public mosaic llc support@publicmosaic.com
confirmed host

IP address 185.244.212.122

vShellcommand-and-control server · :8591, :8443, :8080, :443, :80

Last confirmed 2026-09-15, first seen 2026-09-02. On AS9009.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 5 ports — :8591, :8443, :8080, :443, :80.

185.244.212.122:8591 · vShell

Last confirmed (2 days ago)

first seen2026-09-08 02:25 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS9009 · M247 Europe
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host185.244.212.122 · same as this host

185.244.212.122:8443 · vShell

Last confirmed (3 days ago)

first seen2026-09-02 10:32 UTC
serviceip-port · tcp · alt-HTTPS
rolemalware distribution host — observed serving samples
networkAS9009 · M247 Europe
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host185.244.212.122 · same as this host

185.244.212.122:8080 · vShell

Last confirmed (today)

first seen2026-09-02 10:32 UTC
serviceip-port · tcp · alt-HTTP
rolemalware distribution host — observed serving samples
networkAS9009 · M247 Europe
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host185.244.212.122 · same as this host

185.244.212.122:443 · vShell

Last confirmed (3 days ago)

first seen2026-09-02 10:32 UTC
serviceip-port · tcp · HTTPS blend-in
rolemalware distribution host — observed serving samples
networkAS9009 · M247 Europe
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host185.244.212.122 · same as this host

185.244.212.122:80 · vShell

Last confirmed (today)

first seen2026-09-02 10:32 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS9009 · M247 Europe
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host185.244.212.122 · same as this host

Observation history

18d agotoday

Observed on 14 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Samples served · 8 files

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups