public mosaic llc support@publicmosaic.com
confirmed host

IP address 8.134.70.73

vShellCobalt Strikecontrollers · :8113, :8112, :8111, :6111, :7777, :50050

Last confirmed 2026-09-09, first seen 2026-08-23. On AS37963.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 6 ports — :8113, :8112, :8111, :6111, :7777, :50050, across 2 malware families.

8.134.70.73:8113 · vShell

Last confirmed (5 days ago)

first seen2026-09-02 10:18 UTC
serviceip-port · tcp
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100

8.134.70.73:8112 · vShell

Last confirmed (5 days ago)

first seen2026-09-02 10:18 UTC
serviceip-port · tcp
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100

8.134.70.73:8111 · vShell

Last confirmed (5 days ago)

first seen2026-09-02 10:18 UTC
serviceip-port · tcp
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100

8.134.70.73:6111 · Cobalt Strike

Last confirmed (5 days ago)

first seen2026-09-02 10:18 UTC
serviceip-port · tcp
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100
cs watermark987654321

Beacon configuration

callback8.134.70.73 · same as this host
beacon typeHTTP
cs versionCobalt Strike 4.8 (Feb 28, 2023)
getGET /ga.js
postPOST /submit.php
user-agentMozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
sleep60s ±0%
watermark987654321
server key md5b6dfb641199746982fc41e4341a56e23
inject stube43a1b63f09794f74d90a9889f7acb77
spawn to x86%windir%\syswow64\rundll32.exe
spawn to x64%windir%\sysnative\rundll32.exe

8.134.70.73:7777 · Cobalt Strike

Last confirmed (5 days ago)

first seen2026-08-29 00:41 UTC
serviceip-port · tcp
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100
cs watermark987654321

Beacon configuration

callback8.134.70.73 · same as this host
beacon typeHTTP
cs versionCobalt Strike 4.8 (Feb 28, 2023)
getGET /j.ad
postPOST /submit.php
user-agentMozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; Win64; x64; Trident/6.0; MDDCJS)
sleep60s ±0%
watermark987654321
server key md5b6dfb641199746982fc41e4341a56e23
inject stube43a1b63f09794f74d90a9889f7acb77
spawn to x86%windir%\syswow64\rundll32.exe
spawn to x64%windir%\sysnative\rundll32.exe

8.134.70.73:50050 · Cobalt Strike

Last confirmed (5 days ago)

first seen2026-08-23 03:23 UTC
serviceip-port · tcp · Cobalt Strike team server default
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100
tls certificate0f25a03dd7dfdd4b18c96fd00409a700a5aff274a23c46d69af9eb9057f58733
cert subjectMajor Cobalt Strike
cert subject orgcobaltstrike
cert issuerMajor Cobalt Strike
cert issuer orgcobaltstrike
cert validity2025-05-05 → 2025-08-03
cert typeself-signed
cert key2048-bit
cert serial (decimal)2709667993031680926

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551

Observation history

18d agotoday

Observed on 12 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared JA4X issuance template · 270 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →

Showing 24 of 270. Full cohort →

Shared Cobalt Strike watermark · 108 hosts

A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing one were built from the same copy of the software — which is not the same as one operator, since cracked and leaked builds circulate widely and share a watermark by definition.

Showing 24 of 108. The rest are reachable from any of them.

Pivots & lookups