
Four IPs, One ASN: Weak Link to Decade-Old Food-Lure Malware
A cluster of four IP addresses on Mosaic Telecom's AS26472 network forms a tight, ASN-confirmed infrastructure cohort, but the record's only substantive payload is a decade-old, unsigned Windows executable with food-order filenames. CTX Team's analysis finds no shared imphash, signer, or threat label linking the two, leaving the connection suggestive rather than proven.
Four IP addresses tucked inside a single /18 block, all registered to the same US carrier, are the most coherent piece of evidence in an otherwise threadbare threat record — and they are doing most of the analytical heavy lifting. The four nodes — 173.248.16.79, 173.248.20.145, 173.248.29.213, and 173.248.31.6 — all sit inside 173.248.0.0/18 under ASN 26472, registered to Mosaic Telecom, a Wisconsin-based carrier.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read