public mosaic llc support@publicmosaic.com
confirmed host

IP address 209.200.246.194

Cobalt Strikecommand-and-control server · :45126, :37865, :36843, :34586, :17568, :16556, :32126, :24563

Last confirmed 2026-09-12, first seen 2026-08-28. On AS215311. Its certificate is shared with 100 other confirmed hosts.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 8 ports — :45126, :37865, :36843, :34586, :17568, :16556, :32126, :24563.

209.200.246.194:45126 · Cobalt Strike

Last confirmed (3 days ago)

first seen2026-09-06 05:10 UTC
serviceip-port · tcp
networkAS215311 · Regxa Company for Information Technol…
confidence100 / 100
cs watermark391144938

Beacon configuration

callbackacsdomaindsadas.click · operator-supplied; a redirector or impersonation target, not an attribution
beacon typeHTTP
cs versionCobalt Strike 4.7 (Aug 17, 2022)
getGET /static/js/app.js
postPOST /api/v2/collect
user-agentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
sleep5s ±30%
watermark391144938
server key md5cf4b83bceff826b92577f45f99229763
inject stubb50b86d735412685eb6044ad8d01781c
spawn to x86%windir%\syswow64\svchost.exe
spawn to x64%windir%\sysnative\svchost.exe

209.200.246.194:37865 · Cobalt Strike

Last confirmed (3 days ago)

first seen2026-09-06 05:10 UTC
serviceip-port · tcp
observed hostcloudflare.com
networkAS215311 · Regxa Company for Information Technol…
confidence100 / 100
tls certificatea787f037d1730147e13cc8835ebd0b8d749b59d1be5e86cade5e4a3e68b70eed
cert subject*.cloudflare.com
cert subject orgCloudFlare Inc.
cert issuer*.cloudflare.com
cert issuer orgCloudFlare Inc.
cert validity2026-09-09 → 2036-09-06
cert typeself-signed
cert key3072-bit
cert serial (decimal)5979502284893074343

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551
jarm2ad2ad16d2ad2ad00042d42d00042ddb04deffa1705e2edc44cae1ed24a4da
cs watermark391144938

Beacon configuration

callback209.200.246.194 · same as this host
beacon typeHTTPS
cs versionCobalt Strike 4.7 (Aug 17, 2022)
getGET /api/v2/query
postPOST /api/v2/collect
user-agentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
sleep5s ±30%
watermark391144938
server key md5cf4b83bceff826b92577f45f99229763
inject stubb50b86d735412685eb6044ad8d01781c
spawn to x86%windir%\syswow64\svchost.exe
spawn to x64%windir%\sysnative\svchost.exe

209.200.246.194:36843 · Cobalt Strike

Last confirmed (6 days ago)

first seen2026-09-06 05:10 UTC
serviceip-port · tcp
networkAS215311 · Regxa Company for Information Technol…
confidence100 / 100
tls certificate7b49fc589e7e738e3457859d269996ecef83f693570b0ac482c426b1fa04bd73
cert subjectMajor Cobalt Strike
cert subject orgcobaltstrike
cert issuerMajor Cobalt Strike
cert issuer orgcobaltstrike
cert validity2019-03-16 → 2019-06-14
cert typeself-signed
cert key2048-bit
cert serial (decimal)1220774527

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551

209.200.246.194:34586 · Cobalt Strike

Last confirmed (3 days ago)

first seen2026-09-06 05:10 UTC
serviceip-port · tcp
networkAS215311 · Regxa Company for Information Technol…
confidence100 / 100
cs watermark391144938

Beacon configuration

callback209.200.246.194 · same as this host
beacon typeHTTP
cs versionCobalt Strike 4.7 (Aug 17, 2022)
getGET /api/v2/query
postPOST /api/v2/collect
user-agentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
sleep5s ±30%
watermark391144938
server key md5cf4b83bceff826b92577f45f99229763
inject stubb50b86d735412685eb6044ad8d01781c
spawn to x86%windir%\syswow64\svchost.exe
spawn to x64%windir%\sysnative\svchost.exe

