192.168.8.175:3000/api/ws/

ip C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-10 · Whois queried 2026-10-10T09:51:04

Network

Network
PRIVATE-ADDRESS-CBLK-RFC1918-IANA-RESERVED
CIDR
192.168.0.0/16
Country
US

Contact

Handle
NET-192-168-0-0-1
Abuse
-

Observed in malware

FamilySample SHA-256RoleFirst seen
SecretShoot Crypto Drainer (provisional) ac20f08c0cc3… C2 2026-09-24

About SecretShoot Crypto Drainer (provisional)

Chinese accessibility-driven crypto-wallet drainer disguised as an adult-video app (秘色视频). An AccessibilityService automates on-device crypto withdrawals against targeted wallet/exchange apps (Gate.io, Trust Wallet, imToken) and PhonePe, reading and filling fund-password, amount and SMS/email 2FA fields and tapping confirm, while a WebView JS bridge and a WebSocket channel talk to the operator. Strings are per-string XOR-obfuscated; the build layers decoy services, staged .bt assets and ad-SDK noise. C2 is a wss:// command channel plus an HTTPS error-reporting endpoint on the same operator domain, recovered by decoding the obfuscated config. Family label provisional.

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Valid
2011-10-08 → 2041-09-30
Fingerprint
ebb0fedf1942a099b287c3db00ff732162152481abb2b6c7cbcdb2ba5894a768

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.