144.31.167.91:8443/ws
ip C2Tracked by C2 Tracker · Whois queried never
Network
- Network
- -
- CIDR
- -
- Country
- -
Contact
- Handle
- -
- Abuse
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| WebSocket SMS Stealer (provisional) | 6dd7c9573329… | C2 | 2026-10-11 |
About WebSocket SMS Stealer (provisional)
Modern Kotlin Android stealer (observed 2026) that requests SMS, call and contacts permissions and talks to its C2 over a WebSocket using the OkHttp client. Endpoints seen in captured traffic include an HTTP registration call (/api/v1/register) and a WebSocket channel (/ws) on port 8443. The implant is heavily obfuscated: strings are encrypted and the C2 configuration is stored as a custom AES-GCM container in an encrypted asset (observed name assets/<rand>.cache), so the host is not present in the DEX in any plaintext, base64, hex or single-byte-XOR form and is only resolved at runtime. Provisional bucket pending attribution.
Signing certificate
- Subject CN
- APK Signer
- Issuer CN
- APK Signer
- Valid
- 2019-09-03 → 2049-10-25
- Fingerprint
- b6da01480eefd5fbf2cd3771b8d1021ec791304bdd6c4bf41d3faabad48ee5e1
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.