198.144.149.130:12380/hello
ip C2Tracked by C2 Tracker · Whois queried never
Network
- Network
- —
- CIDR
- —
- Country
- —
Contact
- Handle
- —
- Abuse
- —
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Anubis | 2c4694a79d1b… | C2 | 2026-10-07 |
About Anubis
Android banking trojan, a long-lived descendant of the BankBot/Marcher lineage sold as malware-as-a-service. Heavy abuse of accessibility services for overlay credential theft, keylogging and SMS interception, with a ransomware module in later builds. Shipped as a packer: the real payload is an RC4-encrypted asset whose key is an int[] literal in the loader (each element & 0xff); the unpacked config carries the C2 panel and an RC4 key. Many builds use a dead drop - a Twitter/Telegram profile whose text holds the real C2 behind the key - rather than a hardcoded host.
Signing certificate
- Subject CN
- —
- Issuer CN
- —
- Valid
- 2026-12-04 → 2095-05-16
- Fingerprint
- 6cf777da9d58ca1f80a878acc5ce2d6d07e5819c10d00b43ce46a98e16365a13
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.