Cross Incident Threat Actor Assessment
Consolidated forensic and open source findings from the Farmoria and Rokstats incidents
One actor cluster links both incidents
The strongest evidence is the reuse of a stable Discord identity, supported by two AT&T residential addresses observed at Farmoria. A later Rokstats log cross-check confirmed HollowArc activity from 107.206.22.143; Rokstats investigators independently reported use of 68.90.146.47 without prior knowledge of its Farmoria connection. The surrounding aliases, domain, e-mail addresses, and public profiles expand the cluster.
Key judgments
- The Farmoria activity was deliberate black box testing and abuse tool development. The operator performed ordered reconnaissance, object identifier enumeration, billing probes, upload tests, account rotation, and ticket and error-report flooding. The observed requests show no clear sign of advanced technical knowledge; the route probing followed publicly known wordlists and easily detectable patterns.
- Farmoria controls prevented unauthorized object access, code execution, and payment abuse. Other users' objects returned only refusal or validation responses. Accepted files were inert test images. The incident caused minor service load and outbound support e-mail amplification, with no confirmed breach.
- The Farmoria account hollowarc. is directly tied to 68.90.146.47. A second account, dbquery., was registered from 107.206.22.143, later used through the same VPN session as the active testing, and carried the e-mail domain meshvision.xyz. A later cross-check of Rokstats logs also confirmed hollowarc. activity from 107.206.22.143 during that separate incident.
- The supplied Rokstats record resolves to the same Discord identity. It records username hollowarc., Discord ID 1070712235770527744, and verified e-mail [email protected]. The record was last seen on 16 September 2026.
- HollowArc was the only account reported to have accessed the vulnerable Rokstats endpoint. That exclusive access makes the account central to the later incident. The HPCane claim and reuse of Farmoria-linked addresses support close coordination, but do not prove the two personas belong to one person.
- D***** M****** is a moderate-confidence person-of-interest lead. The lead warrants further investigation, but no stable identifier independently ties this person or a public profile to the operator.
Business meaning
Observed effects
Farmoria received automated requests that triggered 176 outbound e-mails and abusive ticket creation. The actor also enumerated routes and assets already exposed by the public web application. No service degradation, unauthorized customer data access, admin access, code execution, or payment benefit was confirmed.
Forward risk
The actor demonstrated a repeatable account rotation method and then appeared in a later incident. Blocking individual IPs will slow reuse, while address aware registration controls, per-address rate limits, and identity provider reporting provide the durable response.
One chronology, with proof and uncertainty kept separate
Explore the incident sequence, test each finding against its supporting evidence and alternatives, and review archive-wide leads without promoting automated triage into attribution.
Synchronized incident timeline
Select a marker for evidence, analytic weight and the caveat that limits the claim.
Chronology summary. The retained record begins 26 August; a rehearsal occurs 31 August; residential staging spans 1–5 September; the principal Farmoria test and abuse window occurs 5 September; a probable victim recovery follows on 7 September; return and containment activity occurs 9 September; the supplied Rokstats record is last seen 16 September; cross-incident containment follows 21 September; forensic acquisition closes 23 September.
Complete 18-account sequence
All registration rows are shown. Provider-account ownership is not attributed merely because an identity was used in the automated workflow.
| Reference | Farmoria username | Registered CEST | Observed access path | Classification / disposition |
|---|
Retained origin traffic by day
Archive-wide volume provides context, not attribution. Select a bar for the exact count.
Findings explorer
Filter the judgments; every row includes the competing explanation or evidence gap.
Signals that were easy to underweight
These change detection and response priorities even where they do not change attribution.
The earlier VPN session shared the later ordered target list, limiter testing and naming pattern. Treating it as generic scanning would miss five days of preparation.
Pricing and build retrieval on residential addresses looked harmless until the same paths became account anchors and resurfaced in the cross-incident record.
The 7 September recovery/deletion sequence means provider identities must be protected and remediated, not published wholesale as actor IOCs.
Origin evidence begins 26 August, not 27 August as previously summarized. No known-actor event was promoted from that extra day, and earlier or Cloudflare-blocked activity still cannot be disproved.
Attack-surface outcomes
Attempt, observed result and residual gap are kept in separate columns.
| Surface | Target | Observed action | Outcome | Confidence |
|---|
The follow-on incident, separated by evidence type
The supplied account record is directly observed, and a later Rokstats log cross-check confirmed HollowArc activity from 107.206.22.143. Reuse of 68.90.146.47 and exclusive endpoint access remain reported findings. Exploit mechanics remain unresolved without the full endpoint request records.
| Evidence item | Observed or reported value | Weight | Meaning and limit | Source class |
|---|
Application-log corroboration
Aggregate-only scan of dated Laravel, support, billing and Stripe logs; no raw messages or secret values are embedded.
| Category | Matching log lines | Use |
|---|
Cross-incident relationship register
Stable identifiers carry more weight than aliases, location or an IP address in isolation.
| Entity | Related entity | Weight | Basis |
|---|
Archive-wide triage leads
High-signal route and automation heuristics from the complete retained nginx set. These are investigation leads, not confirmed HollowArc activity.
| Address | Window | Requests flagged | High-signal reasons | Representative paths |
|---|
Host-level Internet background
Authentication, firewall and ban telemetry is separated from the HollowArc cluster unless an independent identifier overlaps.
| Signal | Source address | Events | Assessment |
|---|
Known infrastructure in the full retained window
Observed counts and path families are generated from the acquired access-log rotations.
| Address | Role | First / last seen | Requests | Dominant flagged behavior |
|---|
The stable account is the central bridge
Follow the account from Farmoria to Rokstats. The account and address links are separate from HPCane's later claim about the Rokstats endpoint.
