public mosaic llc support@publicmosaic.com
malware family

SQLRCE

3 addresses convicted as SQLRCE remote-access trojan controllers — 3 still listed, 0 archived. Observed from 2026-08-29.

TLP:CLEAR
addresses 3 3 still listed
observations 6 address and port pairs
networks 2 distinct ASNs
first seen 2026-08-29 oldest observation

Detection packs

Rules for the 3 still-listed addresses on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.

About

Named for the channel that distributed it. One of these hosts serves a domain whose label is feiying — 飞鹰, "flying eagle" — and the builds this operator sold were reportedly patched copies of that RAT. That is the whole basis for the association: a name on a single host, not a fingerprint the corpus can match. The rule from that family applies here regardless: a listed address is the operator's panel, never an infected handset.

Ports

:803:4433

Addresses

Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.