192.168.27.128:4444
ip C2 template placeholderTracked by C2 Tracker · Whois queried never
Network
- Network
- —
- CIDR
- —
- Country
- —
Contact
- Handle
- —
- Abuse
- —
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Metasploit | b6dc251ea9ce… | C2 | 2026-10-08 |
About Metasploit
Android payloads generated by the Metasploit Framework's msfvenom (package com.metasploit.stage, the stock android/meterpreter stager). A small bootstrap APK pulls the meterpreter stage from a handler (LHOST:LPORT, default port 4444) and grants a remote operator full device control - SMS, contacts, call logs, camera, microphone and file access. Metasploit is a legitimate penetration-testing framework, so samples range from red-team/training builds (non-routable test LHOSTs such as 10.0.2.15 or 192.168.x, recorded here as placeholders) to real intrusions; the family tag marks the tool, and each sample's handler address is the indicator when it is a routable one.
Signing certificate
- Subject CN
- —
- Issuer CN
- —
- Valid
- 2025-12-22 → 2037-02-08
- Fingerprint
- 8ad283e0a06c7c218615b80ee2f7125635b0580ecebe8fe893479fcbfa06b1c2
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.