public mosaic llc support@publicmosaic.com
confirmed host

IP address 102.204.223.106

vShellcommand-and-control server · :47351, :8084, :4444

Last confirmed 2026-09-14, first seen 2026-08-28. On AS139923.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 3 ports — :47351, :8084, :4444.

102.204.223.106:47351 · vShell

Last confirmed (yesterday)

first seen2026-09-02 10:34 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS139923 · ABCCLOUD SDN.BHD
confidence98 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host102.204.223.106 · same as this host
c2 port47351
typews

102.204.223.106:8084 · vShell

Last confirmed (yesterday)

first seen2026-09-02 10:34 UTC
serviceip-port · tcp
networkAS139923 · ABCCLOUD SDN.BHD
confidence98 / 100

102.204.223.106:4444 · vShell

Last confirmed (yesterday)

first seen2026-08-28 22:26 UTC
serviceip-port · tcp · Metasploit default
networkAS139923 · ABCCLOUD SDN.BHD
confidence98 / 100

Observation history

18d agotoday

Observed on 15 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Samples served · 1 file

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups

lookups: virustotal · shodan · censys