192.168.27.128:4444

ip C2 template placeholder not resolving

Tracked by C2 Tracker · Whois queried never

Network

Network
—
CIDR
—
Country
—

Contact

Handle
—
Abuse
—

Observed in malware

FamilySample SHA-256RoleFirst seen
Metasploit b6dc251ea9ce… C2 2026-10-08

About Metasploit

Android payloads generated by the Metasploit Framework's msfvenom (package com.metasploit.stage, the stock android/meterpreter stager). A small bootstrap APK pulls the meterpreter stage from a handler (LHOST:LPORT, default port 4444) and grants a remote operator full device control - SMS, contacts, call logs, camera, microphone and file access. Metasploit is a legitimate penetration-testing framework, so samples range from red-team/training builds (non-routable test LHOSTs such as 10.0.2.15 or 192.168.x, recorded here as placeholders) to real intrusions; the family tag marks the tool, and each sample's handler address is the indicator when it is a routable one.

Signing certificate

Subject CN
—
Issuer CN
—
Valid
2025-12-22 → 2037-02-08
Fingerprint
8ad283e0a06c7c218615b80ee2f7125635b0580ecebe8fe893479fcbfa06b1c2

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.