| Link | Assessment | Basis |
|---|---|---|
| hollowarc. to Farmoria | Confirmed | Farmoria OAuth record tied the account to 68.90.146.47 and Discord ID 1070712235770527744. |
| hollowarc. to Rokstats record | Confirmed | Exact username and Discord ID in the account record shared by Rokstats, with a provider verified e-mail. |
| Farmoria to Rokstats activity | High | Same stable identity, log-confirmed HollowArc use of 107.206.22.143 in the later incident, independently reported use of 68.90.146.47 before its Farmoria connection was known, and reported exclusive vulnerable endpoint access. |
| meshvision.xyz to dbquery. | Confirmed | The Farmoria account used [email protected]. This confirms use of a domain e-mail address, not domain ownership. |
| meshvision.xyz to HollowArc | Low · indirect | A reported BreachForums appearance adds an indirect online association. No domain ownership or control has been verified. |
| HPCane to HollowArc | Moderate | HPCane claimed the Rokstats attack, while HollowArc was reportedly the sole account accessing the vulnerable endpoint. A false claim or coordination remains possible. |
| Arcane to the incidents | Inconclusive | No stable identifier, infrastructure, or observed server action connects Arcane. We do not currently suspect involvement, but the available evidence cannot rule it out. |
Farmoria preceded the Rokstats follow on
Times from Farmoria are shown in CEST. Database timestamps were converted from UTC in the source forensic report. Rokstats record times remain UTC where stated.
First Farmoria working session
173.245.217.11 performed reconnaissance, framework and admin path guessing, public library enumeration, login limiter testing, and targeted e-mail guessing. The session shared the later toolchain and naming pattern.
First residential connection
107.206.22.143 opened Farmoria pricing content.
HollowArc account created at Farmoria
68.90.146.47 registered hollowarc., loaded the frontend build, and reviewed plans. No active probing occurred in this session.
Second residential account created
107.206.22.143 registered dbquery. with [email protected].
Active Farmoria test and abuse script development
108.171.110.79 carried out route discovery, object identifier walks, billing probes, upload tests, rapid account creation, ticket flooding, and error-report flooding.
Residential and VPN sessions linked
The dbquery. account created from 107.206.22.143 became active through 108.171.110.79.
Fifteen OAuth accounts created in 69 seconds
The account pool enabled per-user rate limit evasion.
Error-report flood accepted
4,919 requests were sent and 3,689 returned 204 without a 429. The endpoint returned no data and production logging discarded the accepted report bodies.
Probable identity owner deleted one account
A different user on a Mexican mobile network used Google sign-in, viewed privacy information, reset a password, and deleted an account created in the burst. This supports the assessment that many OAuth identities were compromised.
Return check from 107.206.22.143
The address fetched static assets only, consistent with checking whether the site still loaded.
Farmoria containment
Seventeen accounts and four addresses were banned for multi-account abuse.
Rokstats follow-on activity
A later Rokstats log cross-check confirmed HollowArc activity from 107.206.22.143. Rokstats investigators also independently identified 68.90.146.47 in their incident and reported that HollowArc alone accessed the vulnerable endpoint. The persona HPCane later claimed the attack.
Rokstats account record updated and last seen
The account record shared by Rokstats for hollowarc. carries this update and last-seen timestamp.
Farmoria HollowArc account banned
User 203 was banned after the cross-organization tip linked the account to the subsequent incident.
Reconnaissance progressed into automated abuse testing
Farmoria's retained request logs show a rehearsal, two account signups from residential connections, and a two-hour VPN session that progressed from route testing to account rotation and support and error-report flooding. The testing exposed scaling weaknesses but did not produce confirmed cross-tenant access or code execution.
Farmoria recorded hollowarc. signing up from 68.90.146.47 and dbquery. signing up from 107.206.22.143. The dbquery. account then appeared in the active VPN session. Rokstats separately found the same HollowArc Discord ID, confirmed later account activity from 107.206.22.143, and independently reported use of 68.90.146.47. The earlier rehearsal and other rotated accounts are linked by behavior and session records, not by a direct HollowArc login from every address.
Observed entity relationship map
The exact provider ID appears in both the Farmoria and Rokstats account records.
