 satods 3389 rdp
Ports open: 3389
Windows 10 (version 1809)/Windows Server 2019 (version 1809)
OS Build: 10.0.17763
CN=FP-SATODS-Deplo
62.10.100.128 darktrace federal azure cloud....first came online jan 14, last seen 1/22 one day before first email, it could line up with email dates: j24,26,28 opm
Ports open: 25
Shodan Search VA BGP started 1/12/2025
9 results found for search query: isp:"U.S. Department of Veterans Affairs" product:"BGP"
152.124.240.1 veterans affairs 195 days port 139 observed 1/23
Ports open: 161
History: 152.130.240.1 veterans affairs 161 upd 578 days up without observation
Search Engine for the Internet of Things
History: 20.140.188.5 1/27/2025 early same day as i think second test email
Search Engine for the Internet of Things
Myjournal-cbp.dhs.gov archive 2 azure....?
20.140.188.5 dhs mail server 2/9/2025 cert
Ports open: 25
151.107.1.117 veterans affairs not sure if related
Ports open: 21, 22, 161, 179, 2000
smtp4dev API
Digital Enablers from pakistan....?
62.10.120.156 NO AUTHENTICATION WTFFFFFF status: sent disclosure email
Ports open: 25, 80, 3389
smtp4dev was able to access MIL ADDRESSES no auth!!!!!!
History: 52.227.170.224 i was looking for opm azure cloud right? started running smtpd on 1/15, 1/21
Search Engine for the Internet of Things
Sign in · GitLab DoD t2s login
T2S Solutions GitLab
t2s-solutions.com
166.165.65.217 dhs self signed sus 1/25 microsoft server and 2/10 rdp
Ports open: 443, 3389
Government republican party of minnesota uses 3cx for phones, didn't i see dhs minnesota?
Check out the 3CX case studies to see how businesses in the Government Sector worldwide are leveraging 3CX to lower telephony costs and more
69.63.170.208 saw-pbx-dhs potential phone system for dhs is 3cx a contractor
Ports open: 135, 137, 445, 3389, 5000, 5001, 5357
SAW-PBX-DHS
104.185.15.11 dhs mail potential
Ports open: 25, 53
Edward Big Balls Github and associates