202.95.15.135:8554/live/display/
ipTracked by C2 Tracker · Whois queried 2026-10-04T18:19:53
Network
- Network
- RCPL-SG
- CIDR
- 202.95.0.0/19
- Country
- SG
Contact
- Handle
- 202.95.0.0 - 202.95.31.255
- Abuse
- abuse@ctgserver.net, abuse@ctgserver.net
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| MMRat | 51847406cf99… | 2023-07-26 |
| MMRat | d06fc998c4aa… | 2023-08-07 |
| MMRat | 124d3a55770d… | 2023-09-03 |
About MMRat
Android banking trojan carrying out bank fraud via fake app stores, abusing the RTSP stack for its C2 channel: the endpoints are rtsp:// const-strings in the <init> of the short helper classes under com/mm/user/utils/. Identified by the com.mm.user.ui.activity.WebViewActivity activity.
Signing certificate
- Subject CN
- 123456
- Issuer CN
- 123456
- Valid
- 2023-04-05 → 2048-03-29
- Fingerprint
- e4e4b72303db373702d41505a1203eb31f5e759bab62a4c2139cc69c6baf8974
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.