Account creation and testing
- 68.90.146.47registeredhollowarc.Confirmed Farmoria OAuth record
- 107.206.22.143registereddbquery.Confirmed Farmoria account record
- dbquery.used108.171.110.79Authenticated in the active VPN testing session
- 108.171.110.79droveaccount poolRapid registrations, tickets, uploads, and error-report flood
- 173.245.217.11testedFarmoriaEarlier VPN rehearsal; linked by sequence and behavior, not a stable account ID
- dbquery.used e-mail atmeshvision.xyzConfirmed address use; domain ownership is unverified
Same account, later endpoint
- hollowarc.matchesRokstats accountExact Discord ID in the account record shared by Rokstats
- 107.206.22.143used byhollowarc.Confirmed by the later Rokstats log cross-check
- 68.90.146.47used byhollowarc.Independently reported by Rokstats investigators before the Farmoria match was known
- hollowarc.accessedvulnerable endpointRokstats reported it was the only account to access that endpoint
- HPCaneclaimed hack ofthat endpointPublic claim; no stable ID proves control of the HollowArc account
Technical attack chain
| Phase and time (CEST) | Actor action | Technical result |
|---|---|---|
| Rehearsal 31 Aug, 05:07-05:51 | From 173.245.217.11, the operator requested marketing pages, robots.txt, sitemaps, authentication routes, /api/user, /health, public library records, developer paths, admin paths, and common Laravel tooling. The session issued 1,692 requests and 497 POST /login attempts. | Developer and sensitive paths returned 403, 404, or 405. Of the login posts, 324 failed CSRF handling, 97 were rate limited, and 76 reached real credential validation; none authenticated. |
| Residential staging 1-5 Sep | 107.206.22.143 first viewed pricing and later registered dbquery.. 68.90.146.47 registered hollowarc., downloaded 444 frontend assets, and reviewed plans. The dbquery. account used [email protected]. | Two AT&T residential connections established the accounts and exposed the frontend route and feature structure before the active VPN session. |
| Route discovery 5 Sep, 05:02-05:29 | From 108.171.110.79, curl tested OAuth providers, referrals, /admin, Nova, Horizon, Telescope, Pulse, log-viewer APIs, storage, exports, WebAuthn, impersonation, automation, command-chain, and account-request routes. | Protected tooling stayed unavailable. Responses were predominantly 403, 404, 405, 419, or 422. One WebAuthn request returned the incident's only 503. |
| Object and billing tests 5 Sep, 05:24-05:50 | The operator walked governor, session, export, account-health, bot, worker, configuration, and marketplace-slot identifiers, including slots 1-200. Coupon validation, checkout, referral, and a forged Stripe webhook were also tested. | Roughly 270 object-oriented requests produced no unauthorized 200 response. Other users' objects remained inaccessible, and no coupon, subscription, referral, or payment benefit was created. |
| Attachment tests 5 Sep, 06:02-06:18 | The operator sent a malformed upload, targeted a ticket belonging to another user, uploaded a six-byte GIF, tried an unsupported type, and then stored a 70-byte 1×1 PNG. | The cross-user ticket returned 404, the unsupported type was rejected by content sniffing, and the accepted GIF and PNG were inert. No executable content or web shell was stored. |
| Account pool assembly 5 Sep, 06:36:23-06:37:32 | Fifteen Discord accounts were registered in 69 seconds. Across the session, sixteen accounts completed 102 OAuth round trips from the same VPN address. | Registration applied no address-based delay, challenge, or rate limit. The operator acquired enough accounts to multiply limits enforced per user. |
| Ticket script verification 5 Sep, 06:02-07:00 | Twenty-four tickets used labels such as “abuse test,” “ticket flood script test,” “script fix verification,” and “single account isolate.” At 06:54, fifteen fresh accounts each created a ticket, uploaded the same PNG, and closed the ticket in a timed sequence. | Single-account throttling generated 25 refusals, while rotation through fresh accounts permitted the scripted series. The workflow generated 176 outbound support e-mail events. |
| Error-report flood 5 Sep, 06:40-07:00 | The account pool sent 4,919 requests to POST /client-errors at roughly 460 requests per minute. | 3,689 requests returned 204 and none returned 429. The endpoint returned no response data; accepted report bodies were discarded at the production log level. |
| Return and containment 9-21 Sep | 107.206.22.143 returned for static assets on 9 September. Farmoria banned seventeen pool accounts and four addresses that day, then banned hollowarc. after the cross-organization notification on 21 September. | The static-only return is consistent with a post-incident availability check. Administrative containment stopped the known accounts and access paths. |
Access paths and their limits
| Address | Network and role | Observed activity and cross-incident link |
|---|---|---|
| 173.245.217.11 | Netprotect consumer VPN exit | Earlier rehearsal session: 1,692 requests, reconnaissance, login testing, and targeted guessing. |
| 107.206.22.143 | AT&T broadband; likely residential access | At Farmoria: pricing reconnaissance, dbquery. registration, and a later return check; that account crossed to the active VPN session. A separate Rokstats log cross-check confirmed later hollowarc. account activity from this address. |
| 68.90.146.47 | AT&T US residential range | At Farmoria: hollowarc. registration, 444 frontend asset requests, and plan views. Rokstats investigators independently reported use of this address in their incident. |
| 108.171.110.79 | Netprotect consumer VPN exit | 6,687 requests and all active exploitation tests, account rotation, ticket creation, uploads, and error-report flooding. |
| 200.63.47.185 200.63.46.202 | ALTAN Redes Mexican mobile carrier | Probable legitimate identity owner. The behavior supports lifting blocks on these addresses. |
What the shared provider tells us. ARIN registers both 107.206.22.143 and 68.90.146.47 to AT&T. The reverse-DNS naming for 107.206.22.143 is consistent with consumer broadband, making residential-style access likely for that address. AT&T serves many subscribers, so the shared provider does not show that the same person, household, or subscription used both connections. The account and log matches carry the cross-incident link. These network lookups establish neither a location nor whether either connection was shared or used as a proxy. See S14.
