156.254.21.112
ipTracked by C2 Tracker · Updated as of 2026-10-08 · Whois queried 2026-10-08T03:18:47
Network
- Network
- —
- CIDR
- 156.254.21.0/24
- Country
- HK
Contact
- Handle
- 156.254.21.0 - 156.254.21.255
- Abuse
- —
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| Flutter SMS Stealer (provisional) | 0137744ec54f… | 2026-10-03 |
About Flutter SMS Stealer (provisional)
A **Flutter**-built Android SMS/PII stealer of likely Chinese origin, distributed under social and adult-content app disguises. Flutter apps compile their real logic to a native Dart "snapshot" inside `lib/<abi>/libapp.so` rather than to ordinary Java/DEX, so both the behaviour and the C2 live in that `.so` file instead of in the usual Android code. **What it does** - Harvests **SMS messages, contacts, call logs and location** and exfiltrates them to the operator. - Ships under the stable packages `com.dataapp.data_collector` and `com.jlsw.jmy`, as well as randomly-named packages (e.g. `com.ncwtaakvv.rzpyvfqstgw`). - Some builds are additionally wrapped with the **Jiagu** commercial packer; the Flutter payload is identical once unpacked. **How the C2 is recovered (binary-only)** The command-and-control endpoint is a hardcoded **bare-IP HTTP** URL compiled directly into the Dart snapshot `libapp.so`, read out of that file's string pool. The cluster rotates across a small set of hosting IPs (observed `156.254.21.112`, `156.254.21.43`, `172.252.173.36`, `172.252.224.194`, `172.252.224.195`, `66.212.58.145`). Family label provisional.
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Valid
- 2026-05-20 → 2056-05-12
- Fingerprint
- fa25c761237f3212f4861c7e4ca5296e1e9458b6224c66b10d6517e61cdca1ad
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.