Infrastructure Analysis and Tracking
We identified 65 IPs across 13 country locations and 35 ASNs, concentrated in the United States (29), China (12), and Hong Kong (7). The strongest address clustering was in 38.11.173.0/24 (8 IPs) and 38.11.221.0/24 (6), all under AS54600 with Cogent organisation labels. Tencent-associated AS45090 followed with 8 IPs in China.
| IP | ASN | Org | Country |
|---|---|---|---|
1.14.193.53 | AS45090 | Tencent cloud computing (Beijing) Co., Ltd. | China |
14.128.50.113 | AS152194 | CTG Server Ltd. | Hong Kong |
14.128.50.115 | AS152194 | CTG Server Ltd. | Hong Kong |
23.248.226.254 | AS138415 | RedLuff, LLC | Hong Kong |
38.11.173.10 | AS54600 | Cogent Communications, LLC | United States |
38.11.173.18 | AS54600 | Cogent Communications, LLC | United States |
38.11.173.36 | AS54600 | Cogent Communications | United States |
38.11.173.49 | AS54600 | Cogent Communications, LLC | United States |
38.11.173.54 | AS54600 | Cogent Communications, LLC | United States |
38.11.173.59 | AS54600 | Cogent Communications, LLC | United States |
38.11.173.69 | AS54600 | Cogent Communications, LLC | United States |
38.11.173.114 | AS54600 | Cogent Communications, LLC | United States |
38.11.221.7 | AS54600 | Cogent Communications, LLC | United States |
38.11.221.20 | AS54600 | Cogent Communications, LLC | United States |
38.11.221.54 | AS54600 | Cogent Communications, LLC | United States |
38.11.221.93 | AS54600 | Cogent Communications, LLC | United States |
38.11.221.107 | AS54600 | Cogent Communications, LLC | United States |
38.11.221.123 | AS54600 | Cogent Communications, LLC | United States |
38.54.16.112 | AS138915 | Kaopu Cloud HK Limited | Singapore |
38.60.136.28 | AS154177 | Cogent Communications, LLC | France |
38.76.188.63 | AS401701 | Cogent Communications, LLC | Venezuela, Bolivarian Republic of |
38.244.50.120 | AS174 | NetLab | United States |
43.162.95.207 | AS132203 | ACEVILLE PTE.LTD. | United States |
45.32.20.49 | AS20473 | The Constant Company, LLC | Japan |
45.76.97.145 | AS20473 | Vultr Holdings, LLC | Japan |
45.149.154.125 | AS215727 | JOGCORP SAS | France |
47.237.90.31 | AS45102 | Alibaba Cloud LLC | Singapore |
47.251.39.59 | AS45102 | Alibaba Cloud - US | United States |
49.235.52.47 | AS45090 | Tencent cloud computing (Beijing) Co., Ltd. | China |
64.118.131.167 | Not reported | Brown Art | United States |
66.179.30.133 | AS399629 | BL Networks | United States |
69.33.213.136 | AS3257 | GTT | United States |
82.29.129.54 | AS142036 | Hosteons Pte. Ltd. | United States |
82.157.129.205 | AS45090 | Tencent Cloud Computing (Beijing) Co., Ltd | China |
89.106.84.222 | 215030 | Aspire Hosting | Germany |
91.224.92.16 | AS209605 | UAB Host Baltic | Lithuania |
100.42.230.112 | AS54288 | 80VPS.com | United States |
103.36.63.166 | AS134771 | Zhejiang zhi cloud information technology co., LTD | China |
103.124.105.32 | AS142036 | Hosteons.com VPS | United States |
103.163.47.128 | AS58519 | Inner Mongolia Ruitong Network Technology Co., Ltd | China |
103.193.173.9 | AS132325; AS206300 | IPXO; LEMON TELECOMMUNICATIONS LIMITED | Hong Kong |
104.234.174.13 | AS134677 | Internet Utilities NA LLC | India |
106.13.196.61 | AS38365 | Beijing Baidu Netcom Science and Technology Co., Ltd. | China |
111.228.36.150 | Not reported | eleven street,No. 18 Institute of Jingdong headquarters | China |
118.25.100.71 | AS45090 | Tencent Cloud Computing (Beijing) Co., Ltd | China |
118.193.39.134 | 135377 | UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED | Hong Kong |
119.45.105.71 | AS45090 | Tencent cloud computing (Beijing) Co., Ltd. | China |
122.51.183.32 | AS45090 | Tencent cloud computing (Beijing) Co., Ltd. | China |
124.221.46.59 | AS45090 | Tencent cloud computing (Beijing) Co., Ltd. | China |
129.28.104.75 | AS45090 | Tencent Cloud Computing (Beijing) Co., Ltd | China |
129.226.195.233 | AS132203 | Not reported | Singapore |
130.94.43.244 | AS154177 | LIGHT NODE LIMITED | United States |
137.220.151.95 | AS152194 | NTT Singapore Pte Ltd | Singapore |
151.245.90.134 | AS31549 | Not reported | Netherlands |
156.239.40.14 | 400619 | AROSSCLOUD INC. | United States |
167.160.190.182 | AS36352 | HostPapa | Canada |
168.222.97.94 | Not reported | Air Products & Chemicals, Inc. | United States |
172.105.240.241 | AS63949 | Linode | Japan |
182.16.62.130 | AS963 | Netsec Limited | Hong Kong |
186.244.245.13 | AS7738 | Globenet Cabos Submarinos America Inc. | Brazil |
189.24.77.148 | 979 | NetLab Global - AP | Brazil |
192.236.166.73 | AS36352 | HostPapa | United States |
198.44.170.40 | AS152705 | VpsQuan L.L.C. | Hong Kong |
207.57.126.196 | AS139659 | NTT America, Inc. | United States |
216.108.230.15 | 26277 | ServerPoint.com | United States |
External reporting
Recently, Team Cymru S2 post shared a post on ARTEX.
Additional Services
In addition to ARTEX, BCON CTI analysed our host dataset to identify additional capabilities or services running on other ports, in order to add context into subplementary toolsets and new detection opportunities. Below is a summary of these findings, of which, all are tracked in our malicious infrastructure tracking platform.
| IP | ASN | Org | Country | Port / Transport | Additional Service / Lead |
|---|---|---|---|---|---|
1.14.193.53 | AS45090 | Tencent cloud computing (Beijing) Co., Ltd. | China | 3333/tcp | Gophish |
1.14.193.53 | AS45090 | Tencent cloud computing (Beijing) Co., Ltd. | China | 8089/tcp | Gophish-related certificate |
38.60.136.28 | AS154177 | Cogent Communications, LLC | France | 18081/tcp | ToShell C2 |
45.76.97.145 | AS20473 | Vultr Holdings, LLC | Japan | 8080/tcp | Strix report interface |
103.163.47.128 | AS58519 | Inner Mongolia Ruitong Network Technology Co., Ltd | China | 8081/tcp | CyberStrikeAI |
118.25.100.71 | AS45090 | Tencent Cloud Computing (Beijing) Co., Ltd | China | 8551/tcp | Cobalt Strike Beacon |
118.25.100.71 | AS45090 | Tencent Cloud Computing (Beijing) Co., Ltd | China | 50050/tcp | Cobalt Strike C2 |
119.45.105.71 | AS45090 | Tencent cloud computing (Beijing) Co., Ltd. | China | 4321/tcp | Adaptix C2 |
137.220.151.95 | AS152194 | CTG Server Ltd. | Singapore | 3333/tcp | Gophish |
137.220.151.95 | AS152194 | CTG Server Ltd. | Singapore | 8888/tcp | Cobalt Strike Beacon |
137.220.151.95 | AS152194 | CTG Server Ltd. | Singapore | 9999/tcp | Cobalt Strike Beacon |
192.236.166.73 | AS36352 | HostPapa | United States | 8080/tcp | CyberStrikeAI |
192.236.166.73 | AS36352 | HostPapa | United States | 8090/tcp | CyberStrikeAI |
- ToShell is a lightweight command-and-control (C2) framework with a team server, web console, and cross-platform agents. It supports payload generation, session management, and remote task execution.
- CyberStrikeAI is an open-source AI-assisted security-testing platform that coordinates security tools and agent workflows. Its web interface supports managing testing activity and reviewing results.
- Cobalt Strike is a commercial adversary-simulation platform used by red teams to emulate attacker activity. Its Beacon component receives tasks from a team server and returns execution results.
- Gophish is an open-source phishing-simulation framework for creating campaigns, sending test emails, and tracking recipient responses. A Gophish-labelled certificate alone does not establish that a Gophish instance is running.
- Adaptix C2 is an extensible post-exploitation and adversary-emulation framework for penetration testers. It combines a team server, operator client, and agents for managing remote sessions.
- Strix is an open-source AI penetration-testing tool for identifying and validating application vulnerabilities. The observed Strix-labelled report page does not establish that this specific project or a running Strix agent is present.
Assessment
For CNI defenders, the immediate value of these findings is a set of infrastructure leads to investigate alongside scanning of exposed systems. Review connections from the identified IPs to determine which services were reached, whether requests attempted exploitation, and whether any activity progressed to authentication or endpoint execution. Distinguishing routine probing from activity requiring response helps focus investigation on systems supporting essential services. The observed scanning alone does not establish compromise.
The additional services give those investigations useful context. Some ARTEX-discovered IPs also expose interfaces or signatures associated with phishing, remote control, and post-exploitation tools. That makes them relevant leads for correlating network and endpoint evidence, but it does not show that all services share an operator.
The broader observation is that AI-assisted security-testing platforms are appearing alongside established offensive tools in internet-facing infrastructure. For defenders, this supports tracking AI-assisted tooling through the same evidence used for other activity: source infrastructure, requests against exposed services, process execution, and subsequent connections.