D Notes BB

prometheus scrape 1
Prometheus scrape 2
Marko Elez async-ip-rotator archive, pushed Jan 1, 2025 removed April 23, 2025
Starlink n doge
canada brief
Twh notes

timeline toc table of contents

DOGE Github Repo Archives of Note

Jordan Wick (the OSINT Persons Archives Are not Entirely Functional so Heres Some others)

Feb 28, 2025 @SollenbergerRC Puts Jordan Wick on Blast

https://threadreaderapp.com/thread/1895609294810464390.html

https://ghostarchive.org/archive/tNvA5

Feb 28, 2025 Jordan Wick Gists Org Chart

https://web.archive.org/web/20250228230950/https://gist.github.com/Jomanw

March 1, 2025 Jordan Wick Github Wayback

https://web.archive.org/web/20250301000617/https://github.com/Jomanw?tab=repositories

Headless browser wasnt properly archived

Marko Elez

Marko Elez async-ip-rotator archive, pushed Jan 1, 2025 removed April 23, 2025

April 23, 2025 captures

Source code for async-headless-browser

Feb 9 capture

https://web.archive.org/web/20250209014408/https://github.com/markoelez/async-ip-rotator/commit/7ce4db636d5b8d9b6e82a8ee91d71669f1d855d3

Marko Elez starred repos captured April 23 just before he deleted

https://web.archive.org/web/20250423140008/https://github.com/markoelez?tab=stars

Repos
https://web.archive.org/web/20250423135845/https://github.com/markoelez?tab=repositories

”Business” Names Used by BB

DiamondCDN, Anchored.host (now Packetware.net), Tesla.sexy

Big Balls Github

https://github.com/edwardc

https://github.com/BigBaIIs

unconfirmed if its him or troll but worth looking into dogegov.dev

https://github.com/edbigballs

Now Broken, Used to Be DOGE.gov Dev Login

doge-sec.cloudflareaccess.com

Aidan Perry Aka @UltraSive

UltraSive on Shitter
references new project Sept 12, 2024 x.com link be careful

UltraSive on Github

UltraSive on Youtube

is main dev and partner at Packetware (though he mentioned not having as much “equity” in business w BB despite doing all the work and bringing his own anchored.host to the table when they merged…?)

Aidan Owns Aqueous Cloud LLC, One upstream Provider Used by Packetware. Hm

Drosoph Consult LLC owned by Aidan’s Brother? Same TX address as Aqueous Cloud

I saw the word Drosoph in the Prisma db so Drosoph=Aidam

Drosoph Consult, LLC

https://opencorporates.com/companies/us_tx/0803440739

2021 - TESLA.SEXY LLC formed

June 2025 - dissolved

I think he was offering DDoS “protection” ie a broker for buying and selling DDoS-for-hire and like usual gang shit

Address listed is his parents house. He didnt even spring for WHOIS anonymity until after he became America’s most punchable bitchboy.

Feb 6, 2025

Wired publishes article drawing attention to Tesla.sexy owned by BB, one of his fronts for doing business w Russian “com” hackers

https://www.wired.com/story/edward-coristine-tesla-sexy-path-networks-doge

Feb 6 also First Day anchored.host (Aidan) Redirects to packetware.net (BB)

https://urlscan.io/result/87a95984-d30f-48ed-b286-042fb069c69b/

Feb 7, 2025 tesla.sexy Comes back Online after 2 Year Hiatus, Presumably as Some Clapback against the Haters

“tlsAgeDays”: 0,
“tlsValidFrom”: “2025-02-06T21:48:23.000Z” issued himself a brand new cert n all

tesla.sexy

https://urlscan.io/result/819862c9-edb5-4d62-8c67-241aff7659d2/

My Article on Kubernetes for Normies, Little Tech Speak

https://open.substack.com/pub/cyberintel/p/i-mapped-the-global-network-big-balls

Prisma Studio Db http://65.108.96.185:5555/

https://s3.us-central-1.wasabisys.com/anchored-cdn/os-images/ubuntu/noble-server-cloudimg-amd64.img

image.png

BB’s GitHub OAuth User Id

76141700

https://api.github.com/user/76141700

goes to edwardc github

Russian User Registered 10/29/2024

image.png

Sus Users to Investigate

João Paulo

8/26/25
inove2pay.com.br

I thought this Brazillian might be related not sure
103.195.102.91
Luiz Roberto da Silva Rosa Santos
https://www.whoxy.com/inove2pay.com.br

https://www.shodan.io/host/103.195.102.91/history?language=en

no email but name

conner.stoltze@gmail.com

2025-07-14T11:11:48.112Z

kk1132650@gmail.com (“j j”)

2025-07-16T09:09:41.146Z

zizoujaouedi123@gmail.com Zizou Zizou

2025-07-18T17:21:03.131Z

SixxHxRx.js 2025-0=7-20

Edward C 2025-08-01 23:12

just 15 minutes later account created:

