logo

Fingerprinting C2s with Shodan

ID: f021b137-a998-543b-9607-304ba90da783

STIX ID: report--f021b137-a998-543b-9607-304ba90da783

Feed Name: KMsec blog

Threat Score
66/100

Date Published: 2023-01-06

Date Updated: 2026-04-19

...
...

This report demonstrates rapid threat-intelligence pivoting from a known PupyRAT C2 IP (103.79.76.40) by using Shodan SSL certificate quirks (OU=CONTROL and randomized Organization values) and TLS handshake errors to identify and enumerate ~40 related hosts, produce IOCs, and observe additional malicious services (including Metasploit). The author provides tuned Shodan queries, CLI extraction steps, and a vetted list of IPs for tracking and blocking, concluding the cluster likely represents a specific threat actor group (probable China-based) rather than default PupyRAT infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.