Farmoria identity and network joins
| Observed join | Why it matters | Confidence |
|---|---|---|
| 68.90.146.47 → hollowarc. | The residential address created the exact account later present in the Rokstats evidence, with stable Discord provider ID 1070712235770527744. | Confirmed |
| 107.206.22.143 → dbquery. | The second residential address created the account using [email protected], connecting the attack pool to an e-mail address at that domain without establishing domain ownership. | Confirmed |
| dbquery. → 108.171.110.79 | The same account created from the residential address was authenticated during the active VPN testing session between 05:29 and 06:01. | Confirmed |
| 108.171.110.79 → account pool | All rapid Discord registrations, ticket-script activity, uploads, and the error flood originated from this VPN exit during the two-hour session. | Confirmed |
| hollowarc. → Rokstats account | The exact Discord provider ID appears in both services' account records. | Confirmed |
| 107.206.22.143 → hollowarc. at Rokstats | The later Rokstats log cross-check confirmed use of the Farmoria-linked address by the HollowArc account. | High |
| 68.90.146.47 → hollowarc. at Rokstats | Rokstats investigators independently reported use of the Farmoria signup address before its Farmoria connection was known. | High · reported |
| hollowarc. → Rokstats endpoint | Rokstats reported HollowArc was the only account to access its vulnerable endpoint; full request-level evidence is not included here. | High · reported |
Tool and behavior fingerprints
The active session combined curl/8.17.0, curl/8.21.0, Chrome 152, and a truncated browser user-agent. More distinctive than any single string is the ordered behavior: public route mapping, Laravel tooling probes, object-ID walks, dummy addresses such as <purpose>[email protected], timed OAuth loops, self-describing ticket names, one-ticket-per-account rotation, and a final single-account control run. This sequence supports correlation if it reappears in later server logs.
Techniques and results
| Technique | What happened | Outcome |
|---|---|---|
| Route and debug discovery | Framework, admin, developer, health, log viewer, Telescope, Pulse, storage, and webhook paths were tested. | All sensitive routes returned 403, 404, 405, or validation errors. |
| Credential guessing | Dummy e-mail patterns and names harvested from a public library were turned into targeted login attempts. | No successful login. Rate limiting stopped repeated guesses, though one customer's exact address was inferable from the display name. |
| Object identifier enumeration | About 270 requests named governors, sessions, exports, health objects, automation rules, bot objects, and marketplace slots. | No unauthorized 200 response. Object-level access control held. |
| Billing and entitlement probes | Coupon, checkout, referral, and forged webhook requests were attempted. | No coupon, subscription, referral, or payment benefit. |
| Upload tests | A bare GIF, one unsupported type, and sixteen identical 1x1 PNGs were submitted. | The GIF and PNGs were inert. The unsupported file was rejected by content sniffing before storage. No code execution or web shell. |
| Rapid OAuth registration | Fifteen Discord registrations completed in 69 seconds, with 102 OAuth round trips. | No address based registration limit, delay, or challenge applied. |
| Ticket flood development | Tickets labelled "abuse test", "spam vector test", "ticket flood script test", and "script fix verification" were created and closed. | Per-account limits were bypassed by rotating through the account pool. Support received 176 outbound e-mail events. |
| Error-report flood | 4,919 requests hit POST /client-errors; 3,689 were accepted at about 460 per minute. | The per-user limit scaled with the account pool. Responses contained no data and accepted bodies were not retained at production log level. |
Impact assessment
| Question | Finding | Basis |
|---|---|---|
| Unauthorized customer data read? | No evidence | Every tested object owned by another user was refused. Large legitimate pages still require a code review of their page properties. |
| Admin or debug access? | No | Every attempt returned 403 or 404. |
| Payment or entitlement abuse? | No | All coupon, checkout, webhook, and referral attempts failed. |
| Code execution or malicious file? | No | Only inert images were stored; content sniffing rejected the alternate file type. |
| Service degradation? | Minor | One 503 occurred, with no recorded outage. |
| Activity outside the web application? | No evidence | No matches in SSH, firewall, mail, bot-gate, origin-pull, drop-box, or canary logs across four hosts. |
Observed activity maps to reconnaissance, access, evasion, and impact techniques
The mapping below applies MITRE ATT&CK terminology to the observed Farmoria and Rokstats behavior. A technique assignment describes the procedure that was observed or attempted; it does not imply that the technique succeeded or produced a breach.
| ATT&CK technique | Observed procedure | Assessment |
|---|---|---|
| T1595.002 Vulnerability Scanning | Ordered route enumeration, status-code comparison, developer and sensitive-path probes, object identifier walking, and billing, upload, and webhook tests against the public Farmoria application. | Confirmed Reconnaissance and vulnerability discovery. |
| T1585.001 Social Media Accounts | Discord identities were used to create and rotate OAuth-backed Farmoria accounts. Fifteen registrations occurred in a 69-second burst and were then used in the coordinated ticket workflow. | High ATT&CK analogue for account infrastructure used in the attack. |
| T1078 Valid Accounts | Authenticated OAuth sessions and multiple valid application accounts were rotated to continue testing after per-account throttling. | Confirmed Valid identities were used; ownership of every provider account is not attributed. |
| T1090 Proxy | The operator moved from residential AT&T access paths to NetProtect consumer VPN exits for the rehearsal and active testing sessions. | Confirmed Infrastructure concealment and access-path rotation. |
| T1110.001 Password Guessing | The rehearsal recorded 497 POST requests to /login and targeted guessing behavior. Request bodies were not retained, so the exact credential values cannot be reconstructed. | Moderate Attempted authentication testing; no successful credential validation was confirmed. |
| T1190 Exploit Public-Facing Application | Farmoria received structured object, billing, upload, and workflow abuse tests. In the later Rokstats incident, HollowArc was reportedly the only account to access the vulnerable public endpoint. | High Public application exploitation behavior; Rokstats impact remains limited by the missing raw request log. |
| T1499.004 Application or System Exploitation | The account pool sent 4,919 requests to POST /client-errors, generated ticket traffic, and triggered 176 outbound support e-mails. | High observed behavior Application-layer resource and workflow amplification occurred, but no sustained outage or confirmed availability loss was observed. |
Farmoria account sequence and technical joins
The supplied Farmoria data contains 18 account records in one confirmed attack cluster. Their shared access paths, near-simultaneous creation, OAuth cadence, and coordinated abuse behavior establish the relationship. Two handles were clearly selected by the actor; the legitimate ownership of the remaining Discord identities is separate and may involve compromised or borrowed accounts.
