public mosaic llc support@publicmosaic.com
confirmed host

IP address 23.95.242.55

reverse-sshvShellcontrollers · :80, :8443, :1080, :443

Last confirmed 2026-09-15, first seen 2026-09-02. On AS36352.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 4 ports — :80, :8443, :1080, :443, across 2 malware families.

23.95.242.55:80 · reverse-ssh

Last confirmed (today)

first seen2026-09-05 08:32 UTC
serviceip-port · tcp
networkAS36352 · HostPapa
confidence100 / 100
tls certificatec1ab3f27443ccfcbc6eb228f0d292a5b4761f42879cc50b68b7a0215833dc87f
cert subject23.95.242.55:80
cert subject orgCloudflare, Inc
cert issuer23.95.242.55:80
cert issuer orgCloudflare, Inc
cert validity2026-08-20 → 2026-09-19
cert typeself-signed
cert key2048-bit
cert serial (decimal)1787203035

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4xa373a9f83c6b_a373a9f83c6b_6361793a4d9e

23.95.242.55:8443 · vShell

Last confirmed (today)

first seen2026-09-02 10:20 UTC
serviceip-port · tcp · alt-HTTPS
rolemalware distribution host — observed serving samples
networkAS36352 · HostPapa
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host23.95.242.55 · same as this host
c2 port8443
typetcp

23.95.242.55:1080 · vShell

Last confirmed (today)

first seen2026-09-02 10:19 UTC
serviceip-port · tcp
rolemalware distribution host — observed serving samples
networkAS36352 · HostPapa
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host23.95.242.55 · same as this host
c2 port1080
typews

23.95.242.55:443 · vShell

Last confirmed (today)

first seen2026-09-02 10:19 UTC
serviceip-port · tcp · HTTPS blend-in
rolemalware distribution host — observed serving samples
networkAS36352 · HostPapa
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host23.95.242.55 · same as this host
c2 port443
typews

Observation history

18d agotoday

Observed on 14 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared JA4X issuance template · 92 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →

Showing 24 of 92. Full cohort →

Samples served · 3 files

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups