The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.
ja4x2166164053c1_2166164053c1_30d204a01551
45.87.53.6:8084 ·
vShell
Last confirmed (today)
first seen2026-09-02 10:21 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.
The certificate names above were validated by the issuing authority at issuance. They describe the certificate, not conduct by the names' owner — a legitimately issued certificate can be deployed on a listed host by whoever holds its private key, so treat the name as a pivot to investigate rather than as an attribution.
The certificate names above were validated by the issuing authority at issuance. They describe the certificate, not conduct by the names' owner — a legitimately issued certificate can be deployed on a listed host by whoever holds its private key, so treat the name as a pivot to investigate rather than as an attribution.
callbackcs.tpedu2metricstw.dpdns.org · operator-supplied; a redirector or impersonation target, not an attribution
beacon typeHTTPS
cs versionCobalt Strike 4.9 (Sep 19, 2023)
getGET /api/v1/get
postPOST /api/v1/post
user-agentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246
sleep6s ±20%
watermark987654321
server key md523df461e477b2a85344332c55d2dd1c8
inject stubae5afcfee8026674dc8f3b4f2da46c7f
spawn to x86%windir%\syswow64\werfault.exe
spawn to x64%windir%\sysnative\werfault.exe
Observation history
18d agotoday
Observed on 18 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.
Shared JA4X issuance template · 289 hosts
These hosts issued certificates from the same template — the same distinguished-name
fields hashed in the same order. It links tooling, not necessarily an operator.
Showing 24 of 289. The rest are reachable from any of them.
Shared Cobalt Strike watermark · 108 hosts
A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing
one were built from the same copy of the software — which is not the same as one operator,
since cracked and leaked builds circulate widely and share a watermark by definition.
Showing 24 of 108. The rest are reachable from any of them.
Samples served · 1 file
Files this address was observed DELIVERING, confirmed as malware by detonation
or by analysis of the file itself. Delivery is an observation, not an attribution — a widely
distributed sample can reach unrelated hosts.
This page is generated from automated scanning and is publicly available. If you
are responsible for this address and it should not be listed, write to
support@publicmosaic.com —
see abuse & takedown for what we need and what happens next, or
opt-out to exclude a whole range from scanning.
Addresses are frequently compromised third-party hosts rather than
infrastructure their owner stood up. A listing records what a scan observed at a point in
time; it is not an allegation about whoever pays for the address.