Why the records form one cluster
| Shared behavior | Observed evidence | Assessment |
|---|---|---|
| Common access path | The rotating identities authenticated and acted through 108.171.110.79. The dbquery. account bridged its residential registration address to that active VPN session. | Confirmed |
| Creation cadence | Fifteen Discord-backed Farmoria accounts were registered from 06:36:23 through 06:37:32 CEST, a 69-second burst consistent with one automation loop. | Confirmed |
| OAuth cadence | Sixteen accounts completed 102 OAuth round trips from the same VPN address during the active session. | Confirmed |
| Coordinated actions | The accounts created tickets, uploaded the same 70-byte PNG, closed tickets in account order, and contributed to the POST /client-errors flood. | High common control |
| Shared disposition | Seventeen cluster accounts were banned for multi-account abuse on 9 September; hollowarc. was banned after the cross-organization notification on 21 September. | Confirmed response |
Farmoria incident account records
| Ref. | Portal ID | Portal username | E-mail in record | Discord provider ID | Classification and disposition |
|---|---|---|---|---|---|
| R-01 | 203 | hollowarc. | [email protected] | 1070712235770527744 | Direct HollowArc actor account banned 09-21 |
| R-02 | 207 | dbquery. | [email protected] | 172818361644744705 | Direct dbquery actor account banned 09-09 |
| R-03 | 208 | luis62yeh | [email protected] | 752694018650931230 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09, working account, 8 tickets |
| R-04 | 209 | nntien1010 | [email protected] | 710733148887056467 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
| R-05 | 210 | aishaaaaaaaaaaa_ | [email protected] | 1537889410778136656 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09, 2 tickets |
| R-06 | 211 | kautiz. | [email protected] | 804707043453173771 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
| R-07 | 212 | yutaakina | [email protected] | 811091605938634773 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
| R-08 | 213 | la_jeta.de_.tu.tia3 | [email protected] | 819315758420066305 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
| R-09 | 214 | jawad.ff.official_21722 | [email protected] | 1182272947130478695 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
| R-10 | 215 | dapwn_91734 | [email protected] | 1396521643634855937 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
| R-11 | 216 | (pseudonymised) | [email protected] per the 09-05 review list | 752637340039512136 + Google 108519083684398022250 | Confirmed cluster use; subsequent owner behavior indicates probable victim; do not attribute the owner self-deleted 09-07, probable victim |
| R-12 | 217 | arman7398 | [email protected] | 1093293476390654012 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
| R-13 | 218 | sms_47 | [email protected] | 1507478735623028909 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
| R-14 | 219 | ryford185 | [email protected] | 1513887925589381154 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
| R-15 | 220 | beat85mx2421 | [email protected] | 761447327495356417 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
| R-16 | 221 | larbi6874 | [email protected] | 1125559361993965649 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
| R-17 | 222 | faycal5430 | [email protected] | 1040135619910844486 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
| R-18 | 223 | moxnster | [email protected] | 1536700818626183168 | Confirmed member of the coordinated attack cluster; provider-account ownership not established banned 09-09 |
Registration and technical correlation fields
All Farmoria registration timestamps are CEST. Short times in the source table occurred on 5 September 2026.
| Ref. | Discord account created | Farmoria registered | Recorded fingerprint | Observed access path | Status |
|---|---|---|---|---|---|
| R-01 | 2023-02-02 | 2026-09-04 18:56:27 | 630374274b | 68.90.146.47 | banned 09-21 |
| R-02 | 2016-04-21 | 2026-09-05 04:44:41 | d84b40320d | 107.206.22.143, then 108.171.110.79 | banned 09-09 |
| R-03 | 2020-09-08 | 2026-09-05 05:08:55 | 1b8f71137a | 108.171.110.79 | banned 09-09, working account, 8 tickets |
| R-04 | 2020-05-15 | 2026-09-05 06:36:23 | 416c98dd8a | 108.171.110.79 | banned 09-09 |
| R-05 | 2026-08-14 | 2026-09-05 06:36:27 | bd1d18cb9d | 108.171.110.79 | banned 09-09, 2 tickets |
| R-06 | 2021-01-29 | 2026-09-05 06:36:32 | 7dac35a293 | 108.171.110.79 | banned 09-09 |
| R-07 | 2021-02-16 | 2026-09-05 06:36:38 | Original fingerprint replaced during administrator access | 108.171.110.79 | banned 09-09 |
| R-08 | 2021-03-10 | 2026-09-05 06:36:42 | 979b564ec1 | 108.171.110.79 | banned 09-09 |
| R-09 | 2023-12-07 | 2026-09-05 06:36:46 | 98c1b8f4d0 | 108.171.110.79 | banned 09-09 |
| R-10 | 2025-07-20 | 2026-09-05 06:36:51 | b2b7cc95aa | 108.171.110.79 | banned 09-09 |
| R-11 | 2020-09-07 | 2026-09-05 06:36:57 | not retained | 108.171.110.79, then 200.63.x | self-deleted 09-07, probable victim |
| R-12 | 2023-04-05 | 2026-09-05 06:37:01 | b953bc9ae5 | 108.171.110.79 | banned 09-09 |
| R-13 | 2026-05-22 | 2026-09-05 06:37:07 | 5f4049d7e0 | 108.171.110.79 | banned 09-09 |
| R-14 | 2026-06-09 | 2026-09-05 06:37:11 | 49fd07ff13 | 108.171.110.79 | banned 09-09 |
| R-15 | 2020-10-02 | 2026-09-05 06:37:17 | 7832c4746f | 108.171.110.79 | banned 09-09 |
| R-16 | 2023-07-03 | 2026-09-05 06:37:21 | 94c68ffe8b | 108.171.110.79 | banned 09-09 |
| R-17 | 2022-11-10 | 2026-09-05 06:37:27 | 5aec11ed18 | 108.171.110.79 | banned 09-09 |
| R-18 | 2026-08-11 | 2026-09-05 06:37:32 | 87be833ab0 | 108.171.110.79 | banned 09-09 |
Personal and public-profile leads
The incident account sequence above preserves the technical joins. Public aliases, personal contact pivots and profile identifiers have been withheld from this public edition while the D***** M****** lead remains unconfirmed.
The later endpoint activity reuses the Farmoria identity cluster
The available Rokstats evidence identifies the account, the two residential access paths, and exclusive access to the vulnerable endpoint. It does not include the complete server request log, endpoint path, request body, or response data, so the report distinguishes the confirmed account linkage from the still-unresolved exploit impact.
Technical sequence supported by the supplied evidence
| Time or order | Observed event | Technical interpretation |
|---|---|---|
| 14 Jun 2026 23:00:57 UTC | The supplied application record created hollowarc. and records the first login at the same time. The OAuth profile carries Discord ID 1070712235770527744 and a provider-verified e-mail. | The account existed before either investigated attack and provides a stable identity anchor independent of display-name reuse. |
| After the 5 Sep Farmoria session | A later Rokstats log cross-check confirms hollowarc. activity from 107.206.22.143. Rokstats investigators independently reported 68.90.146.47 in the later activity. | Both addresses were already tied to account creation at Farmoria. The confirmed 107.206.22.143 match links the access path directly to the same account in the later incident. |
| Rokstats attack window | HollowArc was reportedly the only account that accessed the vulnerable endpoint. | Exclusive endpoint access makes the account action the strongest technical attribution fact in the Rokstats evidence. The missing raw log prevents independent reconstruction of method, payload, status code, and returned data. |
| After endpoint access | The persona HPCane claimed responsibility for the Rokstats attack. Arcane produced no stable identifier or infrastructure match. | The claim is consistent with the exclusive HollowArc access, supporting a moderate-confidence persona link. It remains weaker than the account and network evidence. |
| 16 Sep 2026 23:23:46 UTC | The supplied account record was updated and last seen. | The record confirms continued presence after the Farmoria incident and is consistent with the reported follow-on order. |
| Field | Observed value | Assessment |
|---|---|---|
| Account name | hollowarc. | Exact match to the Farmoria OAuth account. |
| Discord provider ID | 1070712235770527744 | Stable identifier and strongest record-level bridge. |
| Provider verified e-mail | [email protected] | Directly recorded in the OAuth profile and top-level account record. |
| Record created and first login | 14 Jun 2026 23:00:57 UTC | Predates the Farmoria activity. |
| Updated and last seen | 16 Sep 2026 23:23:46 UTC | Postdates the Farmoria session and aligns with the reported follow-on sequence. |
| MFA and locale | MFA enabled; en-US | Account settings only. They do not establish the operator's location. |
| Credential fields | OAuth access and refresh token fields present | Values deliberately omitted. Treat the source file as a secret, restrict access, and revoke or rotate credentials. |
| Application record and role | 6a2f32a9dcbe089d00311f5f 66e8ff7aa75b70702c49fe0a | Internal account and role references preserved for server-side correlation. |
| Account and authorization state | Active; not super-administrator; balance 0; tokens earned 0; tokens spent 0; no governor profiles; no kingdom access | No elevated application role or in-app asset activity appears in the supplied record. |
| Discord profile flags | Discriminator 0; public flags 256; account flags 256; premium type 0; no global name, clan, or primary guild | Provider profile metadata. These values are useful for record matching but do not identify the human operator. |
| Application preferences | Preferred language en; decimal mark .; no thousands separator; virtual-kingdom and payment-sync flags false | Stored application settings only. |
| Consent and referral state | Age confirmation false; referral credited false | No affirmative league-age confirmation or credited referral in the supplied record. |
| Avatar cache artifact | SHA-1 6727d9d3601c1f1cf256f7df082291d07b235418 discord:1070712235770527744:a_afd3887fe7192777c78b1b7a39ca0fd9 WebP, 4,782 bytes; updated 16 Sep 2026 00:51:05 UTC | Stable cached artifact for lawful cross-record comparison. Discord banner reference: a_2ec9465ff2e314c89bcf9d9dcb6104cf. |
Cross-server connection analysis
| Connection | Evidence across the servers | Assessment |
|---|---|---|
| Stable account identity | Farmoria and the Rokstats record share exact username hollowarc. and Discord ID 1070712235770527744. | Confirmed |
| Residential address reuse | 68.90.146.47 created hollowarc. at Farmoria; 107.206.22.143 created the linked dbquery. account. HollowArc use of 107.206.22.143 in the later Rokstats incident was confirmed by log cross-check; 68.90.146.47 reuse remains reported. | High |
| Sequence | Farmoria's active testing ended 5 September. The supplied Rokstats evidence places the endpoint incident afterward, and the account remained present through 16 September. | High |
| Exclusive vulnerable-endpoint access | Rokstats investigators identified HollowArc as the only account to access the endpoint associated with their incident. | High, pending raw-log preservation |
| Claimed persona | HPCane claimed the Rokstats attack; the endpoint account was HollowArc. No provider ID, e-mail, or network record directly joins the two names. | Moderate |
| Arcane | No unique account identifier, address, domain, or server action connects Arcane to either technical record. We do not currently suspect involvement. | Inconclusive |
Account attribution is stronger than person attribution
The evidence reliably identifies accounts, addresses, and an online persona cluster. It does not establish a verified legal identity or exact residence. The table keeps those questions separate.