209.200.246.194:17568 · Cobalt Strike

Last confirmed (6 days ago)

first seen2026-09-06 05:10 UTC
serviceip-port · tcp
networkAS215311 · Regxa Company for Information Technol…
confidence100 / 100
tls certificate87f2085c32b6a2cc709b365f55873e207a9caa10bffecf2fd16d3cf9d94d390c
cert validity2015-05-20 → 2025-05-17
cert typeself-signed
cert key2048-bit
cert serial (decimal)146473198

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551
cs watermark305419896

Beacon configuration

callback209.200.246.194 · same as this host
beacon typeHTTPS
cs versionCobalt Strike 4.0 (Dec 05, 2019)
getGET /g.pixel
postPOST /submit.php
user-agentMozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0; MAM2)
sleep60s ±0%
watermark305419896
server key md579b6e333634c506f6f710dde179796ed
inject stuba56c813864af878a4c10083ca1578e0a
spawn to x86%windir%\syswow64\rundll32.exe
spawn to x64%windir%\sysnative\rundll32.exe

209.200.246.194:16556 · Cobalt Strike

Last confirmed (6 days ago)

first seen2026-09-06 05:10 UTC
serviceip-port · tcp
networkAS215311 · Regxa Company for Information Technol…
confidence100 / 100
cs watermark305419896

Beacon configuration

callbackacac.hopto.org · operator-supplied; a redirector or impersonation target, not an attribution
beacon typeHTTP
cs versionCobalt Strike 4.0 (Dec 05, 2019)
getGET /__utm.gif
postPOST /submit.php
user-agentMozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; QQDownload 733; .NET CLR 2.0.50727)
sleep60s ±0%
watermark305419896
server key md579b6e333634c506f6f710dde179796ed
inject stuba56c813864af878a4c10083ca1578e0a
spawn to x86%windir%\syswow64\rundll32.exe
spawn to x64%windir%\sysnative\rundll32.exe

209.200.246.194:32126 · Cobalt Strike

Last confirmed (6 days ago)

first seen2026-08-28 21:57 UTC
serviceip-port · tcp
networkAS215311 · Regxa Company for Information Technol…
confidence100 / 100
tls certificate87f2085c32b6a2cc709b365f55873e207a9caa10bffecf2fd16d3cf9d94d390c
cert validity2015-05-20 → 2025-05-17
cert typeself-signed
cert key2048-bit
cert serial (decimal)146473198

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551
cs watermark305419896

Beacon configuration

callbackacsdomaindsadas.click · operator-supplied; a redirector or impersonation target, not an attribution
beacon typeHTTPS
cs versionCobalt Strike 4.0 (Dec 05, 2019)
getGET /updates.rss
postPOST /submit.php
user-agentMozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
sleep60s ±0%
watermark305419896
server key md579b6e333634c506f6f710dde179796ed
inject stuba56c813864af878a4c10083ca1578e0a
spawn to x86%windir%\syswow64\rundll32.exe
spawn to x64%windir%\sysnative\rundll32.exe

209.200.246.194:24563 · Cobalt Strike

Last confirmed (6 days ago)

first seen2026-08-28 21:57 UTC
serviceip-port · tcp
networkAS215311 · Regxa Company for Information Technol…
confidence100 / 100
cs watermark305419896

Beacon configuration

callback209.200.246.194 · same as this host
beacon typeHTTP
cs versionCobalt Strike 4.0 (Dec 05, 2019)
getGET /load
postPOST /submit.php
user-agentMozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727)
sleep60s ±0%
watermark305419896
server key md579b6e333634c506f6f710dde179796ed
inject stuba56c813864af878a4c10083ca1578e0a
spawn to x86%windir%\syswow64\rundll32.exe
spawn to x64%windir%\sysnative\rundll32.exe

Observation history

18d agotoday

Observed on 15 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared TLS certificates · 100 hosts

This address served 3 distinct certificates. The hosts below share at least one of them — the set is a union, not a single cluster.

Showing 24 of 100. The rest are reachable from any of them.

Shared JA4X issuance template · 270 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →

Showing 24 of 270. Full cohort →

Shared Cobalt Strike watermark · 31 hosts

A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing one were built from the same copy of the software — which is not the same as one operator, since cracked and leaked builds circulate widely and share a watermark by definition.

Showing 24 of 31. The rest are reachable from any of them.

Pivots & lookups