public mosaic llc support@publicmosaic.com
confirmed host

IP address 45.87.53.6

Cobalt StrikevShellcontrollers · :38778, :8084, :443, :8443

Last confirmed 2026-09-15, first seen 2026-08-24. On AS142637.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 4 ports — :38778, :8084, :443, :8443, across 2 malware families.

45.87.53.6:38778 · Cobalt Strike

Last confirmed (today)

first seen2026-09-07 10:53 UTC
serviceip-port · tcp
networkAS142637 · STAR FAX GROUP PTE
confidence100 / 100
tls certificateac7ed3a41b7874c3daa1bd18cfcdb8bce6f713193de595e16379ba0e282dfbe1
cert subjectPwn3rs Striked
cert subject orgPwn3rs
cert issuerPwn3rs Striked
cert issuer orgPwn3rs
cert validity2026-06-02 → 2026-08-31
cert typeself-signed
cert key2048-bit
cert serial (decimal)1113549837

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551

45.87.53.6:8084 · vShell

Last confirmed (today)

first seen2026-09-02 10:21 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS142637 · STAR FAX GROUP PTE
confidence98 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host45.87.53.6 · same as this host
c2 port8084
typews

45.87.53.6:443 · Cobalt Strike

Last confirmed (today)

first seen2026-08-24 06:30 UTC
serviceip-port · tcp · HTTPS blend-in
observed hosttpedu2metricstw.dpdns.org
networkAS142637 · STAR FAX GROUP PTE
confidence100 / 100
tls certificate6a926e83b7c8667794f9b64f60a162e951a851b7647ab16097d539f7c466acda
cert subjectCloudFlare Origin Certificate
cert subject orgCloudFlare, Inc.
cert issuer orgCloudFlare, Inc.
cert validity2026-06-09 → 2041-06-05
cert typeCA-signed
cert key2048-bit
cert serial (decimal)273827072499912950271979373253768065885154073033
cert names*.tpedu2metricstw.dpdns.org tpedu2metricstw.dpdns.org

The certificate names above were validated by the issuing authority at issuance. They describe the certificate, not conduct by the names' owner — a legitimately issued certificate can be deployed on a listed host by whoever holds its private key, so treat the name as a pivot to investigate rather than as an attribution.

ja4xdc020972a4a8_9fb583da09a2_fb02ba79e164
jarm2ad2ad0002ad2ad00042d42d000000301510f56407964db9434a9bb0d4ee4a
cs watermark987654321

Beacon configuration

callbackcs.tpedu2metricstw.dpdns.org · operator-supplied; a redirector or impersonation target, not an attribution
beacon typeHTTPS
cs versionCobalt Strike 4.9 (Sep 19, 2023)
getGET /api/v1/get
postPOST /api/v1/post
user-agentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246
sleep6s ±20%
watermark987654321
server key md523df461e477b2a85344332c55d2dd1c8
inject stubae5afcfee8026674dc8f3b4f2da46c7f
spawn to x86%windir%\syswow64\werfault.exe
spawn to x64%windir%\sysnative\werfault.exe

45.87.53.6:8443 · Cobalt Strike

Last confirmed (today)

first seen2026-08-24 06:30 UTC
serviceip-port · tcp · alt-HTTPS
observed hosttpedu2metricstw.dpdns.org
networkAS142637 · STAR FAX GROUP PTE
confidence100 / 100
tls certificate6a926e83b7c8667794f9b64f60a162e951a851b7647ab16097d539f7c466acda
cert subjectCloudFlare Origin Certificate
cert subject orgCloudFlare, Inc.
cert issuer orgCloudFlare, Inc.
cert validity2026-06-09 → 2041-06-05
cert typeCA-signed
cert key2048-bit
cert serial (decimal)273827072499912950271979373253768065885154073033
cert names*.tpedu2metricstw.dpdns.org tpedu2metricstw.dpdns.org

The certificate names above were validated by the issuing authority at issuance. They describe the certificate, not conduct by the names' owner — a legitimately issued certificate can be deployed on a listed host by whoever holds its private key, so treat the name as a pivot to investigate rather than as an attribution.

ja4xdc020972a4a8_9fb583da09a2_fb02ba79e164
jarm2ad2ad16d2ad2ad00042d42d00042ddb04deffa1705e2edc44cae1ed24a4da
cs watermark987654321

Beacon configuration

callbackcs.tpedu2metricstw.dpdns.org · operator-supplied; a redirector or impersonation target, not an attribution
beacon typeHTTPS
cs versionCobalt Strike 4.9 (Sep 19, 2023)
getGET /api/v1/get
postPOST /api/v1/post
user-agentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246
sleep6s ±20%
watermark987654321
server key md523df461e477b2a85344332c55d2dd1c8
inject stubae5afcfee8026674dc8f3b4f2da46c7f
spawn to x86%windir%\syswow64\werfault.exe
spawn to x64%windir%\sysnative\werfault.exe

Observation history

18d agotoday

Observed on 18 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared JA4X issuance template · 289 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator.

Showing 24 of 289. The rest are reachable from any of them.

Shared Cobalt Strike watermark · 108 hosts

A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing one were built from the same copy of the software — which is not the same as one operator, since cracked and leaked builds circulate widely and share a watermark by definition.

Showing 24 of 108. The rest are reachable from any of them.

Samples served · 1 file

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups

lookups: virustotal · shodan · censys