| Analytic question | Judgment | Confidence | Alternative explanation |
|---|---|---|---|
| Did the same online identity appear in both incidents? | Yes. The exact hollowarc. account and Discord ID link the records. | Confirmed | None that fits the stable provider ID. |
| Did the same operator likely control the activity? | Yes, or a very closely coordinated operator shared the account and residential connections. | High | Credential sharing or account compromise could let another person operate the identity. |
| Is HPCane the HollowArc operator? | Likely, based on the claim and HollowArc exclusive endpoint access. | Moderate | The claim may be false, exaggerated, or made by a collaborator. |
| Is Arcane linked? | No observed link; Arcane is not currently suspected. | Inconclusive | New evidence could change this assessment. |
| Does the D***** M****** lead identify the operator? | There is an investigative lead, but no stable technical identifier joins this person to the attack activity. | Moderate lead | Account sharing, misleading public profiles, and unrelated name matches remain possible. |
| Does HollowArc control meshvision.xyz? | Ownership is unverified. The dbquery. e-mail and a reported BreachForums appearance provide an indirect association. | Inconclusive | The domain address could be shared, borrowed, or unrelated to the forum appearance. |
Analytic confidence
| Level | Meaning in this report |
|---|---|
| Confirmed | Direct record, exact stable identifier, or verified forensic observation. |
| High | Multiple independent indicators with no persuasive benign explanation. |
| Moderate | Evidence supports the judgment, but one or more plausible alternatives remain. |
| Low | Lead or partial corroboration that should not drive enforcement alone. |
| Inconclusive | The supplied evidence cannot distinguish between material alternatives. |
Person-of-interest lead
D***** M****** is a moderate-confidence person-of-interest lead, not a confirmed operator. Our technical records link online accounts across the two incidents; they do not establish who controlled them.
The available location clues point to Louisiana. Based on a candidate public profile, D***** M****** most likely works in a network operations center there. We have not verified that the profile belongs to the operator or that this person was in Louisiana during either incident.
Public aliases, posts and interests can belong to unrelated people. The shared Discord identity carries more weight than a profile or location clue. Two residential connections support the cross-incident link; VPN exits and browser fingerprints are weaker. The rapid account pool may include compromised identities.
We are withholding the candidate profile, portrait, personal contact details and employment specifics. Detailed indicators are reserved for direct sharing with affected services and incident responders.
HollowArc is the technical identity; HPCane is assessed as a closely coordinated collaborator
The technical evidence establishes HollowArc as the account identity used across both incidents. The exact HollowArc Discord identity appears at Farmoria and Rokstats, the two Farmoria-linked residential addresses reappear in the Rokstats investigation, and HollowArc was reportedly the only account to access the vulnerable Rokstats endpoint. HPCane then claimed the Rokstats attack.
| Hypothesis | Assessment | Reasoning |
|---|---|---|
| HPCane is a closely coordinated collaborator | High - favored | The claim aligns with exclusive HollowArc endpoint access, reused Farmoria infrastructure, and the incident timing. A collaborator could know the exploit details or share account access, infrastructure, and operational information with HollowArc. |
| HollowArc and HPCane are the same operator | Moderate - plausible | The same operator may use both personas, but no stable HPCane account identifier currently joins the names directly. This remains a credible alternative to close collaboration. |
| HPCane is an unrelated false claimant | Low | The claim is supported by the exclusive HollowArc access and cross-incident network linkage. Coincidence or an uninformed false claim explains the evidence less well. |
| Arcane participated in either incident | Inconclusive | No stable account identifier, address, domain, or observed server action connects Arcane to the technical record. We do not currently suspect involvement, though it cannot be ruled out. |
Contain identity reuse and close the scaling path
| Priority | Action | Owner and outcome |
|---|---|---|
| Immediate | Maintain the completed hashed Farmoria evidence set in restricted storage and obtain the exact Rokstats endpoint logs and timestamps for the two residential addresses if they are not already preserved. | Incident response and platform teams. Maintains evidential continuity. |
| Immediate | Revoke every OAuth token contained in the Rokstats-shared export, rotate related application secrets where necessary, and store the raw export in restricted evidence storage. | Rokstats identity and security teams. Removes credential exposure created by the export. |
| Immediate | Report Discord ID 1070712235770527744 and the compromised identity pool to Discord Trust and Safety with the two incident timelines. | Joint incident team. Disrupts the reusable identity pool and supports victims. |
| Immediate | Block or challenge 68.90.146.47 and 107.206.22.143, and apply managed challenges to the Netprotect ranges on login, registration, OAuth callback, ticket, and sensitive API paths. | Edge security. Slows known infrastructure while accounting for VPN rotation. |
| Short term | Rate limit OAuth registration by address and subnet, add a first-time signup challenge, and alert on rapid provider identity rotation. | Application engineering. Closes the account creation scaling path. |
| Short term | Apply ticket and POST /client-errors limits by both account and address. Suppress staff e-mail for very new accounts with no linked game identity. | Application engineering. Prevents account pool amplification. |
| Short term | Review large authenticated page properties, especially command and configuration template pages, for accidental cross-tenant data. | Application security. Resolves the remaining visibility gap that access logs cannot answer. |
| Short term | Stop deriving public display names from e-mail local parts and contact the customer whose exact address was guessed to reset credentials and enable two-factor authentication. | Product and customer support. Reduces targeted guessing exposure. |
| Short term | Fix the attachment processor error that rejects legitimate uploads, while keeping content sniffing, private storage, random names, ownership checks, and sandboxed delivery. | Application engineering. Restores customer functionality without weakening controls. |
| Structural | Adopt a shared cross-incident indicator register that records stable account IDs, domains, evidence source, confidence, first and last seen times, and disposition. | Security operations. Enables defensible partner correlation. |
| Structural | Define an attribution review gate before naming a civil person or exact location in customer, provider, or law-enforcement reporting. | Incident leadership and legal counsel. Keeps account evidence separate from identity claims. |
Evidence supports account linkage, with stated limits
- S1 Farmoria forensic reconstruction dated 21 September 2026.Nginx access logs, selected database tables, audit data, identity records, tickets, attachments, abuse and throttle records, and negative searches across host logs.
