public mosaic llc support@publicmosaic.com
confirmed host

IP address 39.97.57.155

Cobalt Strikecommand-and-control server · :50050, :1223, :1222

Last confirmed 2026-09-15, first seen 2026-09-02. On AS37963. Its certificate is shared with 31 other confirmed hosts.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 3 ports — :50050, :1223, :1222.

39.97.57.155:50050 · Cobalt Strike

Last confirmed (today)

first seen2026-09-06 10:46 UTC
serviceip-port · tcp · Cobalt Strike team server default
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100
tls certificate56a06a233bd30f693de25ef12cc19e8b2c92d3eb97dd969a2578df084c376478
cert subjectMajor Cobalt Strike
cert subject orgcobaltstrike
cert issuerMajor Cobalt Strike
cert issuer orgcobaltstrike
cert validity2022-08-30 → 2022-11-28
cert typeself-signed
cert key2048-bit
cert serial (decimal)659754494

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551

39.97.57.155:1223 · Cobalt Strike

Last confirmed (today)

first seen2026-09-02 10:48 UTC
serviceip-port · tcp
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100
tls certificate56a06a233bd30f693de25ef12cc19e8b2c92d3eb97dd969a2578df084c376478
cert subjectMajor Cobalt Strike
cert subject orgcobaltstrike
cert issuerMajor Cobalt Strike
cert issuer orgcobaltstrike
cert validity2022-08-30 → 2022-11-28
cert typeself-signed
cert key2048-bit
cert serial (decimal)659754494

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551
cs watermark391144938

Beacon configuration

callbackc-proxy-xjmkjgbsdn.cn-hangzhou.fcapp.run · operator-supplied; a redirector or impersonation target, not an attribution
beacon typeHTTPS
cs versionCobalt Strike 4.7 (Aug 17, 2022)
getGET /jquery-3.3.1.min.js
postPOST /jquery-3.3.2.min.js
user-agentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 Edg/139.0.0.0
sleep20s ±37%
watermark391144938
server key md5062a875bfbe9bdb8a75f02ee99b4efcc
inject stubb50b86d735412685eb6044ad8d01781c
spawn to x86%windir%\syswow64\rundll32.exe
spawn to x64%windir%\sysnative\rundll32.exe

39.97.57.155:1222 · Cobalt Strike

Last confirmed (today)

first seen2026-09-02 10:48 UTC
serviceip-port · tcp
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100
tls certificate56a06a233bd30f693de25ef12cc19e8b2c92d3eb97dd969a2578df084c376478
cert subjectMajor Cobalt Strike
cert subject orgcobaltstrike
cert issuerMajor Cobalt Strike
cert issuer orgcobaltstrike
cert validity2022-08-30 → 2022-11-28
cert typeself-signed
cert key2048-bit
cert serial (decimal)659754494

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551
cs watermark391144938

Beacon configuration

callback1328750890-eja72jp2s9.ap-guangzhou.tencentscf.com · operator-supplied; a redirector or impersonation target, not an attribution
beacon typeHTTPS
cs versionCobalt Strike 4.7 (Aug 17, 2022)
getGET /jquery-3.3.1.min.js
postPOST /jquery-3.3.2.min.js
user-agentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 Edg/139.0.0.0
sleep20s ±37%
watermark391144938
server key md5062a875bfbe9bdb8a75f02ee99b4efcc
inject stubb50b86d735412685eb6044ad8d01781c
spawn to x86%windir%\syswow64\rundll32.exe
spawn to x64%windir%\sysnative\rundll32.exe

Observation history

18d agotoday

Observed on 14 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared TLS certificate · 31 hosts

These hosts served the same certificate. That is the strongest link this corpus can draw between two addresses, though it evidences a shared BUILD rather than a shared operator: a leaked or resold profile puts the same certificate in different hands. Full cohort →

Showing 24 of 31. Full cohort →

Shared JA4X issuance template · 270 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →

Showing 24 of 270. Full cohort →

Shared Cobalt Strike watermark · 28 hosts

A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing one were built from the same copy of the software — which is not the same as one operator, since cracked and leaked builds circulate widely and share a watermark by definition.

Showing 24 of 28. The rest are reachable from any of them.

Pivots & lookups