public mosaic llc support@publicmosaic.com
confirmed host

IP address 124.222.57.34

vShellCobalt Strikecontrollers · :9998, :8081, :9999

Last confirmed 2026-09-15, first seen 2026-08-31. On AS45090. Its certificate is shared with 31 other confirmed hosts.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 3 ports — :9998, :8081, :9999, across 2 malware families.

124.222.57.34:9998 · vShell

Last confirmed (today)

first seen2026-09-06 05:44 UTC
serviceip-port · tcp
networkAS45090 · Shenzhen Tencent Computer Systems Com…
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host124.222.57.34 · same as this host

124.222.57.34:8081 · Cobalt Strike

Last confirmed (11 days ago)

first seen2026-09-02 10:41 UTC
serviceip-port · tcp
networkAS45090 · Shenzhen Tencent Computer Systems Com…
confidence100 / 100
tls certificate56a06a233bd30f693de25ef12cc19e8b2c92d3eb97dd969a2578df084c376478
cert subjectMajor Cobalt Strike
cert subject orgcobaltstrike
cert issuerMajor Cobalt Strike
cert issuer orgcobaltstrike
cert validity2022-08-30 → 2022-11-28
cert typeself-signed
cert key2048-bit
cert serial (decimal)659754494

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551

124.222.57.34:9999 · vShell

Last confirmed (today)

first seen2026-08-31 09:01 UTC
serviceip-port · tcp
networkAS45090 · Shenzhen Tencent Computer Systems Com…
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host124.222.57.34 · same as this host

Observation history

18d agotoday

Observed on 16 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared TLS certificate · 31 hosts

These hosts served the same certificate. That is the strongest link this corpus can draw between two addresses, though it evidences a shared BUILD rather than a shared operator: a leaked or resold profile puts the same certificate in different hands. Full cohort →

Showing 24 of 31. Full cohort →

Shared JA4X issuance template · 270 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →

Showing 24 of 270. Full cohort →

Samples served · 3 files

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups