Fingerprinting C2s with Shodan
ID: efc281db-a5ef-5b8a-b7d8-60f1e20331ef
STIX ID: report--efc281db-a5ef-5b8a-b7d8-60f1e20331ef
Feed Name: KMsec blog
Threat Score
A hands-on Shodan-driven analysis starting from a PupyRAT C2 IP (103.79.76.40) used certificate metadata (OU=CONTROL and random 10‑character O fields) and TLS handshake errors to enumerate a cluster of ~40 likely malicious hosts; the report lists the discovered IP indicators and notes the cluster may be linked to a China-associated actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
