REPORT
Dissecting Exposed Adaptix C2 and Rogue MySQL Exploitation Infrastructure
In-depth forensic review of an exposed threat staging server running AdaptixC2, Cobalt Strike 4.9.1, and weaponized Rogue MySQL arbitrary file read attacks.
Targeted reconnaissance, access brokerage, and exploitation of public health and municipal infrastructure.
101[.]42[.]255[.]92 operates as a centralized Command & Control hub and offensive staging node hosted on Tencent Cloud.8081 alongside the modern AdaptixC2 and customized RRR_C2_v1.2 frameworks.LOCAL INFILE protocol feature, forcing connected Java/Spring clients to exfiltrate arbitrary files (application-dev.yml, internal .jar packages).卫生健康委员会).| Indicator Type | Defanged Value | Operational Role |
|---|---|---|
| IPv4 Address | 101[.]42[.]255[.]92 | Staging, Cobalt Strike & Adaptix C2 Node |
| Port / Service | 101[.]42[.]255[.]92:8081 | Cobalt Strike TeamServer Listener |
| Port / Service | 101[.]42[.]255[.]92:3306 | Rogue MySQL Arbitrary File Exfiltration Listener |
| Port / Service | 101[.]42[.]255[.]92:8555 | JNDI / HTTP Payload Delivery |
| Port / Service | 101[.]42[.]255[.]92:8857 | Interactive Reverse Shell Listener |
| Tool Artifact | genCrossC2.Linux | Cross-platform Linux ELF Cobalt Strike Beacon Compiler |
| Tool Artifact | rogue_mysql_server | JDBC Protocol Arbitrary Client File Extraction Tool |