45.120.69.10/
ipTracked by C2 Tracker · Whois queried never
Network
- Network
- —
- CIDR
- —
- Country
- —
Contact
- Handle
- —
- Abuse
- —
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| FakeSpy | fa70929f9589… | 2018-12-12 |
About FakeSpy
Android spyware posing as legitimate postal/ delivery-service apps, exfiltrating SMS and contact data to a PHP panel. The panel base URL is an http:// const-string in the MyService$ReThread (or MeService$ReThread) run() loop; some builds instead carry CONFIG_URL / IP_ADDRESS / LOGS_URL as static field values of Lorg/red/cute/common/Constant;.
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Valid
- 2018-11-06 → 2048-10-29
- Fingerprint
- 3e05bc469b6bd1d83be824d7e012749c12397f6017f3643f029c0de549bbd740
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.