179.198.108.247:3002/commands/

ip C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-10 · Whois queried 2026-10-10T16:30:26

Network

Network
HOSTINGER-HOSTING
CIDR
179.198.96.0/19
Country
BR

Contact

Handle
179.198.96.0 - 179.198.127.255
Abuse
abuse@hostinger.com

Observed in malware

FamilySample SHA-256RoleFirst seen
Android Installer Dropper (provisional) 68335e8d9073… C2 –
Android Installer Dropper (provisional) 9e88db0dda56… C2 –

About Android Installer Dropper (provisional)

**Android Installer Dropper (provisional)** is a label for multi-stage Android droppers whose job is to side-load and install an embedded, encrypted second-stage APK via PackageInstaller, often alongside a VpnService. One observed build (lure More Nutrition) decrypts an asset (XOR plus GZIP) to an in-memory orchestrator DEX that extracts an encrypted archive and installs the embedded b.apk; another ships an encrypted update.enc payload. The final payload and its C2 are recoverable only by dynamic analysis (running the sample and dumping the installed APK), so samples are tracked here pending a dynamic run. Family label provisional.

Signing certificate

Subject CN
teste esss
Issuer CN
teste esss
Valid
2026-08-29 → 2051-08-23
Fingerprint
ae4d2a29348cbbe8aaccda1d49e41bed47d4a6a97d7f98d33550a8871dcdd9e1

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.