Compare commits

...

5 Commits

Author SHA1 Message Date
95b89c56a8 sync: auto-sync from GURU-5070 at 2026-06-09 10:13:37
Author: Mike Swanson
Machine: GURU-5070
Timestamp: 2026-06-09 10:13:37
2026-06-09 10:14:16 -07:00
53584e1497 report(kittle): IC3 complaint filed - submission ID aa2ef504... (2026-06-09)
IC3 filed 2026-06-09 12:46 EST. Stamped the submission ID on the report; bank freeze letters
(Truist/First State/Chase) updated with the IC3 # and real Kittle/ACG contacts - now turnkey to send.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-09 09:49:35 -07:00
4c580fe485 report(kittle): fraud PREVENTED - City stopped payment, Foam Factory confirmed mule
Per Kittle bookkeeper (2026-06-09): City of Tucson stopped the payment before any funds reached
the attacker (no completed loss; attempted $130k+). Kittle confirms no Foam Factory relationship,
confirming both receiving accounts are mules. Also: Ken un-restricted from sending (Outbox/Drafts
verified empty first); Lori was never restricted.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-09 09:15:07 -07:00
42135ed557 report(kittle): fold confirmed invoice amounts into IC3 report
Inv #31468 $123,776.75 (confirmed), Inv #31400 ~$8,818, Inv #31453 $41,231 (open);
total identified exposure $130,000+ since the ACH change redirects all City->Kittle payments.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-09 08:04:36 -07:00
c5a7c15cff report(kittle): IC3 BEC/ACH-fraud complaint package
Consolidated FBI IC3 report for the Kittle payment-redirection fraud: victim/payer info,
fraudulent mule accounts (Truist 053201607/1410020505238; Foam Factory First State + Chase),
targeted City of Tucson payments (Inv #31400 ~$8,818 6/9 EFT; Inv #31468 $123,776.75),
attacker IPs/domains/phone, full timeline, and evidence inventory. Evidence package assembled
to Downloads/Kittle-IC3-Package (report + 2 ACH form PDFs + recovered emails + 171-event audit CSV).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-09 07:52:24 -07:00
3 changed files with 241 additions and 0 deletions

View File

@@ -0,0 +1,95 @@
# FBI IC3 Complaint Package — BEC / ACH Payment-Redirection Fraud
> Prepared by Arizona Computer Guru (ACG) for Kittle Design & Construction LLC
> Incident date: 2026-06-08 to 2026-06-09 (UTC) · Package date: 2026-06-09
> Complaint type: Business Email Compromise (BEC) / EAC — Wire/ACH fraud
> **FILED: FBI IC3 complaint `aa2ef50482ca4c05a54ae0f6cb56ffa0` — 2026-06-09 12:46 PM EST**
---
## 1. VICTIM INFORMATION
**Primary victim (compromised business):**
- Kittle Design & Construction LLC — Tucson, Arizona
- Domain / M365 tenant: kittlearizona.com (tenant ID 3d073ebe-806a-4a5e-9035-3c7c4a264fc0)
- EIN on the fraudulent form: 86-0942406 (purported Kittle EIN — verify; attacker likely copied the real EIN)
- Point of contact: Ken Schagel (owner), ken@kittlearizona.com, cell 520-310-1525
- Compromised mailboxes: Ken@kittlearizona.com (entry point, Global Admin), Accounting@kittlearizona.com (finance — accessed via Ken's delegate rights)
**Intended payer targeted by the fraud:**
- City of Tucson, Business Services Department (BSD) — Accounts Payable
- Finance contact in the fraud thread: Randi Arnett, Finance Manager (Randi.Arnett@tucsonaz.gov); AP: HCDAccountsPayable-Finance@tucsonaz.gov
- Other City staff CC'd by the attacker: Monica Barcenas, Angelica Favela, Alexa Johnson, Katharine Mitchell; Buyer: Casey Adams (Casey.Adams@tucsonaz.gov)
**Reporting party / IT provider:** Arizona Computer Guru (Managed Service Provider). Contact: Mike Swanson.
## 2. FINANCIAL TRANSACTION INFORMATION
**Nature:** Attacker submitted a fraudulent ACH/EFT banking-change ("BSD ACH Application", "Change" box) to the City of Tucson, impersonating Kittle's bookkeeper, to redirect Kittle's incoming City payments to attacker-controlled accounts.
**Targeted / exposed payments (City of Tucson → Kittle, EFT):**
- Invoice #31468 — Job #5654.25, "MMC Generator Upgrade" — **$123,776.75** (confirmed from the City payment thread).
- Invoice #31400 — KDC Job #5700.25B, "COT Knights Inn — Fire Suppression" (PO-007291); City indicated EFT processing **2026-06-09**. Amount ~**$8,818.00** (approximate per thread; confirm exact with City).
- Additional open Kittle invoices were identified in the mailbox (e.g. Invoice #31453, **$41,231.00**, due 2026-06-28); any billed to the City would also have been exposed.
- **Total identified exposure: $130,000+** (≥ $123,776.75 + ~$8,818). Because an approved ACH banking change redirects ALL future City-of-Tucson payments to Kittle, exposure is NOT limited to a single invoice and the true figure may be higher.
**Fraudulent receiving (mule) accounts:**
| # | Bank | Routing/ABA | Account # | Name on account | Source |
|---|---|---|---|---|---|
| 1 (submitted to City) | **Truist Bank** | **053201607** | **1410020505238** | "Kittle Design & Construction" | BSD ACH Application form attached to the attacker's 2026-06-08 email |
| 2 (second form in mailbox) | First State Bank (Eastpoint, MI) | 072410165 | 62100616 | FOAM FACTORY INCORPORATED | ACH-FoamFactory.pdf found in Ken's mailbox |
| 2b | JPMorgan Chase Bank, N.A. (New York, NY) | 021000021 (wire) / 072000326 (ACH); SWIFT CHASUS33 | 2906183268 | FOAM FACTORY INCORPORATED | same form |
**Attacker contact phone on the fraudulent form:** (659) 221-9243
**Loss status — PREVENTED (no completed loss).** Confirmed 2026-06-09 by Kittle's bookkeeper (Darline Cabrera), after speaking with the City of Tucson: **the City stopped the payment before any funds were transferred to the attacker.** No completed financial loss occurred. Attempted / exposed amount: **$130,000+** (as above). Kittle also confirmed it has **no business relationship with Foam Factory Incorporated**, confirming both receiving accounts are attacker-controlled mule accounts. The fraudulent accounts should still be reported and frozen, and the perpetrator pursued (this complaint documents an attempted wire/ACH fraud).
## 3. SUBJECT (PERPETRATOR) INFORMATION
**IP addresses used:**
| IP | Use | Geolocation | ASN |
|---|---|---|---|
| 64.44.131.168 | OWA access to Ken + Accounting mailboxes; sent the fraudulent ACH emails; deleted evidence | Chicago, IL | AS20278 Nexeon Technologies (VPN/hosting) |
| 40.126.41.96 | Contact harvesting via python-httpx | Microsoft Azure | Microsoft Corp |
| 45.134.224.220 | Bulk phishing send (1,000 emails) | Kansas City, MO | AS147049 PacketHub S.A. (hosting) |
**Impersonation infrastructure:**
- `Accounting.kittlearizona@gmx.com` — GMX free account impersonating Kittle's Accounting dept (inserted into the City invoice thread starting 2026-06-05)
- `tucsonoz.com` — lookalike domain of the City's `tucsonaz.gov` (e.g. randi.arnett@tucsonoz.com)
- Attacker tooling: python-httpx/0.28.1 using an OAuth token for the Microsoft Desktop app (`d3590ed6-52b3-4102-aeff-aad2292ab01c`)
## 4. INCIDENT NARRATIVE
On 2026-06-08, an external attacker compromised the Microsoft 365 account of Ken Schagel (owner / Global Administrator) of Kittle Design & Construction LLC, accessing it via Outlook on the Web from IP 64.44.131.168 beginning 13:24 UTC. Ken's account held standing FullAccess (delegate) permission to the company's Accounting (finance) mailbox (a legitimate permission Ken granted himself on 2026-05-15, ~3 weeks before the incident). The attacker used that delegate access to enter the Accounting mailbox.
From the Accounting mailbox, the attacker — impersonating Kittle's bookkeeper ("Darline Cabrera") — submitted a fraudulent ACH/EFT banking-change form to the City of Tucson's Accounts Payable, attempting to redirect Kittle's incoming City payments (including Invoice #31400, EFT scheduled 2026-06-09) to a Truist Bank account they controlled. The attacker had pre-positioned by inserting a GMX lookalike address (Accounting.kittlearizona@gmx.com) into the legitimate Kittle↔City invoice thread as early as 2026-06-05. The attacker hard-deleted the EFT and invoice emails from both Ken's and Accounting's mailboxes to conceal the activity (recovered by ACG from the audit-log dumpster).