Mrcomq mrcomq@gmail.com

and next day 2025-08-02

vaskotodorov147@gmail.com

2025-08-03

Peter dri3peter@gmail.com

Lucca Bassoli site ownership

https://www.whoxy.com/name/50514142

image.png

image.png

172.93.110.120

mac BC:24:11:2C:BD:9A

project id

a45bkg9pb95tgb8

host id

2f7ed9af-db4c-4d5a-825a-884eeb1aa49f

103.195.102.88

BC:24:11:E5:32:E0

host id yuqi

103.195.102.86

minecrafthosting24.com
s1.mia.us.minecrafthosting24.com
www.minecrafthosting24.com

Mia—Miami node

94:7a:a2:c2:2d:b6

project id

cm6wck75f000gt901y1lc272k

host id

5746b2dc-6913-4272-bffa-7e15eb9a3f1f

Aidan Public Ssh Key

ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDLiY+FDNaNpYE57ifSccEnKuG6gDp0Sv7mFYXXbt+3l5KqrvuRiuFh40Vy7y9Lvf9EMbR1qyraDabbCfrV8j6GRHNoCl3wvmSvnR2M0tCsK/w50QTTWfrG2Lc2QIbBzDoJW4kIcg2ZA1kPTq8kKGBmwjhn0ztCFqyoDIiNL40o5DeaW09SdfsUA7M/aVNlyc5PG6JH5qdqhijhV8ysq3xBvJywVFH4BcgNF1SzlLNaJZHyKbnaLy4H1MEn7z3r6lhwaPYgxJfCGbrIKKyerGkchwhJDw9iXf7vh8SfW1Wa8XI/Ru+ULPeLYQTK2IwusIieg8Nlr8Uf6Mqu0i9iXxAEj+ydxHHt/blWMO7XfEb3nB4KXIkHEBHhGWMpMHktIKcPSvl1b+Zbe0v/3NtLyjenhFjKwNbKEePRomDLpB1x4I4+shvu8uA0ffbSHIK689GXKpjcaklIHPjEl0UC4BHg7TLI/VVGJ1n0H0vXnwGQ0H8lRqs3Kmz9gwTyzcArzKc= sive@sive-HP-255-G8-Notebook-PC

Belongs to Aidan Projectid a45bkg9pb95tgb8 the Main Project

first api key hash created 2025-01-14T21:34:26.086Z

c048856dff4cfc2cbfbb9b37c9780debeaf95184b6e46e8298b33b12bbc89b1d

second api key hash created 2025-02-19T07:06:15.973Z

38c47683c34e578753a7abc6ba46192ca03dec3913cef413064825a64f041c7f

Notes from Screenpal

https://go.screenpal.com/channels/cTQQqcVZ5l

LONG New Dallas VMs 8/2/25, HypervisorNode, Admin 2/18/25 Fast, Users Fast (Recording #20)

https://go.screenpal.com/watch/cTQiF3no3O0

Look at 10:32, the projectID created 3/29/2024 and updated 2/18/2025 prob Ed or Aidan. it’s a VM with one of few projectIDs not the main one.

13:58 test.delete 1/14/2025, updated 2/18/2025

15:29 viewing raw CANCELED at without sort
16:38 showing very few servers paid for through Stripe. So where are they getting the money for everything else?
18:23 the special project created 3/29/24, updated 2/18/25 when all the admin accounts were created
admin ID #9
20:10 approx 182 admins created 2/18/25

Test Project 2 is Important, Shows IP Rotation and VM Deletion (Recording #25)

https://go.screenpal.com/watch/cTQi36no3EG

Test Project 2 has 154 services, 2 API keys, 1 SSH key, 33 ProxMoxVMs,, (Recording #25)
7:43 nice view of all canceled VMs and IPs
7:58 shows lots of troubleshooting on 1/26/2025 and “vpn-tutorial”
shows IP address rotation of the German SSH 63.x.x.x/24 range

pattern is 3, 5, 7, 9 1 or 2 minutes apart, lives for 2 days before deletion

9:15 shows fresh installs of Ubuntu 7/3/2025
and api (VM)creation and deletion one day later…is the service id for this found in prometheus?
9:20 IPv4 Subnet
9:35 IPv4 Addresses showing gateway, MAC, the 2 main projectIDs have the only assigned IPs
9:48 shows VM names implying infra, there’s a Chinese name VM yuqi
end of video shows users and emails but there’s better vids of this

Feb 24 Same Shit Poetry Posted by BB to Shitter

image.png

https://nitter.net/as400495/status/1893827215168561441#m

nietszche quotes, based, manosphere gettin jacked, russian bots, the usual

prisma

Note the subdomains connected to 65.108.96.185 — analytics, bacon(??), coolify, helsinki (location of a lot of their IPs these days), traefik*** (important for working out how the proxies are working big picture)

image.png

LXC Container Notes

https://www.xda-developers.com/heres-how-i-run-docker-in-an-lxc-on-proxmox/lxc is container inside container

https://www.xda-developers.com/i-use-proxmox-backup-server-with-truenas-over-nfs/