IP address 47.90.209.157
Last confirmed 2026-09-15, first seen 2026-09-08. On AS45102. Its certificate is shared with 31 other confirmed hosts.
This address answered on 2 ports — :18084, :54321, across 2 malware families.
47.90.209.157:18084 · vShell
Last confirmed (today)
vShell configuration
Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.
47.90.209.157:54321 · Cobalt Strike
Last confirmed (2 days ago)
The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.
Observation history
Observed on 8 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.
Shared TLS certificate · 31 hosts
These hosts served the same certificate. That is the strongest link this corpus can draw between two addresses, though it evidences a shared BUILD rather than a shared operator: a leaked or resold profile puts the same certificate in different hands. Full cohort →
Showing 24 of 31. Full cohort →
Shared JA4X issuance template · 270 hosts
These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →
Showing 24 of 270. Full cohort →
Samples served · 4 files
Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.
Pivots & lookups
Listed in error?
This page is generated from automated scanning and is publicly available. If you are responsible for this address and it should not be listed, write to support@publicmosaic.com — see abuse & takedown for what we need and what happens next, or opt-out to exclude a whole range from scanning.
Addresses are frequently compromised third-party hosts rather than infrastructure their owner stood up. A listing records what a scan observed at a point in time; it is not an allegation about whoever pays for the address.