wemoro4384-36454.portmap.host:36454

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-10 · Whois queried 2026-10-10T14:21:14

Registration

Registrar
NameCheap, Inc.
Registered
2018-07-10T11:44:49.000Z
Expires
2027-07-10T23:59:59.000Z

DNS

Resolves to
127.0.0.1
Nameservers
ns-cloud-b1.googledomains.com, ns-cloud-b2.googledomains.com, ns-cloud-b3.googledomains.com, ns-cloud-b4.googledomains.com
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
SpyMax (provisional) 172d362a74c7… C2 2026-07-13

About SpyMax (provisional)

**SpyMax (provisional)** is a commercial Android spyware/RAT of the SpyNote family (SpyMax lineage), built from a public builder and repackaged under game and utility lures (for example "Proxy hs" and "Google Translate") with randomised package and class names per build. The C2 is stored as base64 static fields initializeService.ClientHost and ClientPort (decoded at runtime by a Base64 helper) and reached as a raw TCP socket to ClientHost:ClientPort; builds also carry a ConnectionKey. It runs a full surveillance stack: live screen streaming via MediaProjection (Screen_Sender / SecondarySocket), live camera capture (CameraHandler socket), keylogging (KeyboardService), an Accessibility service (AccessService), a FloatingView overlay, geolocation (LocationService plus Yandex static-maps), SMS theft and app installation (REQUEST_INSTALL_PACKAGES). Some builds ship a LAN/test C2 (for example 192.168.18.46) left by the operator or a red-teamer. Family label provisional.

Signing certificate

Subject CN
Cybersecurity
Issuer CN
Cybersecurity
Valid
2026-07-13 → 2027-07-13
Fingerprint
aa534955a5f0f72f72cf26617e1c6c5ac90a19aa3ecf3bba55ae31c354a16a50

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.