172.252.224.195

ip C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-08 · Whois queried 2026-10-08T05:31:33

Network

Network
EGNL-1
CIDR
172.252.0.0/16
Country
US

Contact

Handle
NET-172-252-0-0-1
Abuse
—

Observed in malware

FamilySample SHA-256RoleFirst seen
Flutter SMS Stealer (provisional) d653d39c372a… C2 2026-09-30

About Flutter SMS Stealer (provisional)

A **Flutter**-built Android SMS/PII stealer of likely Chinese origin, distributed under social and adult-content app disguises. Flutter apps compile their real logic to a native Dart "snapshot" inside `lib/<abi>/libapp.so` rather than to ordinary Java/DEX, so both the behaviour and the C2 live in that `.so` file instead of in the usual Android code. **What it does** - Harvests **SMS messages, contacts, call logs and location** and exfiltrates them to the operator. - Ships under the stable packages `com.dataapp.data_collector` and `com.jlsw.jmy`, as well as randomly-named packages (e.g. `com.ncwtaakvv.rzpyvfqstgw`). - Some builds are additionally wrapped with the **Jiagu** commercial packer; the Flutter payload is identical once unpacked. **How the C2 is recovered (binary-only)** The command-and-control endpoint is a hardcoded **bare-IP HTTP** URL compiled directly into the Dart snapshot `libapp.so`, read out of that file's string pool. The cluster rotates across a small set of hosting IPs (observed `156.254.21.112`, `156.254.21.43`, `172.252.173.36`, `172.252.224.194`, `172.252.224.195`, `66.212.58.145`). Family label provisional.

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Valid
2026-03-28 → 2056-03-20
Fingerprint
167598b91e940acd6999032df1fa5dfab6a7155989a992f9706dc0b290940cca

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.