public mosaic llc support@publicmosaic.com
confirmed host

IP address 101.201.103.158

Cobalt Strikecommand-and-control server · :50050, :8066

Last confirmed 2026-09-15, first seen 2026-09-07. On AS37963. Its certificate is shared with 99 other confirmed hosts.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 2 ports — :50050, :8066.

101.201.103.158:50050 · Cobalt Strike

Last confirmed (today)

first seen2026-09-08 13:48 UTC
serviceip-port · tcp · Cobalt Strike team server default
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100
tls certificate98b44f7822edba8b4e4d3f6ec822ce46a32013fdf4648793972125e2926c4da2
cert subjectMajor Cobalt Strike
cert subject orgcobaltstrike
cert issuerMajor Cobalt Strike
cert issuer orgcobaltstrike
cert validity2026-09-05 → 2026-12-04
cert typeself-signed
cert key2048-bit
cert serial (decimal)17802853589447667117

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551

101.201.103.158:8066 · Cobalt Strike

Last confirmed (today)

first seen2026-09-07 01:23 UTC
serviceip-port · tcp
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100
tls certificate87f2085c32b6a2cc709b365f55873e207a9caa10bffecf2fd16d3cf9d94d390c
cert validity2015-05-20 → 2025-05-17
cert typeself-signed
cert key2048-bit
cert serial (decimal)146473198

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551
cs watermark987654321

Beacon configuration

callback101.201.103.158 · same as this host
beacon typeHTTPS
cs versionCobalt Strike 4.7 (Aug 17, 2022)
getGET /updates.rss
postPOST /submit.php
user-agentMozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0)
sleep60s ±0%
watermark987654321
server key md52325fe9416cc5c282a7ae0f426789bce
inject stubcc4ba01c076d925ce1fc333d59ba83db
spawn to x86%windir%\syswow64\rundll32.exe
spawn to x64%windir%\sysnative\rundll32.exe

Observation history

18d agotoday

Observed on 9 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared TLS certificates · 99 hosts

This address served 2 distinct certificates. The hosts below share at least one of them — the set is a union, not a single cluster.

Showing 24 of 99. The rest are reachable from any of them.

Shared JA4X issuance template · 270 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →

Showing 24 of 270. Full cohort →

Shared Cobalt Strike watermark · 108 hosts

A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing one were built from the same copy of the software — which is not the same as one operator, since cracked and leaked builds circulate widely and share a watermark by definition.

Showing 24 of 108. The rest are reachable from any of them.

Pivots & lookups