Separately/concurrently, the attacker harvested contacts (18:3618:53 UTC) and sent ~1,000 phishing emails ("Ken Schagel shared a file with you") from 45.134.224.220 between 21:1421:26 UTC (747 delivered). ACG detected the incident ~21:30 UTC and performed containment/remediation. The payment-redirection fraud was identified by ACG on 2026-06-09 via mailbox-audit and message-trace analysis.
## 5. TIMELINE (UTC)
- 2026-06-05 ~11:52 — Attacker (via Accounting.kittlearizona@gmx.com) inserts into the Kittle↔City invoice thread.
- 2026-06-08 13:24 — First attacker OWA login to Ken's account (64.44.131.168).
- 2026-06-08 14:5121:09 — Attacker accesses Accounting mailbox as delegate (21 access events); reads Inbox\Customers, Assured Partners, Employees, Sent, Deleted.
- 2026-06-08 15:52 / 16:45 / 18:52 / 20:29 — Attacker sends "EFT UPDATE" / ACH-change emails on behalf of Accounting@ to Randi Arnett (City of Tucson); hard-deletes the thread after each.
- 2026-06-08 18:3618:53 — Contact harvest (python-httpx, 40.126.41.96).
- 2026-06-08 21:1421:26 — 1,000-recipient phishing blast (45.134.224.220).
- 2026-06-08 ~21:30 — ACG detects, begins containment.
- 2026-06-09 — ACG identifies the ACH payment-redirection fraud; password resets; client notified; this package prepared.
## 6. EVIDENCE INVENTORY (preserved by ACG)
- `Downloads/kittle-bec-attachments/FRAUD_BSD_ACH_APPLICATION.pdf` — the fraudulent ACH change form submitted to the City (shows Truist 053201607 / 1410020505238).
- `Downloads/kittle-bec-attachments/Ken_ACH-FoamFactory.pdf` — second ACH form (Foam Factory Inc accounts).
- Recovered email thread (EFT UPDATE / ACH, Accounting@ ↔ Randi Arnett) — recovered from the M365 Recoverable Items dumpster via Graph (the attacker hard-deleted the originals).
- Microsoft 365 Unified Audit Log: MailItemsAccessed (delegate, IP 64.44.131.168), SendOnBehalf, SoftDelete/HardDelete events for Accounting@ and Ken@ — exportable on request.
- Message trace confirming delivery of the fraud emails and the original recalled message.
- Prior incident report: `clients/kittle/reports/2026-06-08-breach-check.md` (full BEC remediation, phishing campaign, inbox rules).
## 7. ACTIONS TAKEN BY ACG / VICTIM
- Compromised accounts' sessions revoked; passwords reset (Ken's password changed in person 2026-06-09).
- Malicious inbox rules removed; mailbox forwarding, transport rules, and delegate access re-verified clean (2026-06-09).
- Kittle contacted the City of Tucson; **the City stopped the fraudulent payment** before any funds were transferred (confirmed 2026-06-09). Kittle confirmed no relationship with Foam Factory Incorporated.
- Ken's account was auto-restricted from sending by outbound-spam protection during the phishing blast; ACG verified nothing malicious was queued (Outbox/Drafts empty) and **removed the restriction (sending restored 2026-06-09).**
- Client advised to file this IC3 complaint and notify Truist / First State Bank / JPMorgan Chase fraud departments to freeze the receiving accounts.
---
*Package compiled from M365 unified audit log, message trace, and recovered mailbox evidence. Dollar amounts to be confirmed with the City of Tucson. ACG can provide raw audit-log exports and the recovered emails/attachments on request.*

View File

@@ -0,0 +1,73 @@
# Safe Site — NexSite recalled-PDF forensic investigation
## User
- **User:** Mike Swanson (mike)
- **Machine:** GURU-5070
- **Role:** admin
## Date
- Investigation opened 2026-06-08; forensic sweep + reconstruction 2026-06-09.
- Reconstructed 2026-06-09 from work done on GURU-5070 (live session `eebb22f9-…`, which was never `/save`d — hence this log).
## Client
- **Safe Site Utility Services LLC** — M365 tenant `safesitellc.com`, tenant ID `71b4e637-c802-4137-a812-ae50dbc839e3`.
- GuruRMM client **Safesite** `fe17552f-736b-42ec-86a2-0e6f107f2397` (sites Bell / Glendale / Unknown).
## The request (from Jonathan Byrd, j.byrd@nexsitepartners.com)
External sender `m.paris@nexsitepartners.com` sent **"Re: NWWells - SafeSite - Vendor Forms"** with attachment **`SSUS 06122026.PDF`** to 9 Safe Site recipients on 2026-06-08 ~18:54 UTC. The email was recalled. Question: **was the PDF accessed/downloaded on any managed machine?**
Recipient → machine (via Datto "Last User"):
| Recipient | Machine | GuruRMM enrolled? |
|---|---|---|
| beeanna | 0225-DELL3550 | yes |
| david | 0622-DAVID-HP | yes |
| jon | 0525-ASUSFX707Z | yes |
| justinb | 0525-DELL3550-1 | yes |
| lennyg | DESKTOP-3USU20B | yes |
| suzannep | 1122-SUZANNE-DELL | yes |
| travisf | MSI | yes |
| thomasc | 0724-DELL3550 | yes |
| jeremiahw | **DESKTOP-LOPKB4G** | **NOT enrolled** |
## Mail-side findings (COMPLETE)
1. **Mailbox content search** (Graph `$search` for "SSUS 06122026" across all 9 mailboxes) → **all `[CLEAN]`**. The recall succeeded — no message carrying the PDF remains in any of the 9 mailboxes.
2. **EXO recall-proof** (`_recall_proof_poller.sh``~/Downloads/safesite-recall-proof.json`, pulled 2026-06-09 03:39 UTC, after the Exchange Operator SP's Exchange-Admin role finally propagated):
- `Search-UnifiedAuditLog` FreeText "SSUS 06122026" → **0 rows**.
- Delete/purge ops (HardDelete/SoftDelete/MoveToDeletedItems) by the 9 recipients → **0 rows**.
- `Get-MessageTraceV2` (sender m.paris@nexsitepartners.com) → 74 rows; the message shows **Delivered** to all 9 recipients before recall (distribution list `potholing@` = Expanded).
- **Caveat:** the UAL does not log a PDF opened directly from an Outlook attachment, so "0 audit hits" is **not** proof it was never opened — only that there's no mail/SharePoint audit trace.
## Endpoint forensic sweep (GuruRMM) — the definitive "on disk / downloaded?" check
Forensic PowerShell (runs as SYSTEM) searches each user profile's Downloads / Desktop / Documents / Outlook `Content.Outlook` cache / Temp / Recent / OneDrive for `*06122026*`, reads the **Zone.Identifier (Mark-of-the-Web)** on any hit, and scans Chrome/Edge **download-history** DBs for the pattern. Emits JSON `{host, hitCount, hits[]}`.
**First dispatch (2026-06-09 03:4415:05 UTC):** 7 commands; only **2 completed**, both **CLEAN (hitCount 0)****MSI** (travisf) and **0525-DELL3550-1** (justinb). The other 5 **failed: "Command timeout"** — the Safesite agents are WS-disconnected (alive, `last_seen` updates ~every minute, but no persistent socket), so short-timeout commands expire before pickup.
**Re-dispatch (2026-06-09 ~15:4x UTC, this session):** same script, `timeout_seconds=1800` so it survives the agents' frequent reconnects. Sent to the 6 remaining enrolled targets:
| Machine (recipient) | command_id |
|---|---|
| 0225-Dell3550 (beeanna) | 86340d9b |
| 0622-David-HP (david) | 8d3e6530 |
| 0525-ASUSFX707Z (jon) | 9aa25e67 |
| DESKTOP-3USU20B (lennyg) | 1cf8dfea |
| 1122-Suzanne-Dell (suzannep) | 3322e787 |
| 0724-Dell3550 (thomasc) | 16b2a2b1 |
Results → `~/Downloads/safesite-forensic-results.txt`. **[STATUS: in progress at time of writing — poller collecting.]**
## Current status / open items (as of 2026-06-09 ~16:10 UTC)
- **CLEAN — 7 of 9 machines** (hitCount 0; no `06122026` file, no Mark-of-the-Web, no browser-DL trace):
MSI (travisf), 0525-DELL3550-1 (justinb), 0225-DELL3550 (beeanna), 0622-DAVID-HP (david),
0525-ASUSFX707Z (jon), 1122-SUZANNE-DELL (suzannep), 0724-DELL3550 (thomasc).
