156.254.21.43

ip C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-08 · Whois queried 2026-10-08T05:31:35

Network

Network
—
CIDR
156.254.21.0/24
Country
HK

Contact

Handle
156.254.21.0 - 156.254.21.255
Abuse
—

Observed in malware

FamilySample SHA-256RoleFirst seen
Flutter SMS Stealer (provisional) ee5c1fe15733… C2 2026-10-06
Flutter SMS Stealer (provisional) 35ac16a035e6… C2 2026-10-08

About Flutter SMS Stealer (provisional)

A **Flutter**-built Android SMS/PII stealer of likely Chinese origin, distributed under social and adult-content app disguises. Flutter apps compile their real logic to a native Dart "snapshot" inside `lib/<abi>/libapp.so` rather than to ordinary Java/DEX, so both the behaviour and the C2 live in that `.so` file instead of in the usual Android code. **What it does** - Harvests **SMS messages, contacts, call logs and location** and exfiltrates them to the operator. - Ships under the stable packages `com.dataapp.data_collector` and `com.jlsw.jmy`, as well as randomly-named packages (e.g. `com.ncwtaakvv.rzpyvfqstgw`). - Some builds are additionally wrapped with the **Jiagu** commercial packer; the Flutter payload is identical once unpacked. **How the C2 is recovered (binary-only)** The command-and-control endpoint is a hardcoded **bare-IP HTTP** URL compiled directly into the Dart snapshot `libapp.so`, read out of that file's string pool. The cluster rotates across a small set of hosting IPs (observed `156.254.21.112`, `156.254.21.43`, `172.252.173.36`, `172.252.224.194`, `172.252.224.195`, `66.212.58.145`). Family label provisional.

Signing certificate

Subject CN
LBCXY7
Issuer CN
LBCXY7
Valid
2026-10-07 → 2027-11-10
Fingerprint
ae75f8a4ff37d54ecc6951b2fdeeb60eb83e2d578ff931e5c8dc0e0852c1fb4f

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.