180.150.226.122:8080
ip C2Tracked by C2 Tracker · Whois queried never
Network
- Network
- -
- CIDR
- -
- Country
- -
Contact
- Handle
- -
- Abuse
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| WhiteBroad | 2fc1f2220375… | C2 | 2018-12-07 |
| WhiteBroad | 77efb6de7409… | C2 | 2018-12-13 |
About WhiteBroad
Android spyware family spanning several build flavors: com.red.rainbow and cn.close.vcl.play (plus repacks caught by a four-part manifest fingerprint) carry the C2 as a CompileConfig static field or ApiManager getApi() const-string shaped http://host/v1/api/...; a common/Constant; class exposes the full endpoint set (IP_ADDRESS, CONFIG_URL, *_URL). The com.android.hellon flavor moves the C2 into the .rodata of bundled libhelper/libma?sker native libraries as plain http(s) .php URLs.
Signing certificate
- Subject CN
- yescofield
- Issuer CN
- yescofield
- Valid
- 2018-07-03 → 2043-06-27
- Fingerprint
- 806b6f8979e54c2eaa8bd1281b0c886814a187b681321e04dbda7f333cd3ca6b
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.