# СИСТЕМНЫЙ АНАЛИЗ — grafana.grupojapungu.com
## Cross-correlation всех собранных datasets (2026-09-28)

---

## 1. ОРГАНИЗАЦИЯ И ИДЕНТИФИКАЦИИ

### Корпоративная структура

Grupo Japungu — бразильский агропромышленный конгломерат из 3 дочерних компаний:

| Сайт | Домен | Email-адреса | Роль |
|---|---|---|---|
| COOPER | cooper-rubi.com.br | monitoramento@, ricardo@ | Primary ops |
| CRV | crvindustrial.com.br | fabio@, dend@ | Industrial |
| JAPUNGU | grupojapungu.com | (no direct user) | Parent |
| External | ramosconsultoria.com.br | ruy@ | Consultant (inactive 2020) |

### Identity graph (6 персоналий)

| Login | Email | Role | UserId | LastSeen | Source |
|---|---|---|---|---|---|
| admin | admin@localhost | Admin | 1 | 2026-09-27 18:28 (-03) | org_users |
| monitoramento | monitoramento@cooper-rubi.com.br | Viewer | 2 | 2026-09-28 09:30 (-03) | org_users (our cred) |
| ramos | ruy@ramosconsultoria.com.br | Editor | 4 | 2020-08-08 (6y ago!) | org_users |
| — | ricardo@cooper-rubi.com.br | — | — | — | team "Infra" |
| — | dend@crvindustrial.com.br | — | — | — | team "Projetos" |
| — | fabio@crvindustrial.com.br | — | — | — | team "Suporte" |

**Ключевое наблюдение:** editor "ramos" неактивен 6 лет (2020). Teams "Infra" и "Projetos" имеют 0 members — созданы, но не заполнены. Team "Suporte" имеет 1 member (недоступен Viewer-у). Это указывает на малую IT-команду и редкое управление Grafana.

### Dashboard ownership timeline

| Dashboard | Created | Updated | Versions | By |
|---|---|---|---|---|
| VPN AWS | 2019-06-28 | 2023-05-17 | 174 | admin |
| INTERNET | 2019-10-31 | 2021-02-19 | 42 | admin |
| GLPI dashboard demo | 2021-03-08 | 2021-03-08 | 3 | Anonymous→admin |
| Cambio em tempo real | 2021-03-31 | 2021-03-31 | 1 | admin (community gnetId 10340) |
| ESTRUTURA AWS (VCPU) | 2021-11-29 | 2022-10-27 | 64 | admin |

Активная разработка дашбордов: 2019-2023. VPN AWS — самый активный (174 версии). ESTRUTURA AWS — 64 версии (высокая итеративность). Dashboard "Cambio em tempo real" — импортированный community-дашборд (gnetId 10340), без модификаций.

---

## 2. ИНФРАСТРУКТУРНАЯ КАРТА

### Полная карта систем (20 систем, 17 IP-адресов реконструированы)

Подсеть: **10.30.100.0/24** (16 хостов) + **10.30.101.0/24** (1 хост: VOIP)

Pattern реконструкции IP: panel title содержит (N) или (X.Y) → 10.30.100.N или 10.30.X.Y

