cert serial (decimal)703235022014801625296792456233046473579389120079
cert names*.mcprotocol.cnmcprotocol.cn
The certificate names above were validated by the issuing authority at issuance. They describe the certificate, not conduct by the names' owner — a legitimately issued certificate can be deployed on a listed host by whoever holds its private key, so treat the name as a pivot to investigate rather than as an attribution.
cert serial (decimal)703235022014801625296792456233046473579389120079
cert names*.mcprotocol.cnmcprotocol.cn
The certificate names above were validated by the issuing authority at issuance. They describe the certificate, not conduct by the names' owner — a legitimately issued certificate can be deployed on a listed host by whoever holds its private key, so treat the name as a pivot to investigate rather than as an attribution.
user-agentMozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko
sleep5s ±37%
watermark987654321
server key md52a64d6fedbedc56c73d4029755312b14
inject stub3168a134f2bc8f773f6274cb54f59efd
spawn to x86%windir%\syswow64\dllhost.exe
spawn to x64%windir%\sysnative\dllhost.exe
Observation history
18d agotoday
Observed on 18 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.
Shared JA4X issuance template · 19 hosts
These hosts issued certificates from the same template — the same distinguished-name
fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →
A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing
one were built from the same copy of the software — which is not the same as one operator,
since cracked and leaked builds circulate widely and share a watermark by definition.
This page is generated from automated scanning and is publicly available. If you
are responsible for this address and it should not be listed, write to
support@publicmosaic.com —
see abuse & takedown for what we need and what happens next, or
opt-out to exclude a whole range from scanning.
Addresses are frequently compromised third-party hosts rather than
infrastructure their owner stood up. A listing records what a scan observed at a point in
time; it is not an allegation about whoever pays for the address.