public mosaic llc support@publicmosaic.com
malware family

Metasploit

1 address convicted as Metasploit command-and-control servers — 1 still listed, 0 archived. Observed from 2026-09-03.

TLP:CLEAR
addresses 1 1 still listed
observations 1 address and port pairs
networks 1 distinct ASNs
first seen 2026-09-03 oldest observation

Detection packs

Rules for the 1 still-listed address on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.

About

Metasploit is the open-source penetration-testing framework maintained by Rapid7. A listed address is a handler exposed on the internet — a listener waiting for a payload to call back — which criminals run as readily as red teams do. Upstream population estimate: hosts of this family observed moving toward AS14061 on 2026-09-06 (fewer than 10 hosts) — the upstream scanner's estimate from a passive search population, not this archive's observation, and shown only for networks where this archive holds at least one host of this family.

Ports

:4431

Addresses

Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.