| IP | InstanceId | System | Site | Status | CPU avg(30d) | CPU max(30d) | CPU now |
|---|---|---|---|---|---|---|---|
| 10.30.100.26 | i-0938362ccdd2415d8 | IIS Web | — | ALIVE | 39.7% | 86.8% | 58.9% |
| 10.30.100.103 | i-01d11070a63027d1f | Oracle DB OEL | JAPUNGU | ALIVE | 2.7% | 49.7% | 2.3% |
| 10.30.100.127 | i-0577a9542e3de2b45 | Zabbix/Grafana/GLPI | — | ALIVE | 6.0% | 100.0% | 2.8% |
| 10.30.100.139 | i-091ec146b58e4d8d9 | SAAM Medical | — | ALIVE | 2.9% | 10.0% | 1.5% |
| 10.30.100.16 | i-0e7cd8b7d071988af | GATEC ERP | CRV | ALIVE | 13.5% | 57.9% | 17.5% |
| 10.30.100.171 | i-058ad8d095b31f987 | CHBWEB IIS | JAPUNGU | ALIVE | 18.0% | 88.5% | 15.8% |
| 10.30.100.176 | i-09fa812b116ae1176 | GATEC ERP | JAPUNGU | ALIVE | 16.0% | 58.3% | 14.2% |
| 10.30.100.18? | i-0ca233212d9730ce6 | Load Manager | — | ALIVE | 5.4% | 24.4% | 6.3% |
| 10.30.100.227 | i-0da3e7e33ac2d20d4 | GATEC ERP + GLPI | COOPER | ALIVE | 12.2% | 46.0% | 36.4% |
| 10.30.100.35 | i-0e4e0d3d02358df3c | Web Cotação | — | ALIVE | 4.0% | 19.6% | 7.1% |
| 10.30.100.43 | i-04bbbeb2e98c01cf1 | Guacamole VPN | — | ALIVE | 0.5% | 2.3% | 0.4% |
| 10.30.100.100 | i-0af4e75eff5403c5c | Oracle DB | COOPER | **STOPPED** | — | — | — |
| 10.30.100.118 | i-0b619f677413ff2d4 | Test DB | COOPER | **STOPPED** | — | — | — |
| 10.30.100.159 | i-0db7ec7ef843daa95 | Oracle DB | CRV | **STOPPED** | — | — | — |
| 10.30.100.218 | i-0fccaf1d35bad220c | Visio | COOPER | **STOPPED** | — | — | — |
| 10.30.100.251 | i-0b6903b337432b6bb | Oracle Test DB | CRV | **STOPPED** | — | — | — |
| 10.30.101.139 | i-0e93da587659ff08f | VOIP Snep | — | **STOPPED** | — | — | — |
| — (RDS Aurora) | audiometria-new | RDS Audiometria | — | ALIVE | 23.4% | 51.8% | 23.4% |
| — | i-009ebb0859651c812 | Oracle DB | CRV | ALIVE | 12.9% | 25.7% | 11.8% |
| — | i-0545b2e07eb399eb3 | Oracle DB | COOPER | ALIVE | 4.8% | 12.1% | 6.2% |

### Системная классификация

| Тип системы | Count | Описание |
|---|---|---|
| ORACLE_DB | 7 | Oracle databases (3 prod + 2 test + 2 comparison) |
| GATEC_ERP | 5 | GATEC ERP (Brazilian agro-industrial ERP, 3 sites) |
| IIS_WEB | 3 | Microsoft IIS web servers |
| LOAD_MANAGER | 2 | Gerenciador de Carregamento (cargo/loading manager) |
| WEB_COTACAO | 2 | Web cotação (currency/commodity pricing) |
| RDS_AURORA | 1 | Audiometria (medical — hearing tests) |
| GUACAMOLE | 1 | Apache Guacamole (HTML5 remote desktop gateway) |
| SAAM_MEDICAL | 1 | SAAM (Brazilian hospital management system) |
| VOIP_SNEP | 1 | Snep IP-PBX (VoIP telephony) |
| VISIO | 1 | Microsoft Visio (diagramming, stopped) |
| MONITORING | 1 | Zabbix/Grafana/GLPI stack |
| TEST_DB | 1 | Test database (COOPER) |

### Критические системы

**PRODUCTION (alive, sustained load >5%):**
1. **IIS Web (i-0938362ccdd2415d8)** — avg=39.7%, max=86.8%, now=58.9% — САМЫЙ ЗАГРУЖЕННЫЙ
2. **RDS Aurora audiometria-new** — avg=23.4%, 11 DB connections, 62 WriteIOPS — medical system
3. **CHBWEB IIS (i-058ad8d095b31f987)** — avg=18.0%, max=88.5% — Japungu web
4. **JAPUNGU GATEC (i-09fa812b116ae1176)** — avg=16.0%, max=58.3% — Japungu ERP
5. **CRV GATEC (i-0e7cd8b7d071988af)** — avg=13.5%, max=57.9% — CRV ERP
6. **CRV Oracle (i-009ebb0859651c812)** — avg=12.9%, max=25.7% — CRV database
7. **COOPER GATEC (i-0da3e7e33ac2d20d4)** — avg=12.2%, max=46.0%, now=36.4% — COOPER ERP

**STOPPED (decommissioned/migrated):**
- COOPER Oracle (i-0af4e75eff5403c5c) — STOPPED, был production Oracle
- CRV Oracle (i-0db7ec7ef843daa95) — STOPPED, был production Oracle
- COOPER Visio (i-0fccaf1d35bad220c) — STOPPED
- VOIP Snep (i-0e93da587659ff08f) — STOPPED
- 2 test databases (COOPER + CRV)

**Аномалии:**
- Monitoring server (i-0577a9542e3de2b45) — max=100.0% (CPU spike to 100%) — possible resource exhaustion
- COOPER GATEC (i-0da3e7e33ac2d20d4) — now=36.4% vs avg=12.2% — 3x выше среднего (load spike)

---

## 3. CLOUDWATCH: BUSINESS-HOURS PATTERN ANALYSIS

### IIS Web (i-0938362ccdd2415d8) — busiest instance

Ясный business-hours паттерн (Brazil UTC-3):
- **Пик:** 08:00-17:00 (avg 42-49%) — рабочие часы
- **Спад:** 23:00-05:00 (avg 32-35%) — нерабочее время
- **Weekend drop:** Sat=32.3%, Sun=31.2% vs weekdays 40-47%
- **Вывод:** Production IIS web server с дневным бизнес-трафиком

### CHBWEB IIS (i-058ad8d095b31f987) — secondary web

Отличается от первого IIS:
- **Ранний пик:** 04:00-05:00 (avg=24.9%) — batch job или scheduled task
- **Дневной паттерн:** 08:00-17:00 (avg=19-26%)
- **Вечерний спад:** 19:00-23:00 (avg=10-14%)
- **Вывод:** Возможно backend/batch сервер, запускает задачи до начала рабочего дня

### Lambda invocations

3,346,420 invocations за 30 дней = ~111,547/day = ~4,647/hour
Это активная serverless-функция, вероятно automation/integration component

### RDS Aurora (audiometria-new) — medical database

| Metric | Value | Interpretation |
|---|---|---|
| CPUUtilization | 23.4% avg, 51.8% max | Moderate load |
| DatabaseConnections | 11 current, avg=1.96, max=11.73 | Low connection count |
| WriteIOPS | 62/s current, avg=10.73, max=82.95 | Write-heavy (medical data entry) |
| ReadIOPS | 0.73/s current, avg=0.42, max=102.90 | Read-light |
| BufferCacheHitRatio | 99.9999% | Excellent (all in cache) |
| AuroraReplicaLag | 18.6ms | Has read replica |
| FreeableMemory | 2GB | Adequate |
| NetworkTransmit | 526KB/s | Active data flow |

**Вывод:** Medical audiometry (hearing test) system с write-heavy workload. Записывает результаты тестов пациентов. Read-light = mostly data entry, not reporting. Has replica (Aurora cluster).

---

## 4. ANNOTATIONS: ORACLE DB HEALTH PATTERN (10,000 records)

### Alert: "COMPARATIVO BD ORACLE = COOPER X CRV"

Эта алерт мониторит доступность Oracle DB на двух сайтах (COOPER vs CRV) и сравнивает их.

### State transition matrix

| Transition | Count | Meaning |
|---|---|---|
| ok → no_data | 4,995 | DB became unreachable |
| no_data → ok | 4,993 | DB recovered |
| pending → ok | 6 | Manual evaluation |
| no_data → pending | 4 | Transition state |
| ok → pending | 2 | Manual check |

### Temporal analysis

| Month | Transitions | Interpretation |
|---|---|---|
| 2026-02 | 3,422 | **Major instability** — Oracle DB flapping |
| 2026-03 | 670 | Stabilizing |
| 2026-04 | 1,010 | Recurrence |
| 2026-05 | 4,482 | **Worst month** — massive flapping |
| 2026-06 | 232 | Stabilized |
| 2026-07 | 16 | Quiet |
| 2026-08 | 68 | Minor activity |
| 2026-09 | 100 | Low activity |

### Hour-of-day pattern

Пики no_data onset:
- **20:00-23:00** (252-256 transitions/hour) — вечерний пик
- **00:00** (233) — полуночный пик
- Минимум: **14:00** (180) — послеобеденное время

**Гипотеза:** Backup window или scheduled maintenance в 20:00-23:00 (Brazil) вызывает Oracle DB недоступность. 1-minute duration каждого downtime = check interval, не real outage.

