public mosaic llc support@publicmosaic.com
confirmed host

IP address 117.72.125.206

Cobalt StrikevShellcontrollers · :11111, :8888

Last confirmed 2026-09-15, first seen 2026-09-05. On AS141679.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 2 ports — :11111, :8888, across 2 malware families.

117.72.125.206:11111 · Cobalt Strike

Last confirmed (today)

first seen2026-09-06 05:43 UTC
serviceip-port · tcp
networkAS141679 · China Telecom Beijing Tianjin Hebei B…
confidence100 / 100
cs watermark666666666

Beacon configuration

callback117.72.125.206 · same as this host
beacon typeHTTP
cs versionCobalt Strike 4.9 (Sep 19, 2023)
getGET /ca
postPOST /submit.php
user-agentMozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0; MASP)
sleep60s ±0%
watermark666666666
server key md5ca1c5ee4c6f4451759972387cacad5ac
inject stub40ed048138df0b3e23a0ef24dc5efa1a
spawn to x86%windir%\syswow64\rundll32.exe
spawn to x64%windir%\sysnative\rundll32.exe

117.72.125.206:8888 · vShell

Last confirmed (today)

first seen2026-09-05 11:02 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS141679 · China Telecom Beijing Tianjin Hebei B…
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host117.72.125.206 · same as this host

Observation history

18d agotoday

Observed on 11 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared Cobalt Strike watermark · 56 hosts

A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing one were built from the same copy of the software — which is not the same as one operator, since cracked and leaked builds circulate widely and share a watermark by definition.

Showing 24 of 56. The rest are reachable from any of them.

Samples served · 3 files

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups