Known malicious kithighother
Miku / Singapore VPS operator — open-directory toolkit (YARA content anchor)
family: infrahunter-sg-vps-miku-2026-08
A directory listing (Python http.server 'Directory listing for', or nginx/Apache 'Index of /') that exposes two or more of the operator's own tool and output file names. Tool files: New API quota fraud (succeaccounts.txt, ulneurls.txt), asset mapping (classify_assets.py, probe_vps.py, uu_search1), the SOCKS5/HTTP proxy pool (freshen_socks5.py, build_conn_pool.py, build_http_plain.py, refresh_http_pool.sh, glider_socks5.conf, verify3.py). Recon output: ffuf443.json. Matched by a YARA rule on the page HTML.
Anchors
YARA ruleMiku_SG_VPS_OpenDir_Tooling
Provenance
Added: 2026-09-14 09:31
Condition: a listing header AND 2 of 12 exact href="<name>" values. Generic names from the same listings (3000.txt, test_api.py, prune.py, OneForAll/, fscan/, nuclei-templates/, 代理IP.txt) are left out on purpose. Tested against every captured directory-listing page ('Index of /…' and 'Directory listing for…'): it matched only the actor's two listings, and no other page carried even one of the 12 names. The listings expose stolen New API account lists and proxy-pool tooling.