198.144.149.130:12380/hello

ip C2 not resolving

Tracked by C2 Tracker · Whois queried never

Network

Network
—
CIDR
—
Country
—

Contact

Handle
—
Abuse
—

Observed in malware

FamilySample SHA-256RoleFirst seen
Anubis 2c4694a79d1b… C2 2026-10-07

About Anubis

Android banking trojan, a long-lived descendant of the BankBot/Marcher lineage sold as malware-as-a-service. Heavy abuse of accessibility services for overlay credential theft, keylogging and SMS interception, with a ransomware module in later builds. Shipped as a packer: the real payload is an RC4-encrypted asset whose key is an int[] literal in the loader (each element & 0xff); the unpacked config carries the C2 panel and an RC4 key. Many builds use a dead drop - a Twitter/Telegram profile whose text holds the real C2 behind the key - rather than a hardcoded host.

Signing certificate

Subject CN
—
Issuer CN
—
Valid
2026-12-04 → 2095-05-16
Fingerprint
6cf777da9d58ca1f80a878acc5ce2d6d07e5819c10d00b43ce46a98e16365a13

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.