- **2 machines deferred — both effectively offline:**
- **DESKTOP-3USU20B (lennyg)** — enrolled but agent last checked in 13:43 UTC; forensic command queued (will run on reconnect, else re-dispatch).
- **DESKTOP-LOPKB4G (jeremiahw)** — NOT enrolled in GuruRMM and offline; sweep via Datto/Intune or after agent install once back online.
- **So far: no evidence the PDF was downloaded or opened on any swept machine.**
- Underlying issue: Safesite GuruRMM agents are WS-disconnected (known fleet issue) — they execute on reconnect but short timeouts fail. Use `timeout_seconds=1800` for this fleet until the WS issue is resolved.
## Syncro
- Ticket **#32395** (Safesite LLC, contact Jonathan Byrd) — created 2026-06-09; initial customer-facing update emailed (recall verified + 6/9-then-7/9 clean); internal progress note added.
## Artifacts on GURU-5070
- `~/Downloads/safesite-recall-proof.json` — EXO recall proof.
- `~/Downloads/safesite-forensic-results.txt` — endpoint sweep results.
- `.claude/scripts/_recall_proof_poller.sh` — the EXO poller (one-shot, completed).

View File

@@ -0,0 +1,73 @@
# Dataforth FreePBX restore · Birth Biologic admin reset tooling · Safesite PDF forensics
## User
- **User:** Mike Swanson (mike)
- **Machine:** GURU-5070
- **Role:** admin
## Session Summary
Three threads across two days (2026-06-08 → 06-09). The largest was a **total phone outage at Dataforth** (Sangoma FreePBX 17 / Asterisk 22.5.2 at 192.168.100.2, FirstDigital PJSIP trunk). Outbound was failing with `Could not create dialog to invalid URI 'FirstDigital'` — the trunk contact had gone *Unavailable* because FirstDigital's Sonus SBC stopped answering SIP `OPTIONS` (measured 0/5), and Asterisk 22 refuses to build a call to an Unavailable contact, so no INVITE ever left the box. Fix: set the trunk `qualify_frequency=0` (DB `pjsip` id=1) and re-applied the recurring `PJSip.class.php` line-504 patch (wiped again by the Oct FreePBX update, which had broken `fwconsole reload`). After reload, a test INVITE got `100/183/200` from FirstDigital — outbound restored. Then **inbound** was reported dead too; packet captures proved FD's INVITEs weren't reaching the PBX at all. SSH'd into the Dataforth UDM-Pro (via the D2TESTNAS jump + a root key Mike authorized) and found the root cause: **there was never an inbound SIP port-forward** — inbound had only ever survived on NAT pinholes punched by the qualify-OPTIONS keepalive, which the `qualify=0` fix removed. Added a source-locked (66.7.123.0/24) WAN UDP 5060 + RTP 10000-20000 → 192.168.100.2 DNAT + forward-accept, persisted in `/data/on_boot.d/30-freepbx-sip-forward.sh`. Inbound test calls answered. Ticket #32392 resolved, 1.0 hr emergency remote billed (prepaid ×1.5).
Second thread: **Birth Biologic** `operations@` M365 password reset. The plain Graph `passwordProfile` PATCH 403'd because operations@ holds SharePoint+Teams Admin roles (Microsoft protects admin accounts — needs Global/Privileged Authentication Administrator). Mike reset it via the portal. To make admin-account resets programmatic going forward, built `scripts/reset-password.sh` in the remediation-tool skill: JIT-assigns the Tenant Admin SP the Privileged Authentication Administrator role (the app holds `RoleManagement.ReadWrite.Directory`), resets, then de-elevates. Committed + the vaulted UDM creds correction synced to the fleet. Also confirmed operations@ already has all-SharePoint access via its SharePoint Admin role.
