Known malicious kithighother

Miku / Singapore VPS operator — open-directory toolkit (YARA content anchor)

family: infrahunter-sg-vps-miku-2026-08

A directory listing (Python http.server 'Directory listing for', or nginx/Apache 'Index of /') that exposes two or more of the operator's own tool and output file names. Tool files: New API quota fraud (succeaccounts.txt, ulneurls.txt), asset mapping (classify_assets.py, probe_vps.py, uu_search1), the SOCKS5/HTTP proxy pool (freshen_socks5.py, build_conn_pool.py, build_http_plain.py, refresh_http_pool.sh, glider_socks5.conf, verify3.py). Recon output: ffuf443.json. Matched by a YARA rule on the page HTML.

Anchors

YARA ruleMiku_SG_VPS_OpenDir_Tooling

Provenance

Added: 2026-09-14 09:31
Condition: a listing header AND 2 of 12 exact href="<name>" values. Generic names from the same listings (3000.txt, test_api.py, prune.py, OneForAll/, fscan/, nuclei-templates/, 代理IP.txt) are left out on purpose. Tested against every captured directory-listing page ('Index of /…' and 'Directory listing for…'): it matched only the actor's two listings, and no other page carried even one of the 12 names. The listings expose stolen New API account lists and proxy-pool tooling.

Sightings (2)

HostScanScriptMatchWhen
69.48.228.86:90011fd3b5f1…http://69.48.228.86:9001/#htmlyara2026-09-14 09:33
69.48.228.86850a05a5…http://69.48.228.86/#htmlyara2026-09-14 09:33