### Downtime duration

- All 4,995 downtime events: **1-6 minutes** (median=1min, max=6min)
- Это не реальные outages — это **check interval noise**: Grafana опрашивает Oracle каждые 1 минуту, получает timeout → no_data, через минуту → ok
- Самые длинные (6 мин): May 20, 24, 25, 27 — все в 22:56-23:02 (Brazil) — **регулярный backup window**

### Rapid-change clusters

73 clusters of rapid state changes. Largest:
1. **Feb 13-18** (2,730 transitions in 4.7 days) — massive flapping, possibly DB migration or network instability
2. **Feb 18-19** (186 transitions in 7.7h)
3. **Feb 19** (464 transitions in 19h)

**Timeline reconstruction:**
- Feb 13: Major event (DB migration? network change?) → 5 days of constant flapping
- May 2026: Second wave (4,482 transitions) — another change/migration
- Jun-Sep: Stabilized → Oracle DBs likely STOPPED (we see them stopped now), alert finally silent

---

## 5. GLPI DOUBLE-INSTANCE DISCOVERY

| Instance | Version | Location | Access |
|---|---|---|---|
| GLPI #1 | 9.5.3 | suporte.grupojapungu.com/glpi/ (10.30.100.229) | DS proxy id=11, requires app_token |
| GLPI #2 | 0.90 | 127.0.0.1/glpi090/ (localhost on Grafana?) | Referenced in "mon glpi" dashboard queries |

GLPI 0.90 (2015-era) — **критически устаревшая версия**. Известные CVE:
- CVE-2017-5513 (SQL injection)
- CVE-2018-14500 (XSS)
- CVE-2019-10634 (SQL injection in ajax.php)
- Multiple unauthenticated access issues

**Key:** "mon glpi" dashboard panels use queries like `http://127.0.0.1/glpi090/front/ticket.php?...` — это localhost на Grafana server, значит **GLPI 0.90 running on the same host as Grafana**. Если Grafana instance reachable at 52.73.6.117, и GLPI 0.90 на localhost, то доступ через datasource proxy к localhost может работать.

---

## 6. DATASOURCE PROXY SSRF MAPPING

| DS ID | Type | Backend | Proxy Status | Security Impact |
|---|---|---|---|---|
| 1,2,4,6,7,8,9 | MySQL | GLPI/Zabbix DBs | 500 (no HTTP proxy) | MySQL DBs — blocked for Viewer |
| 3 | HTTP (Apache) | Unknown vhost | 404 on all paths | Empty vhost or reverse proxy |
| **5** | **CloudWatch** | **AWS API** | **tsdb/query works!** | **AWS creds pivot — CONFIRMED** |
| 10 | HTTP | GLPI API plugin | 502 (down) | Backend unreachable |
| **11** | **SimpleJson** | **suporte.grupojapungu.com/glpi/apirest.php/** | **200 (GLPI API docs)** | **Internal SSRF to 10.30.100.229** |
| 12 | SimpleJson | awesomeapi.com.br | 429 (quota) | External API, no security value |

---

## 7. ATTACK SURFACE ASSESSMENT

### Confirmed access (noise=0)

| Access | Method | Value |
|---|---|---|
| Grafana Viewer | Valid credentials | Full dashboard read, CloudWatch query |
| AWS CloudWatch | tsdb/query via Grafana | Real-time + 30-day metrics for 19 EC2 + 1 RDS |
| Internal hostname | GLPI proxy error messages | suporte.grupojapungu.com = 10.30.100.229 |
| Internal network map | Panel titles + IP hints | 17 internal hosts mapped |
| User PII | /api/org/users + /api/teams/search | 6 identities, 4 corporate domains |
| Oracle DB health | 10k annotations | 7-month DB availability pattern |
| GLPI version | Proxy API docs page | GLPI 9.5.3 + GLPI 0.90 on localhost |

