public mosaic llc support@publicmosaic.com
confirmed host

IP address 84.201.20.74

PureRATremote-access trojan controller · :443, :56002, :56001

Last confirmed 2026-09-10, first seen 2026-08-31. On AS214036.

listed last confirmed feed checked TLP:CLEAR SURICATA .RULES SEE THE LIVE FEED →

This address answered on 3 ports — :443, :56002, :56001.

84.201.20.74:443 · PureRAT

Last confirmed (5 days ago)

first seen2026-09-01 05:53 UTC
serviceip-port · tcp · HTTPS blend-in
observed hostapi.purecoder.io
networkAS214036 · Ultahost
confidence100 / 100
tls certificate44e8cd1d92caa289781f5b9b7a7dc6993f4fd8cfae729d193b6685f4c7227767
cert subjectapi.purecoder.io
cert subject orgPureCrack
cert issuerapi.purecoder.io
cert issuer orgPureCrack
cert validity2026-08-24 → 2036-08-22
cert typeself-signed
cert key2048-bit
cert serial (decimal)4457528140472048119
cert names*.purecoder.io api.purecoder.io api1.purecoder.io api2.purecoder.io

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x0b479b1b5763_0b479b1b5763_e9d2b55797df
payload sha-256f28d167da2ad333973e93fa494d7f4fe5c67d5628a061f02514862086e6c7000

The payload hash is the SHA-256 of the file this listener served when it was scanned. A host can change what it serves at any time, so this identifies a sample to look up or analyse rather than describing what it serves now. Only the response’s Content-Type claimed a download — no executable magic bytes were seen — so the bytes behind this hash are unverified.

84.201.20.74:56002 · PureRAT

Last confirmed (6 days ago)

first seen2026-08-31 09:16 UTC
serviceip-port · tcp
networkAS214036 · Ultahost
confidence100 / 100
tls certificateecb28dd1de46b0e824cd4144ee1e8e5c0f247ca8184f67b058f8e56e68b43010
cert subjectPureRAT Agent
cert issuerPureRAT Agent
cert validity2026-08-24 → 2036-08-22
cert typeself-signed
cert key2048-bit
cert serial (decimal)3407146920727906314

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x7022c563de38_7022c563de38_000000000000

84.201.20.74:56001 · PureRAT

Last confirmed (6 days ago)

first seen2026-08-31 09:16 UTC
serviceip-port · tcp
networkAS214036 · Ultahost
confidence100 / 100
tls certificateecb28dd1de46b0e824cd4144ee1e8e5c0f247ca8184f67b058f8e56e68b43010
cert subjectPureRAT Agent
cert issuerPureRAT Agent
cert validity2026-08-24 → 2036-08-22
cert typeself-signed
cert key2048-bit
cert serial (decimal)3407146920727906314

The certificate names above are what the certificate ASSERTS, not proof this host owns them — a self-signed certificate can claim any subject, so treat a familiar name here as an impersonation attempt rather than an identity.

ja4x7022c563de38_7022c563de38_000000000000

Observation history

18d agotoday

Observed on 11 of the 18 days since this archive began recording, 2026-08-29 UTC. Presence is per UTC day: a day is marked when the scanner confirmed this address at least once, not once per scan.

Shared JA4X issuance template · 67 hosts

These hosts issued certificates from the same template — the same distinguished-name fields hashed in the same order. It links tooling, not necessarily an operator.

Showing 24 of 67. The rest are reachable from any of them.

Pivots & lookups