Third thread: **Safesite (Safe Site Utility Services)** forensic review of a recalled phishing email (`SSUS 06122026.PDF` from m.paris@nexsitepartners.com to 9 recipients). Mail side: all 9 mailboxes clean (recall succeeded), UAL 0 hits, message-trace confirmed delivery-then-recall. Endpoint side: a GuruRMM forensic sweep (per-user Downloads/Outlook-cache/Recent/OneDrive search for the file + Zone.Identifier MotW + browser DL history). First dispatch mostly timed out (Safesite agents are WS-disconnected); re-dispatched with `timeout_seconds=1800`. **7 of 9 machines swept CLEAN; no evidence the PDF was downloaded/opened anywhere.** 2 machines (lennyg DESKTOP-3USU20B, jeremiahw DESKTOP-LOPKB4G) stayed offline → deferred. Opened Syncro #32395 (contact Jonathan Byrd), emailed an initial update, billed 1.5 hr remote (prepaid → 0), and set up a coord auto-followup (todo + fleet broadcast) so any free session completes the last 2 machines and closes out with Jonathan.
## Key Decisions
- **Dataforth: do NOT revert `qualify=0`.** Reverting would re-break outbound (FD ignores OPTIONS). The inbound problem was the missing UDM port-forward, not our change — proven by timeline (inbound worked 2.5 h after the AM change, then died with the pinhole).
- **Source-locked the UDM SIP forward to 66.7.123.0/24** (FD's subnet) to keep internet SIP scanners off the PBX.
- **Persisted UDM rules via `/data/on_boot.d/`** (matching the existing Neptune SNAT pattern) rather than the UI, for reboot survival; recommended Mike add a UI rule afterhours for provision-safe persistence.
- **Built JIT-elevation password reset** rather than granting the Tenant Admin app a standing Privileged Auth Admin role — minimizes blast radius; the app could already self-elevate via RoleManagement.ReadWrite.Directory, so no new exposure.
- **Safesite: long timeouts (1800s) for this fleet** — the agents are alive but WS-disconnected (recent last_seen, is_connected=false), so commands must survive until the next reconnect.
- **Safesite followup via coord todo + fleet broadcast, not a cloud routine** — the work needs internal-network access (GuruRMM 172.16.3.30, vault) that a cloud-scheduled agent can't reach, so a fleet workstation session must run it.
## Problems Encountered
- **paramiko quoting through nested `sudo bash -c "..."`** truncated Asterisk CLI commands (`asterisk -rx core` → "No such command"). Fixed by uploading scripts via SFTP and running `sudo bash <file>`, or single-quoting inner commands.
- **UDM SSH auth failures** — vaulted password `Paper123!@#-unifi` was stale; the device SSH wanted `azcomputerguru`/`r3tr0gradE99#` and 2FA. Resolved by tunneling through D2TESTNAS and having Mike add a root SSH key. His first add-key command lost the `>>` redirect (echoed the key instead of writing it); re-issued with `tee -a`.
- **GuruRMM forensic timeouts** — first sweep failed with "Command timeout" on WS-disconnected agents; fixed with `timeout_seconds=1800` + re-dispatch.
- **Syncro ticket POST returned empty once** (both #32392 and the recall work) — per skill rule, GET-verified no duplicate before retrying.
- **Coord todo via raw API returned null** — switched to the `coord` skill's `coord.py` which created it cleanly.
## Configuration Changes
- `.claude/skills/remediation-tool/scripts/reset-password.sh` — NEW (JIT admin password reset). Mirrored to repo `.claude/skills/...`.
- `.claude/commands/remediation-tool.md` — documented the JIT password-reset pattern + admin-target caveat.
- Dataforth PBX `192.168.100.2`: `pjsip` DB id=1 `qualify_frequency` 60→0; `PJSip.class.php` line 504 re-patched (backup `.bak.20260608083954`).
- Dataforth UDM `192.168.0.254`: `/data/on_boot.d/30-freepbx-sip-forward.sh` — NEW (SIP/RTP DNAT + forward-accept); root key added to `/root/.ssh/authorized_keys`.
- Vault `clients/dataforth/udm.sops.yaml` — corrected creds (azcomputerguru/r3tr0gradE99#), added console_ssh_user + notes (committed 880761d).
- `clients/safesite/session-logs/2026-06-08-safesite-nexsite-pdf-forensics.md` — NEW (Safesite forensic log).
## Credentials & Secrets
- **Dataforth UDM** `192.168.0.254`: SSH `azcomputerguru` / `r3tr0gradE99#`; console user `root` (ACG via root SSH key over D2TESTNAS jump); web `azcomputerguru` / `r3tr0gradE99#`. 2FA push. Vault: `clients/dataforth/udm.sops.yaml`.
- **Dataforth PBX** `192.168.100.2`: `sangoma` / `Gptf*77ttb!@#!@#`. Vault: `clients/dataforth/pbx.sops.yaml`.
- **D2TESTNAS** `192.168.0.9`: `root` / `Paper123!@#` (jump host). Vault: `clients/dataforth/d2testnas.sops.yaml`.
- **Birth Biologic** tenant `birthbiologic.com` (19a568e8-9e88-413b-9341-cbc224b39145 via openid; tenant-admin app 709e6eed). operations@ id `d9a0a1af-d216-4cc0-929a-3170573f7dd5`, new password set by Mike in portal (C@lmOp$26).
## Infrastructure & Servers
- **Dataforth FreePBX:** 192.168.100.2 (Sangoma FreePBX 17 / Asterisk 22.5.2). Trunk FirstDigital, SBC 66.7.123.215:5060 (Sonus), match 66.7.123.0/24, IP-auth (no registration). Public IP 67.206.163.122 (eth8 on UDM). FD ignores OPTIONS but answers INVITEs.
- **Dataforth UDM-Pro:** 192.168.0.254 / 192.168.0.1, UniFi OS 5.1.15. WAN eth8 67.206.163.122/29 + 67.206.163.124/32 (Neptune). Port-forwards in mongo `ace.portforward` (Exchange→172.16.3.11; new SIP via on_boot.d).
- **Safesite:** M365 `safesitellc.com` (71b4e637-c802-4137-a812-ae50dbc839e3). GuruRMM client `fe17552f-736b-42ec-86a2-0e6f107f2397` (sites Bell/Glendale/Unknown), ~28 agents, all WS-disconnected. GuruRMM API `http://172.16.3.30:3001`.
## Commands & Outputs
- UDM jump+key SSH: paramiko Transport over D2TESTNAS `direct-tcpip` channel to 192.168.0.254:22, `auth_publickey('root', ~/.ssh/id_ed25519)`.
- UDM SIP forward: `iptables -t nat -A UBIOS_PREROUTING_USER_HOOK -d 67.206.163.122/32 -s 66.7.123.0/24 -p udp --dport 5060 -j DNAT --to-destination 192.168.100.2:5060` (+ RTP 10000:20000, + `UBIOS_FORWARD_IN_USER` ACCEPTs).
- Safesite forensic sweep: PowerShell searching `C:\Users\*\{Downloads,Desktop,Documents,AppData\Local\Microsoft\Windows\INetCache\Content.Outlook,Temp,Recent,OneDrive*}` for `*06122026*`, reads `-Stream Zone.Identifier`, scans browser `History` DBs; emits `{host,hitCount,hits}`. Result: 7/9 hitCount=0.
## Pending / Incomplete Tasks
- **Safesite #32395:** sweep DESKTOP-3USU20B (lennyg, enrolled, cmd 1cf8dfea queued) and DESKTOP-LOPKB4G (jeremiahw, NOT enrolled) when online; then email Jonathan final findings + mark coord todo `5766a59f` done. (Auto-followup coordinated: todo 5766a59f + broadcast faaec0ce.)
- **Dataforth #32392:** Mike to add the UI port-forward afterhours (on_boot.d covers reboots meanwhile). Re-apply `PJSip.class.php` patch after any future `fwconsole ma updateall`.
- **Birth Biologic:** validate `reset-password.sh` end-to-end on next real admin reset.
## Reference Information
- **Syncro tickets:** #32392 (Dataforth FreePBX, Resolved, 1.0h emergency remote, prepaid 34.5→33.0). #32395 (Safesite forensics, In Progress, 1.5h remote, prepaid 1.5→0; contact Jonathan Byrd 3458770; invoice 1650620815).
- **Commits:** reset-password.sh + doc (31e5cbd3); vault UDM creds (880761d).
- **Coord:** todo `5766a59f-0ddf-43d8-b16b-1c60024a3c04`; broadcast `faaec0ce-ed5f-4e0f-8693-904a3d000c38`.
- **Artifacts on GURU-5070:** `~/Downloads/safesite-recall-proof.json`, `~/Downloads/safesite-forensic-results.txt`.
- **Forensic cmd ids (Safesite re-dispatch):** 86340d9b, 8d3e6530, 9aa25e67, 1cf8dfea, 3322e787, 16b2a2b1.