logo

Follow-up on Russian “Host F”

ID: 8961fd75-7278-5415-bcc8-26d45bc7b723

STIX ID: report--8961fd75-7278-5415-bcc8-26d45bc7b723

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2023-02-15

Date Updated: 2026-04-27

Author: Ivonne Francia; Samuel Hoffman; Internal Intelligence Analyst

...
...

Censys analysts revisited Host F (95.213.145.99), previously associated with ransomware C2 infrastructure and Bitcoin callbacks, and observed that while some ransomware-related ports were removed, the host later served Rapid7 Metasploit Pro (port 3790) alongside other tools. The report documents port history and service fingerprints, concluding the host is likely still controlled by the same operator and may have shifted from directly hosting ransomware kits to a managerial or penetration-testing/initial-access role within a broader ransomware network.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.