public mosaic llc support@publicmosaic.com
confirmed host

IP address 49.51.230.17

Cobalt StrikevShellcontrollers · :50050, :53001, :9898, :9001

Last confirmed 2026-09-15, first seen 2026-09-02. On AS132203.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 4 ports — :50050, :53001, :9898, :9001, across 2 malware families.

49.51.230.17:50050 · Cobalt Strike

Last confirmed (today)

first seen2026-09-04 05:26 UTC
serviceip-port · tcp · Cobalt Strike team server default
networkAS132203 · Tencent Building, Kejizhongyi Avenue
confidence100 / 100
tls certificate02fd77af71d8670199c4295286416c3aa3f06100430725c9e3feab0cec10dfe3
cert subjectPwn3rs Striked
cert subject orgPwn3rs
cert issuerPwn3rs Striked
cert issuer orgPwn3rs
cert validity2026-08-08 → 2026-11-06
cert typeself-signed
cert key3072-bit
cert serial (decimal)351558072506005757

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551
jarm2ad2ad16d2ad2ad00042d42d00042ddb04deffa1705e2edc44cae1ed24a4da

49.51.230.17:53001 · Cobalt Strike

Last confirmed (today)

first seen2026-09-02 10:22 UTC
serviceip-port · tcp
networkAS132203 · Tencent Building, Kejizhongyi Avenue
confidence100 / 100
cs watermark987654321

Beacon configuration

callback49.51.230.17 · same as this host
beacon typeHTTP
cs versionCobalt Strike 4.9 (Sep 19, 2023)
getGET /load
postPOST /submit.php
user-agentMozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0; MAAU)
sleep60s ±0%
watermark987654321
server key md5d07ea6b0ded677bfd2ae45fc63d5ec2d
inject stub0b34150c342e35d2ffacb2227620d91c
spawn to x86%windir%\syswow64\rundll32.exe
spawn to x64%windir%\sysnative\rundll32.exe

49.51.230.17:9898 · vShell

Last confirmed (today)

first seen2026-09-02 10:22 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS132203 · Tencent Building, Kejizhongyi Avenue
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host49.51.230.17 · same as this host
c2 port9898
typetcp

49.51.230.17:9001 · vShell

Last confirmed (today)

first seen2026-09-02 10:22 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS132203 · Tencent Building, Kejizhongyi Avenue
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host49.51.230.17 · same as this host
c2 port9001
typetcp

Observation history

18d agotoday

Observed on 14 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared JA4X issuance template · 270 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →

Showing 24 of 270. Full cohort →

Shared Cobalt Strike watermark · 108 hosts

A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing one were built from the same copy of the software — which is not the same as one operator, since cracked and leaked builds circulate widely and share a watermark by definition.

Showing 24 of 108. The rest are reachable from any of them.

Samples served · 2 files

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups