logo

Fingerprinting C2s with Shodan

ID: efc281db-a5ef-5b8a-b7d8-60f1e20331ef

STIX ID: report--efc281db-a5ef-5b8a-b7d8-60f1e20331ef

Feed Name: KMsec blog

Threat Score
70/100

Date Published: 2023-01-06

Date Updated: 2026-04-19

...
...

A hands-on Shodan-driven analysis starting from a PupyRAT C2 IP (103.79.76.40) used certificate metadata (OU=CONTROL and random 10‑character O fields) and TLS handshake errors to enumerate a cluster of ~40 likely malicious hosts; the report lists the discovered IP indicators and notes the cluster may be linked to a China-associated actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.