Abuse & takedown
If an address, domain or certificate you are responsible for appears in our indicator feed and should not, write to us and we will re-examine it. This page says what we publish, what we need from you to check a listing, and what happens after you write.
Effective 29 August 2026 · Public Mosaic LLC
Write to us
support@publicmosaic.com, with Abuse in the subject line. There is no form and no account required. A plain email from a human is fine, and so is an automated report from an abuse desk.
Include, if you can:
- The indicator exactly as it appears in the feed — the IP address and port, and the domain if one is listed. A listing is per address and port, so an address alone may match several records or none.
- What you believe is wrong — see the grounds below. One sentence is enough; you do not need to prove a negative.
- Your relationship to the host — operator, hosting provider, network owner, incident responder acting for the owner.
You do not need to send logs, packet captures, or evidence of remediation. We re-check the host ourselves rather than asking you to prove anything.
What we publish, and what a listing means
We publish infrastructure — addresses, domains, ports and certificates assessed as command-and-control servers, at /indicators and in the machine-readable feed. A listing is a statement that our scanner observed determinative command-and-control characteristics at that address and port, at the times recorded on the record. It is not a statement about who owns the address, who rents it, or who is responsible.
A host reaches the feed only on a determinative match: it is malicious, sits on a routable address, and either its framework was identified by value — certificate DN attributes, the JA4X X.509 template, a framework marker path, or a behavioural probe — or it served a malicious-category content signature. JARM and JA4S corroborate but are never determinative on their own. The lower-confidence candidate tier is never published, and the publication floor is confidence 90.
Grounds we act on
These are the cases we see most, and each of them is a good reason to write:
- Misidentification. The service at that address and port is not what we assessed it to be. Signatures can and do produce false matches; retiring one retracts every record it produced, not just the one you wrote about.
- Remediated compromise. The host was compromised, you have cleaned it up, and the listing now describes a state that has ended.
- Reassignment. The address has been reallocated to you since the sighting, and the record describes a previous tenant's activity.
- Shared infrastructure. The indicator names a platform, CDN or reverse proxy rather than the tenant actually operating the service behind it.
What happens next
We re-scan the host and re-examine the signal the listing rested on. If we withdraw the listing, two things happen on different clocks, and it is worth being precise about which is which:
- The page for the address is removed immediately. It starts answering 410 Gone within about a minute, which is also the signal search engines treat as a deliberate removal rather than a broken link.
- The record leaves the feed at the next export cycle, which runs about every fifteen minutes. That is a separate system from this website, so the two do not complete at the same moment.
There is nothing further for you to do in either case, and no confirmation step to chase.
If we do not withdraw it, we will tell you why, in terms specific enough to argue with. We would rather be shown wrong than be quietly ignored, and a disputed listing that survives should at least be legible to the person disputing it.
These listings have their own pages, and search engines index them
Every address in the feed has a page at publicmosaic.com/ip/<address>. Those pages are served as ordinary HTML and are open to search engines, so an address that appears here can show up in results for a search on that address.
We think that is the right way to publish this — a defender who finds an address in a log at 2am should be able to look it up — but it changes what a listing costs the person responsible for the address, so two things are worth stating.
A listing is an observation, not an allegation about you. A large share of command-and-control infrastructure runs on machines somebody else compromised, or on rented addresses whose provider had no part in it. The page records what a scan saw at a point in time. It does not say who put it there.
Removal is per address, and it is the fast route. Write to us as above and, if the listing is withdrawn, the page goes within about a minute. If you are responsible for a whole range rather than one machine, opt-out is the better instrument — it is verified, and it covers addresses we have not seen yet as well as the ones we have. A takedown here does not: it retracts what was published, and a fresh detection on the same address later would be listed again.
Listings expire on their own
A record drops out 90 days after its last confirmed sighting. Hosts are re-scanned about every thirty minutes, so a host that has genuinely stopped serving command-and-control traffic normally falls out well before that, without anyone writing to us. The 90-day window is an outer bound, not a wait: it exists so that infrastructure which goes quiet and returns is not repeatedly forgotten.
It does mean a listing can outlast the controller behind it. If that is your situation, write anyway — we would rather re-check early than leave a remediated host listed for weeks.
What removal here does not reach
The feed is published TLP:CLEAR for defensive use, which means anyone may copy it. Removing a record from our feed stops us publishing it and stops it reaching anyone who reads us going forward, but we cannot retract copies already taken by other people, aggregators, or security products that ingested the feed earlier. If a listing has propagated somewhere that matters to you, tell us and we will confirm in writing that we have withdrawn it, which is usually what a downstream consumer needs.
Related
If you operate a network and want your address space excluded from scanning and listing altogether rather than contesting a single record, see opt-out. What this site records about you when you read it — which is a separate matter from the indicators, and never joined to them — is set out in privacy.