public mosaic llc support@publicmosaic.com
confirmed host

IP address 111.229.4.108

QuasarCobalt Strikecontrollers · :8955, :2096

Last confirmed 2026-09-15, first seen 2026-08-28. On AS45090.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 2 ports — :8955, :2096, across 2 malware families.

111.229.4.108:8955 · Quasar

Last confirmed (5 days ago)

first seen2026-09-10 12:34 UTC
serviceip-port · tcp
observed hostcwlabtes.shop
networkAS45090 · Shenzhen Tencent Computer Systems Com…
confidence98 / 100

111.229.4.108:2096 · Cobalt Strike

Last confirmed (today)

first seen2026-08-28 22:15 UTC
serviceip-port · tcp
observed hostdyshop.online
networkAS45090 · Shenzhen Tencent Computer Systems Com…
confidence100 / 100
tls certificate89db360aff192a136b98a247e5f071a68709f43f0d472d6be6c2982faae49384
cert subjectCloudFlare Origin Certificate
cert subject orgCloudFlare, Inc.
cert issuer orgCloudFlare, Inc.
cert validity2025-06-17 → 2040-06-13
cert typeCA-signed
cert key2048-bit
cert serial (decimal)672404333158293440403851240460174422638450849308
cert names*.dyshop.online dyshop.online

The certificate names above were validated by the issuing authority at issuance. They describe the certificate, not conduct by the names' owner — a legitimately issued certificate can be deployed on a listed host by whoever holds its private key, so treat the name as a pivot to investigate rather than as an attribution.

ja4xdc020972a4a8_9fb583da09a2_fb02ba79e164
jarm2ad2ad16d2ad2ad00042d42d00042d47e4e0ae17960b2a5b4fd6107fbb0926
cs watermark100000

Beacon configuration

callbackwww.dyshop.online · operator-supplied; a redirector or impersonation target, not an attribution
beacon typeHTTPS
cs versionCobalt Strike 4.5 (Dec 14, 2021)
getGET /login.js
postPOST /cwlabtes.js
user-agentMozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko
sleep20s ±37%
watermark100000
server key md5eefe6af1760f939c5ffc58304e10c0de
inject stub04e0a11be59147a8d73d2b3e9fea832c
spawn to x86%windir%\syswow64\dllhost.exe
spawn to x64%windir%\sysnative\dllhost.exe

Observation history

18d agotoday

Observed on 18 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared JA4X issuance template · 19 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →

Shared Cobalt Strike watermark · 8 hosts

A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing one were built from the same copy of the software — which is not the same as one operator, since cracked and leaked builds circulate widely and share a watermark by definition.

Pivots & lookups