public mosaic llc support@publicmosaic.com
confirmed host

IP address 134.122.153.121

Sliverreverse-sshvShellcontrollers · :8080, :443, :80

Last confirmed 2026-09-15, first seen 2026-09-02. On AS152194.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 3 ports — :8080, :443, :80, across 3 malware families.

134.122.153.121:8080 · Sliver

Last confirmed (today)

first seen2026-09-04 04:40 UTC
serviceip-port · tcp · alt-HTTP
networkAS152194 · CTG Server
confidence100 / 100
tls certificate253eb7154b2ebd6c89c962d87845d0b04b1f19cc93524f345e0bd3ae864cf459
cert subjectlocalhost
cert subject orgPlace
cert validity2026-08-27 → 2028-08-26
cert typeCA-signed
cert key4096-bit
cert serial (decimal)162958439362230562005805709773687851029
cert nameslocalhost

The certificate names above were validated by the issuing authority at issuance. They describe the certificate, not conduct by the names' owner — a legitimately issued certificate can be deployed on a listed host by whoever holds its private key, so treat the name as a pivot to investigate rather than as an attribution.

ja4x000000000000_7c32fa18c13e_bf0f0589fc03

134.122.153.121:443 · reverse-ssh

Last confirmed (today)

first seen2026-09-04 04:40 UTC
serviceip-port · tcp · HTTPS blend-in
networkAS152194 · CTG Server
confidence100 / 100
tls certificate16c0033299d245fcc6ad9472c00d6450c495b31b326bc32471fecb321b7fc8ed
cert subject134.122.153.121:443
cert subject orgCloudflare, Inc
cert issuer134.122.153.121:443
cert issuer orgCloudflare, Inc
cert validity2026-08-26 → 2026-09-25
cert typeself-signed
cert key2048-bit
cert serial (decimal)1787716389

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4xa373a9f83c6b_a373a9f83c6b_6361793a4d9e

134.122.153.121:80 · vShell

Last confirmed (today)

first seen2026-09-02 10:42 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS152194 · CTG Server
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host134.122.153.121 · same as this host
c2 port80
typews

Observation history

18d agotoday

Observed on 14 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared JA4X issuance template · 192 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator.

Showing 24 of 192. The rest are reachable from any of them.

Samples served · 1 file

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups