public mosaic llc support@publicmosaic.com
confirmed host

IP address 165.154.6.188

SlivervShellcontrollers · :31337, :1389

Last confirmed 2026-09-15, first seen 2026-09-02. On AS135377.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 2 ports — :31337, :1389, across 2 malware families.

165.154.6.188:31337 · Sliver

Last confirmed (today)

first seen2026-09-05 21:28 UTC
serviceip-port · tcp · Sliver default
networkAS135377 · UCLOUD INFORMATION TECHNOLOGY (HK)
confidence100 / 100
tls certificatefe2e7943d833783a0746fd657b8f49400c06e3c5bae8c8c0699931232db8b0cb
cert subjectmultiplayer
cert issueroperators
cert validity2025-10-28 → 2028-10-27
cert typeCA-signed
cert key256-bit
cert serial (decimal)173373364756192294174076890011830997722
cert namesmultiplayer

The certificate names above were validated by the issuing authority at issuance. They describe the certificate, not conduct by the names' owner — a legitimately issued certificate can be deployed on a listed host by whoever holds its private key, so treat the name as a pivot to investigate rather than as an attribution.

ja4x7022c563de38_7022c563de38_bf0f0589fc03

165.154.6.188:1389 · vShell

Last confirmed (today)

first seen2026-09-02 10:32 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS135377 · UCLOUD INFORMATION TECHNOLOGY (HK)
confidence98 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host165.154.6.188 · same as this host
c2 port1389
typetcp

Observation history

18d agotoday

Observed on 14 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared JA4X issuance template · 504 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →

Showing 24 of 504. Full cohort →

Samples served · 1 file

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups