C2
Key: 45.221.118.180 · Resolved IP: 45.221.118.180
HK / AS55933 / CLOUDIE-AS-AP Cloudie Limited
Protocols: http · Ports: 8443, 111
First view: 2026-03-29 00:05:36 CET · Last view: 2026-04-01 16:05:43 CEST
HK / AS55933 / CLOUDIE-AS-AP Cloudie Limited
Protocols: http · Ports: 8443, 111
First view: 2026-03-29 00:05:36 CET · Last view: 2026-04-01 16:05:43 CEST
Endpoints
| ID | Protocol | Port | First view | Last view | SubmitURIs | Paths | URLs | Seen in |
|---|---|---|---|---|---|---|---|---|
| http:111 | http | 111 | 2026-04-01 00:05:27 CEST | 2026-04-01 16:05:43 CEST | /submit.php | /ptj, /g.pixel |
3
sample
|
2 |
| http:8443 | http | 8443 | 2026-03-29 00:05:36 CET | 2026-03-29 16:05:18 CEST | /submit.php | /IE9CompatViewList.xml, /g.pixel |
3
sample
|
2 |
Raw JSON
{
"Endpoints": {
"http:111": {
"Firsttime": 1774994727.4613004,
"lasttime": 1775052343.0166402,
"paths": [
"/ptj",
"/g.pixel"
],
"port": "111",
"protocol": "http",
"seen_in": [
{
"arch": "x86",
"beacon_ip": "45.221.118.180",
"beacon_port": "111",
"config_hash": "40daecd34e157e75931efb7b2101670636ce685ee97675a0b227249200a13dfe",
"trial": false,
"ts": 1775052341.1653323,
"version": "Cobalt Strike 4.9 (Sep 19, 2023)",
"watermark": 987654321
},
{
"arch": "x64",
"beacon_ip": "45.221.118.180",
"beacon_port": "111",
"config_hash": "a86c1a5e4b77bb1805597ea7af49bd1bea02ea66fe834865abb494f91e63b892",
"trial": false,
"ts": 1775052343.0166402,
"version": "Cobalt Strike 4.9 (Sep 19, 2023)",
"watermark": 987654321
}
],
"submituris": [
"/submit.php"
],
"urls": [
"http://45.221.118.180:111/ptj/submit.php",
"http://45.221.118.180:111/submit.php",
"http://45.221.118.180:111/g.pixel/submit.php"
]
},
"http:8443": {
"Firsttime": 1774739136.7115502,
"lasttime": 1774793118.5692787,
"paths": [
"/IE9CompatViewList.xml",
"/g.pixel"
],
"port": "8443",
"protocol": "http",
"seen_in": [
{
"arch": "x86",
"beacon_ip": "45.221.118.180",
"beacon_port": "8443",
"config_hash": "44437180b7e0105f88427907ddc2edb95144cdaa81c456d800b434122d2838f2",
"trial": false,
"ts": 1774793116.2978957,
"version": "Cobalt Strike 4.9 (Sep 19, 2023)",
"watermark": 987654321
},
{
"arch": "x64",
"beacon_ip": "45.221.118.180",
"beacon_port": "8443",
"config_hash": "ada033dd46d18017a892577e01b79d9a7c19f50fd98b024337918aa1b21b255c",
"trial": false,
"ts": 1774793118.5692787,
"version": "Cobalt Strike 4.9 (Sep 19, 2023)",
"watermark": 987654321
}
],
"submituris": [
"/submit.php"
],
"urls": [
"http://45.221.118.180:8443/IE9CompatViewList.xml/submit.php",
"http://45.221.118.180:8443/submit.php",
"http://45.221.118.180:8443/g.pixel/submit.php"
]
}
},
"Firsttime": 1774739136.7115502,
"Host": "45.221.118.180",
"IP": "45.221.118.180",
"IPs": [
"45.221.118.180"
],
"Paths": [
"/IE9CompatViewList.xml",
"/g.pixel",
"/ptj"
],
"Ports": [
"8443",
"111"
],
"Protocols": [
"http"
],
"SubmitURIs": [
"/submit.php"
],
"URLs": [
"http://45.221.118.180:8443/IE9CompatViewList.xml/submit.php",
"http://45.221.118.180:8443/submit.php",
"http://45.221.118.180:8443/g.pixel/submit.php",
"http://45.221.118.180:111/ptj/submit.php",
"http://45.221.118.180:111/submit.php",
"http://45.221.118.180:111/g.pixel/submit.php"
],
"ip_enrichment": {
"45.221.118.180": {
"ASN": {
"number": 55933,
"org": "CLOUDIE-AS-AP Cloudie Limited"
},
"GEO": {
"country": "HK",
"country_name": "Hong Kong",
"lat": 22.25,
"lon": 114.1667
},
"first": 1774739136.7115502,
"last": 1774739139.2530057,
"meta": {
"build_db": "2025-10-14 12:06:54",
"db_source": "GeoOpen-Country-ASN"
},
"source": "ip.circl.lu",
"updated": 1774739151.136946
}
},
"lasttime": 1775052343.0166402
}