public mosaic llc support@publicmosaic.com
confirmed host

IP address 8.152.201.69

Cobalt StrikevShellcontrollers · :50001, :8084

Last confirmed 2026-09-05, first seen 2026-09-02. On AS37963.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 2 ports — :50001, :8084, across 2 malware families.

8.152.201.69:50001 · Cobalt Strike

Last confirmed (10 days ago)

first seen2026-09-02 10:19 UTC
serviceip-port · tcp
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100
cs watermark987654321

Beacon configuration

callback8.152.201.69 · same as this host
beacon typeHTTP
cs versionCobalt Strike 4.9 (Sep 19, 2023)
getGET /pixel.gif
postPOST /submit.php
user-agentMozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; 360space)
sleep60s ±0%
watermark987654321
server key md5fc7f0360c0a94e9f19faf5a78650690a
inject stubae5afcfee8026674dc8f3b4f2da46c7f
spawn to x86%windir%\syswow64\rundll32.exe
spawn to x64%windir%\sysnative\rundll32.exe

8.152.201.69:8084 · vShell

Last confirmed (10 days ago)

first seen2026-09-02 10:19 UTC
serviceip-port · tcp
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100

Observation history

18d agotoday

Observed on 4 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared Cobalt Strike watermark · 108 hosts

A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing one were built from the same copy of the software — which is not the same as one operator, since cracked and leaked builds circulate widely and share a watermark by definition.

Showing 24 of 108. The rest are reachable from any of them.

Pivots & lookups