# GitLab Public Repo — New Credentials Found
# Date: 2026-09-22

## Source: gitlab.pharmalink.id (35.247.168.114)
## Public project: alvinjo15/api_Marketing (id=91)

## NEW CREDENTIALS

### MySQL — spetnaz@34.87.44.167
- **User**: spetnaz
- **Password**: sp3tn4z2019
- **Host**: 34.87.44.167:3306 (GCP MySQL — was firewalled!)
- **Database**: upload-download-vb
- **Source**: files/etc/skeleton/skeleton.development.yaml

This is a NEW MySQL credential set not found in any binary analysis!
The password sp3tn4z2019 was NOT in our custom wordlist for hashcat.

## GitLab instance info
- URL: https://gitlab.pharmalink.id
- IP: 35.247.168.114 (GCP)
- OAuth2 token in repos: 6314442f... (EXPIRED)
- Public API accessible without auth
- 4 public projects, 4 groups visible

## Architecture revealed by repos
- **black-bear** = panakea/virtue (telemedicine)
  - panakea-be, panakea-fe, panakea-py, panakea-dashboard
  - panakea-virtue-lab-operators, panakea-virtue-phlebotomist
  - panakeavirtue-be, panakeavirtue-doctor
  - telekonsultasi-service, panakea-payment-api
  - horizon-api, panakea-dataplatform

- **innopharm** = manufacturing/IoT
  - innokitch, admin-innopharm-be/fe
  - master-manufacturing-be, manufacturing-fe
  - pharmavit-master-be/fe
  - inventaris-be/fe
  - be-smart-building, smart-building-setting-be
  - iot-healthcare-be

- **white-panther** = manufacturing/admin
  - manufacture-be, py-smart-building
  - inventaris-fe, admin-innopharm-fe

## GitLab OAuth2 token (expired)
6314442f2385edd0216b39e9a19f29cdec213e2f483d59ab1d3b6a1fd5636aed
- Used in all 13 k8s-env repo remotes
- Format: oauth2:<token>@gitlab.pharmalink.id
- Status: EXPIRED (401 invalid_token)

## Other findings
- Vilbert Gunawan (vilbertgunawan@gmail.com) — developer
- Go skeleton project with MySQL, mux, sqlx
- Maintainer in Dockerfile: Vilbert Gunawan
