C2
Key: 129.28.85.210 · Resolved IP: 129.28.85.210
Protocols: https · Ports: 55112
First view: 2025-12-26 08:10:57 CET · Last view: 2026-01-15 16:11:09 CET
Endpoints
| ID |
Protocole |
Port |
First view |
Last view |
SubmitURIs |
Paths |
URLs |
Seen in |
| https:55112 |
https |
55112 |
2025-12-26 08:10:57 CET |
2026-01-15 16:11:09 CET |
/api/y |
/api/x |
2
Sample
- https://129.28.85.210:55112/api/x/api/y
- https://129.28.85.210:55112/api/y
|
4
hashes
|
{
"Endpoints": {
"https:55112": {
"Firsttime": 1766733057.118062,
"lasttime": 1768489869.012521,
"paths": [
"/api/x"
],
"port": "55112",
"protocol": "https",
"seen_in": [
{
"arch": "x64",
"beacon_ip": "129.28.85.210",
"beacon_port": "55112",
"config_hash": "eb20d7a73373715b66a69800872ac9e711228e2cfe603efa46763fe4ed78b711",
"trial": false,
"ts": 1766941408.5791101,
"version": "Cobalt Strike 4.9 (Sep 19, 2023)",
"watermark": 666666666
},
{
"arch": "x64",
"beacon_ip": "129.28.85.210",
"beacon_port": "55112",
"config_hash": "a54aa4539e5efcb8f1a4ad974b87c8adc7486b2194bb4baa2e117cdf3aefe922",
"trial": false,
"ts": 1768489869.012521,
"version": "Cobalt Strike 4.9 (Sep 19, 2023)",
"watermark": 666666666
},
{
"arch": "x86",
"beacon_ip": "129.28.85.210",
"beacon_port": "55112",
"config_hash": "aab27ffc328b2e88b00d4f5c2f2b5c406d00bff729d39ab1141d3474538ce31f",
"trial": false,
"ts": 1766941406.6371684,
"version": "Cobalt Strike 4.9 (Sep 19, 2023)",
"watermark": 666666666
},
{
"arch": "x86",
"beacon_ip": "129.28.85.210",
"beacon_port": "55112",
"config_hash": "6e9644efe42aa45f0e1ca2b0b22a3c81580f3d953c51e6d5720fb15277c99cd6",
"trial": false,
"ts": 1768489866.2110744,
"version": "Cobalt Strike 4.9 (Sep 19, 2023)",
"watermark": 666666666
}
],
"submituris": [
"/api/y"
],
"urls": [
"https://129.28.85.210:55112/api/x/api/y",
"https://129.28.85.210:55112/api/y"
]
}
},
"Firsttime": 1766733057.118062,
"Host": "129.28.85.210",
"IP": "129.28.85.210",
"IPs": [
"129.28.85.210"
],
"Paths": [
"/api/x"
],
"Ports": [
"55112"
],
"Protocols": [
"https"
],
"SubmitURIs": [
"/api/y"
],
"URLs": [
"https://129.28.85.210:55112/api/x/api/y",
"https://129.28.85.210:55112/api/y"
],
"ip_enrichment": {
"129.28.85.210": {
"ASN": {
"number": 45090,
"org": "TENCENT-NET-AP Shenzhen Tencent Computer Systems Company Limited"
},
"GEO": {
"country": "CN",
"country_name": "China",
"lat": 35.0,
"lon": 105.0
},
"first": 1766733057.118062,
"last": 1767453248.4464035,
"meta": {
"build_db": "2025-10-14 12:06:54",
"db_source": "GeoOpen-Country-ASN"
},
"source": "ip.circl.lu",
"updated": 1767456638.5154772
}
},
"lasttime": 1768489869.012521
}