192.168.8.175:3000/api/ws/
ip C2Tracked by C2 Tracker · Updated as of 2026-10-10 · Whois queried 2026-10-10T09:51:04
Network
- Network
- PRIVATE-ADDRESS-CBLK-RFC1918-IANA-RESERVED
- CIDR
- 192.168.0.0/16
- Country
- US
Contact
- Handle
- NET-192-168-0-0-1
- Abuse
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| SecretShoot Crypto Drainer (provisional) | ac20f08c0cc3… | C2 | 2026-09-24 |
About SecretShoot Crypto Drainer (provisional)
Chinese accessibility-driven crypto-wallet drainer disguised as an adult-video app (秘色视频). An AccessibilityService automates on-device crypto withdrawals against targeted wallet/exchange apps (Gate.io, Trust Wallet, imToken) and PhonePe, reading and filling fund-password, amount and SMS/email 2FA fields and tapping confirm, while a WebView JS bridge and a WebSocket channel talk to the operator. Strings are per-string XOR-obfuscated; the build layers decoy services, staged .bt assets and ad-SDK noise. C2 is a wss:// command channel plus an HTTPS error-reporting endpoint on the same operator domain, recovered by decoding the obfuscated config. Family label provisional.
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Valid
- 2011-10-08 → 2041-09-30
- Fingerprint
- ebb0fedf1942a099b287c3db00ff732162152481abb2b6c7cbcdb2ba5894a768
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.