- S2 HollowArc public exposure ledger dated 21 September 2026.Public GitHub, Steam, Tumblr, Space Station 14, Bluesky, Docker Hub, DNS, RDAP, and certificate transparency observations.
- S3 Rokstats-shared account export for hollowarc..Discord provider ID, verified e-mail, account timestamps, profile flags, and credential field presence. Token values and unrelated community memberships were excluded.
- S4 Rokstats investigation findings shared during collaboration.Vulnerable endpoint exclusivity, address reuse, the HPCane claim, Arcane lead status, and threat-intelligence e-mail correlation.
- S5 Archived public weather record used for a bounded regional cross-check.Exact location details are withheld from this public version.
- S6 Restricted public-profile review for the D***** M****** lead.Identifying profile details and visual exhibits are withheld from this public version.
- S7 Validated threat-intelligence resource capture.The resource was validated and summarized in sanitized form. Credential hash material and adjacent third-party records were excluded.
- S8 Public Hack The Box profile for user 411676, reviewed 21 September 2026.Exact handle HollowArc; joined September 2020; first visible activity records a Lame machine system flag on 2 October 2022.
- S9 CyberInt threat-intelligence alias finding for chacon111 and public exact-handle enrichment, reviewed 21 September 2026.CyberInt is the trusted threat-intelligence platform used for this investigation. Public enrichment found one eBay review dated 29 May 2024 and one QuickBooks Community question dated 29 October 2022; ownership of those public accounts was not established.
- S10 MITRE ATT&CK Enterprise technique definitions, reviewed 21 September 2026.T1595.002 Vulnerability Scanning; T1585.001 Social Media Accounts; T1078 Valid Accounts; T1090 Proxy; T1110.001 Password Guessing; T1190 Exploit Public-Facing Application; and T1499.004 Application or System Exploitation.
- S11 Completed VDS forensic collection, closed 23 September 2026.Verified MySQL, nginx, journal, audit, system, application and historical-log artifacts; final MySQL delta and live prefix; 80-entry SHA-256 manifest with zero verification mismatches. Active-file and acquisition-boundary qualifications are retained.
- S12 Subsequent Rokstats log cross-check shared during collaboration.Confirmed hollowarc. activity from 107.206.22.143 in the later incident. The underlying endpoint requests and responses are not included in this public report.
- S13 BreachForums observation reported during incident review.Supports only an indirect HollowArc association with meshvision.xyz. The public report does not establish domain ownership or account control.
- S14 ARIN registrations for 107.206.22.143 and 68.90.146.47, plus a reverse-DNS lookup for 107.206.22.143, checked 26 September 2026.AT&T is the registered holder of both ranges. Shared ISP ownership does not identify a subscriber or location; the reverse-DNS naming supports likely consumer broadband for 107.206.22.143 only.
Material limits
- The interactive workbench adds archive-wide traffic context and evidence-linked findings, but it remains an analytical view rather than a substitute for the preserved source artifacts. Reproduce material conclusions against the hashed evidence before legal or enforcement use.
- The MITRE ATT&CK mapping describes observed or attempted procedures. It does not assert technique success or impact beyond the supporting evidence.
- Farmoria access logs record request path, status, size, address, and client metadata, but not POST bodies or response content.
- Traffic blocked at the Cloudflare edge may not appear in origin logs.
- The completed Farmoria web-log archive begins on 26 August 2026, extending the previously summarized boundary by one day. Earlier behavior is not visible in that dataset.
- The Rokstats-shared account export is treated as evidence from Rokstats' separate investigation. Its acquisition method and full chain of custody were not independently validated by Farmoria.
- An account, e-mail address, or IP address identifies an online access path. It does not by itself identify the human at the keyboard.
- Provider identities in the rapid Farmoria account pool may belong to victims. They should not be publicly named as attackers.
- Public profile data can be false, stale, borrowed, or intentionally misleading. Negative search results mean only that no defensible result was observed.
- D***** M****** remains a moderate-confidence person-of-interest lead. No stable technical identifier links the person or a specific public profile to the operator.
- Person-specific images and profile links are withheld from this public version.
- The breach-data capture comes from a validated threat-intelligence resource. The HollowArc record was retained as evidence; the credential hash and unrelated records were excluded.
- Language overlap and public web-security activity are broad behavioral signals. Neither identifies a person as the operator.
- The Hack The Box exact-handle and timing match is a low-confidence lead. No verified e-mail, account ID, or other stable identifier joins user 411676 to the confirmed HollowArc cluster.
- CyberInt confirms chacon111 as a HollowArc alias. The separate eBay and QuickBooks exact-handle accounts are not attributed to HollowArc without a second stable identifier.
- The location assessment is regional and probabilistic. It should not be used to identify a home address or individual without independent lawful corroboration.