public mosaic llc support@publicmosaic.com
confirmed host

IP address 103.136.150.98

vShellcommand-and-control server · :60337, :60336, :60335, :60334

Last confirmed 2026-09-15, first seen 2026-09-02. On AS26383.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 4 ports — :60337, :60336, :60335, :60334.

103.136.150.98:60337 · vShell

Last confirmed (today)

first seen2026-09-02 10:34 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS26383 · Baxet Group
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host103.136.150.98 · same as this host
c2 port60337
typetcp

103.136.150.98:60336 · vShell

Last confirmed (today)

first seen2026-09-02 10:34 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS26383 · Baxet Group
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host103.136.150.98 · same as this host
c2 port60336
typetcp

103.136.150.98:60335 · vShell

Last confirmed (today)

first seen2026-09-02 10:34 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS26383 · Baxet Group
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host103.136.150.98 · same as this host
c2 port60335
typetcp

103.136.150.98:60334 · vShell

Last confirmed (today)

first seen2026-09-02 10:34 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS26383 · Baxet Group
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host103.136.150.98 · same as this host
c2 port60334
typetcp

Observation history

18d agotoday

Observed on 14 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Samples served · 4 files

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups