public mosaic llc support@publicmosaic.com
confirmed host

IP address 8.163.59.20

vShellCobalt Strikecontrollers · :9999, :8008

Last confirmed 2026-09-15, first seen 2026-09-10. On AS37963. Its certificate is shared with 99 other confirmed hosts.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 2 ports — :9999, :8008, across 2 malware families.

8.163.59.20:9999 · vShell

Last confirmed (today)

first seen2026-09-12 06:03 UTC
serviceip-port · tcp
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100

vShell configuration

Operator-supplied settings recovered by detonating a captured sample in a sandbox — the configured command-and-control host, mutex and campaign, not a live reading of this address.

c2 host8.163.59.20 · same as this host

8.163.59.20:8008 · Cobalt Strike

Last confirmed (today)

first seen2026-09-10 12:33 UTC
serviceip-port · tcp
networkAS37963 · Hangzhou Alibaba Advertising
confidence100 / 100
tls certificate87f2085c32b6a2cc709b365f55873e207a9caa10bffecf2fd16d3cf9d94d390c
cert validity2015-05-20 → 2025-05-17
cert typeself-signed
cert key2048-bit
cert serial (decimal)146473198

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x2166164053c1_2166164053c1_30d204a01551
cs watermark666666666

Beacon configuration

callback8.163.59.20 · same as this host
beacon typeHTTPS
cs versionCobalt Strike 4.9 (Sep 19, 2023)
getGET /jquery-3.3.1.min.js
postPOST /jquery-3.3.2.min.js
user-agentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 OPR/111.0.0.0 (Edition Yx 03)
sleep5s ±25%
watermark666666666
server key md5ca1c5ee4c6f4451759972387cacad5ac
inject stub40ed048138df0b3e23a0ef24dc5efa1a
spawn to x86%windir%\syswow64\runonce.exe
spawn to x64%windir%\sysnative\runonce.exe

Observation history

18d agotoday

Observed on 6 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared TLS certificate · 99 hosts

These hosts served the same certificate. That is the strongest link this corpus can draw between two addresses, though it evidences a shared BUILD rather than a shared operator: a leaked or resold profile puts the same certificate in different hands. Full cohort →

Showing 24 of 99. Full cohort →

Shared JA4X issuance template · 270 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator. Full cohort →

Showing 24 of 270. Full cohort →

Shared Cobalt Strike watermark · 56 hosts

A watermark identifies the Cobalt Strike licence a beacon was generated from. Hosts sharing one were built from the same copy of the software — which is not the same as one operator, since cracked and leaked builds circulate widely and share a watermark by definition.

Showing 24 of 56. The rest are reachable from any of them.

Samples served · 3 files

Files this address was observed DELIVERING, confirmed as malware by detonation or by analysis of the file itself. Delivery is an observation, not an attribution — a widely distributed sample can reach unrelated hosts.

Pivots & lookups