public mosaic llc support@publicmosaic.com
confirmed host

IP address 103.45.66.107

VenomRATremote-access trojan controller · :7878

Last confirmed 2026-09-05, first seen 2026-09-01. On AS152194.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

The upstream re-labelled one or more episodes below in place; only the most recent earlier label is kept, and the archive does not record when the change happened.

103.45.66.107:7878 · VenomRAT

Last confirmed (10 days ago)

first seen2026-09-01 18:32 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
earlier labelDcRat or VenomRAT
networkAS152194 · CTG Server
confidence100 / 100
jarm2ad2ad16d2ad2ad22c2ad2ad2ad2adfd9c9d14e4f4f67f94f0359f8b28f532

VenomRAT configuration

These settings were recovered from a sample this address was observed serving, not from this listener itself. They describe that sample, not necessarily this address's own configuration.

c2 port7878
mutex2512d01a58a84e27
version1.0
groupDefault

Observation history

18d agotoday

Observed on 4 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Samples served · 1 file

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups