116.205.4.18:33889/control/
ipTracked by C2 Tracker · Whois queried 2026-10-04T15:33:46
Network
- Network
- HWCSNET
- CIDR
- 116.205.0.0/17
- Country
- CN
Contact
- Handle
- 116.205.0.0 - 116.205.127.255
- Abuse
- ipas@cnnic.cn, ipas@cnnic.cn
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| APT41 | b66847d571e4… | 2019-09-15 |
| APT41 | 1107200102a2… | 2024-03-08 |
| APT41 | 391d22d89fc8… | 2024-03-08 |
| APT41 | 48e3f32e770f… | 2024-03-08 |
| APT41 | 4e5379745f10… | 2024-03-08 |
About APT41
Android surveillanceware (Lookout calls the two documented strains WyrmSpy and Dragonegg) attributed to the China-nexus actor APT41. Highly permission-hungry implants focused on call logs, SMS, contacts, audio capture and location tracking, masquerading as legitimate apps (e.g. fake security updates or romanticesque apps) and persist via a BootReceiver. The C2 server, password, version and a CustomId sit as meta-data in the manifest; additional http(s) C2 URLs hide as const-strings in a *Root class's DownRootPlan() method.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2023-08-30 → 2078-06-02
- Fingerprint
- cc8c0d961d882f2bd8b8f7ef7d24eb92598749e7dc226a91f121293d8637775a
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.