The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.
The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.
callbackwww.qkshhdjrbd.work · operator-supplied; a redirector or impersonation target, not an attribution
beacon typeHTTPS
cs versionCobalt Strike 4.9 (Sep 19, 2023)
getGET /jquery-3.3.1.min.js
postPOST /jquery-3.3.2.min.js
user-agentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 OPR/111.0.0.0 (Edition Yx 03)
sleep5s ±25%
watermark666666666
server key md5ca1c5ee4c6f4451759972387cacad5ac
inject stub40ed048138df0b3e23a0ef24dc5efa1a
spawn to x86%windir%\syswow64\runonce.exe
spawn to x64%windir%\sysnative\runonce.exe
Observation history
18d agotoday
Observed on 14 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.
Shared JA4X issuance template · 270 hosts
These hosts issued certificates from the same template — the same distinguished-name
fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →
A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing
one were built from the same copy of the software — which is not the same as one operator,
since cracked and leaked builds circulate widely and share a watermark by definition.
This page is generated from automated scanning and is publicly available. If you
are responsible for this address and it should not be listed, write to
support@publicmosaic.com —
see abuse & takedown for what we need and what happens next, or
opt-out to exclude a whole range from scanning.
Addresses are frequently compromised third-party hosts rather than
infrastructure their owner stood up. A listing records what a scan observed at a point in
time; it is not an allegation about whoever pays for the address.