public mosaic llc support@publicmosaic.com
confirmed host

IP address 49.235.130.208

vShellVipercontrollers · :8524, :8523, :60000

Last confirmed 2026-09-15, first seen 2026-08-28. On AS45090. Its certificate is shared with 39 other confirmed hosts.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 3 ports — :8524, :8523, :60000, across 2 malware families.

49.235.130.208:8524 · vShell

Last confirmed (5 days ago)

first seen2026-09-08 14:13 UTC
serviceip-port · tcp
networkAS45090 · Shenzhen Tencent Computer Systems Com…
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host49.235.130.208 · same as this host

49.235.130.208:8523 · vShell

Last confirmed (5 days ago)

first seen2026-09-08 14:13 UTC
serviceip-port · tcp
networkAS45090 · Shenzhen Tencent Computer Systems Com…
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host49.235.130.208 · same as this host

49.235.130.208:60000 · Viper

Last confirmed (today)

first seen2026-08-28 21:52 UTC
serviceip-port · tcp
networkAS45090 · Shenzhen Tencent Computer Systems Com…
confidence100 / 100
tls certificate4de3278507c89d2242a12c20b74878e3f84970c463a924771f156a3da7d7b5a1
cert subjectd1d38ec9
cert subject orgd1d38ec9
cert issuer0d72da0c
cert issuer org0d72da0c
cert validity2021-03-29 → 2031-03-27
cert typeCA-signed
cert key4096-bit
cert serial (decimal)126845285010036579050228249670234730282378094178

The certificate names above were validated by the issuing authority at issuance. They describe the certificate, not conduct by the names' owner — a legitimately issued certificate can be deployed on a listed host by whoever holds its private key, so treat the name as a pivot to investigate rather than as an attribution.

ja4x2166164053c1_2166164053c1_000000000000
jarm21d19d00021d21d00042d43d0000005ad20eceaf7f71ae0887d2ff117bf97f

Observation history

18d agotoday

Observed on 18 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared TLS certificate · 39 hosts

These hosts served the same certificate. That is the strongest link this corpus can draw between two addresses, though it evidences a shared BUILD rather than a shared operator: a leaked or resold profile puts the same certificate in different hands. Full cohort →

Showing 24 of 39. Full cohort →

Shared JA4X issuance template · 44 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →

Showing 24 of 44. Full cohort →

Samples served · 6 files

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups