3.67.78.149:2002
ipTracked by C2 Tracker · Whois queried 2026-10-04T12:51:51
Network
- Network
- AMAZON-FRA
- CIDR
- 3.64.0.0/12
- Country
- —
Contact
- Handle
- NET-3-64-0-0-1
- Abuse
- —
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| AndroRat | 347f1b018f64… | 2023-05-10 |
About AndroRat
One of the oldest open-source Android RATs (first released ~2012), still repackaged into fresh campaigns. Classic builds carry the my.app.client package; repackaged flavors ship under innocuous package names and app titles like "Google Service Framework".
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Valid
- 2016-10-23 → 2044-03-10
- Fingerprint
- 1e08a903aef9c3a721510b64ec764d01d3d094eb954161b62544ea8f187b5953
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.