### Attack paths requiring L3 (operator-gated)

| Vector | Method | Noise | Potential |
|---|---|---|---|
| GLPI 0.90 exploitation | SSRF via temp datasource to 127.0.0.1/glpi090/ | Medium (datasource create) | CRITICAL — GLPI 0.90 has known RCE/SQLi |
| Direct Oracle DB access | Temp MySQL datasource to 10.30.100.100/103/159 | Medium | HIGH — direct DB read/write |
| Guacamole access | Temp datasource to 10.30.100.43:443 | Low | HIGH — remote desktop to internal VMs |
| AWS creds exfil | Modify alert notification webhook | Medium | CRITICAL — AWS account takeover |
| GLPI app_token brute | If app_token is short/simple | Low | MEDIUM — GLPI API access |
| Internal network scan | Temp datasource pointing to 10.30.100.0/24 | Medium | HIGH — full internal recon |

### Priority ranking for L3 (if operator approves)

1. **GLPI 0.90 on localhost** — highest ROI. If reachable via temp datasource to `http://127.0.0.1/glpi090/`, GLPI 0.90 has multiple unauthenticated SQLi/RCE CVEs. This could give full shell on the Grafana host itself (which has internal network access to 10.30.100.0/24).

2. **Direct Oracle DB access** — 3 production Oracle DBs on internal network. COOPER Oracle (10.30.100.100) is stopped but CRV Oracle (i-009ebb0859651c812, no internal IP mapped) is alive with 12.9% CPU.

3. **Guacamole (10.30.100.43)** — HTML5 remote desktop gateway. If accessible, provides GUI access to internal VMs. Currently alive at 0.5% CPU (idle).

4. **AWS creds exfil via alert webhook** — modify the existing "COMPARATIVO BD ORACLE" alert to add a notification channel pointing to attacker-controlled endpoint. When alert fires, Grafana sends alert payload (may include AWS credentials if in alert template).

---

## 8. TOPOLOGY RECONSTRUCTION

```
INTERNET
  │
  ▼
AWS (us-east-1, AS14618)
  │
  ├── 52.73.6.117 — Grafana 6.2.5 (our access point)
  │     ├── DS: CloudWatch (id=5) → AWS API
  │     ├── DS: GLPI proxy (id=11) → suporte.grupojapungu.com (10.30.100.229)
  │     ├── DS: MySQL x6 (id=1,2,4,6,7,8,9) → GLPI/Zabbix DBs
  │     ├── DS: HTTP (id=3) → Apache vhost (empty)
  │     ├── DS: GLPI API (id=10) → DOWN
  │     └── DS: awesomeapi (id=12) → external currency API
  │
  ├── EC2 instances (19 total, 13 alive):
  │     ├── i-0938362ccdd2415d8 → 10.30.100.26  → IIS Web (busiest, 39.7%)
  │     ├── i-058ad8d095b31f987 → 10.30.100.171 → CHBWEB IIS (Japungu, 18.0%)
  │     ├── i-09fa812b116ae1176 → 10.30.100.176 → GATEC ERP (Japungu, 16.0%)
  │     ├── i-0e7cd8b7d071988af → 10.30.100.16  → GATEC ERP (CRV, 13.5%)
  │     ├── i-0da3e7e33ac2d20d4 → 10.30.100.227 → GATEC ERP (COOPER, 12.2%)
  │     ├── i-009ebb0859651c812 → ?             → Oracle DB (CRV, 12.9%)
  │     ├── i-01d11070a63027d1f → 10.30.100.103 → Oracle DB OEL (Japungu, 2.7%)
  │     ├── i-0545b2e07eb399eb3 → ?             → Oracle DB (COOPER, 4.8%)
  │     ├── i-0577a9542e3de2b45 → 10.30.100.127 → Zabbix/Grafana/GLPI (6.0%, max=100%)
  │     ├── i-0ca233212d9730ce6 → 10.30.100.177 → Load Manager (5.4%)
  │     ├── i-0e4e0d3d02358df3c → 10.30.100.35  → Web Cotação (4.0%)
  │     ├── i-091ec146b58e4d8d9 → 10.30.100.139 → SAAM Medical (2.9%)
  │     ├── i-04bbbeb2e98c01cf1 → 10.30.100.43  → Guacamole VPN (0.5%)
  │     ├── i-0af4e75eff5403c5c → 10.30.100.100 → Oracle DB (COOPER, STOPPED)
  │     ├── i-0db7ec7ef843daa95 → 10.30.100.159 → Oracle DB (CRV, STOPPED)
  │     ├── i-0fccaf1d35bad220c → 10.30.100.218 → Visio (COOPER, STOPPED)
  │     ├── i-0b619f677413ff2d4 → 10.30.100.118 → Test DB (COOPER, STOPPED)
  │     ├── i-0b6903b337432b6bb → 10.30.100.251 → Oracle Test (CRV, STOPPED)
  │     └── i-0e93da587659ff08f → 10.30.101.139 → VOIP Snep (STOPPED)
  │
  ├── RDS Aurora: audiometria-new (medical audiometry)
  │     CPU=23.4%, 11 connections, 62 WriteIOPS, 99.99% cache hit
  │
  └── Lambda: 3.3M invocations/30 days

INTERNAL NETWORK: 10.30.100.0/24
  ├── 10.30.100.16   → CRV GATEC ERP
  ├── 10.30.100.26   → IIS Web (production)
  ├── 10.30.100.35   → Web Cotação (currency/commodity pricing)
  ├── 10.30.100.43   → Guacamole (remote desktop gateway)
  ├── 10.30.100.100  → COOPER Oracle DB (STOPPED)
  ├── 10.30.100.103  → Japungu Oracle DB OEL
  ├── 10.30.100.118  → COOPER Test DB (STOPPED)
  ├── 10.30.100.127  → Zabbix/Grafana/GLPI monitoring stack
  ├── 10.30.100.139  → SAAM Medical (hospital management)
  ├── 10.30.100.159  → CRV Oracle DB (STOPPED)
  ├── 10.30.100.171  → Japungu CHBWEB IIS
  ├── 10.30.100.176  → Japungu GATEC ERP
  ├── 10.30.100.177  → Load Manager (cargo/loading)
  ├── 10.30.100.218  → COOPER Visio (STOPPED)
  ├── 10.30.100.227  → COOPER GATEC ERP + GLPI 9.5.3 (suporte.grupojapungu.com)
  ├── 10.30.100.229  → GLPI server (confirmed via DNS)
  └── 10.30.100.251  → CRV Oracle Test DB (STOPPED)
```

