Follow-up on Russian “Host F”
ID: 8961fd75-7278-5415-bcc8-26d45bc7b723
STIX ID: report--8961fd75-7278-5415-bcc8-26d45bc7b723
Feed Name: Censys Blog
Date Published: 2023-02-15
Date Updated: 2026-04-27
Author: Ivonne Francia; Samuel Hoffman; Internal Intelligence Analyst
Censys analysts revisited Host F (95.213.145.99), previously associated with ransomware C2 infrastructure and Bitcoin callbacks, and observed that while some ransomware-related ports were removed, the host later served Rapid7 Metasploit Pro (port 3790) alongside other tools. The report documents port history and service fingerprints, concluding the host is likely still controlled by the same operator and may have shifted from directly hosting ransomware kits to a managerial or penetration-testing/initial-access role within a broader ransomware network.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