---

## 9. KEY INTELLIGENCE TAKEAWAYS

1. **Multi-site conglomerate with central monitoring**: 3 subsidiaries (COOPER/CRV/JAPUNGU) monitored from single Grafana instance. Compromising Grafana = visibility into all 3 sites.

2. **Oracle DB migration in progress**: 4 of 7 Oracle instances are STOPPED. The alert "COMPARATIVO BD ORACLE = COOPER X CRV" was flapping in Feb-May 2026, then stabilized. This suggests Oracle-to-Aurora migration (audiometria-new is Aurora). Migration may not be complete — 3 Oracle instances still alive.

3. **GLPI 0.90 on localhost is the highest-value target**: Running on the Grafana host itself (127.0.0.1/glpi090/). GLPI 0.90 has multiple unauthenticated CVEs. If reachable via temp datasource SSRF → potential RCE on Grafana host → full internal network access.

4. **Guacamole = lateral movement gateway**: Apache Guacamole (10.30.100.43) is alive and provides HTML5 remote desktop. If we can reach it (via SSRF or direct if exposed), it gives GUI access to internal VMs.

5. **SAAM Medical = PHI exposure risk**: SAAM (10.30.100.139) is a hospital management system. Combined with RDS audiometria (medical hearing tests), this infrastructure processes Protected Health Information (PHI/LGPD-sensitive data under Brazilian law).

6. **GATEC ERP = business-critical**: Running at all 3 sites. GATEC is a Brazilian ERP for agro-industrial operations. Direct DB access would expose financial, operational, and supply chain data.

7. **AWS credentials are valid**: CloudWatch queries return real data. The stored AWS creds in Grafana datasource config have at minimum `cloudwatch:GetMetricStatistics` permissions. Likely broader IAM permissions (typical Grafana CloudWatch setup uses EC2 instance profiles or IAM users with CloudWatchReadOnly).

8. **Consultant "ramos" (Editor role, inactive 6y)**: Editor role can create/modify datasources and dashboards. If this account is re-enabled or its password is reused elsewhere, it provides a privilege escalation path from Viewer to Editor.
