179.198.108.247:3002/commands/
ip C2Tracked by C2 Tracker · Updated as of 2026-10-10 · Whois queried 2026-10-10T16:30:26
Network
- Network
- HOSTINGER-HOSTING
- CIDR
- 179.198.96.0/19
- Country
- BR
Contact
- Handle
- 179.198.96.0 - 179.198.127.255
- Abuse
- abuse@hostinger.com
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Android Installer Dropper (provisional) | 68335e8d9073… | C2 | – |
| Android Installer Dropper (provisional) | 9e88db0dda56… | C2 | – |
About Android Installer Dropper (provisional)
**Android Installer Dropper (provisional)** is a label for multi-stage Android droppers whose job is to side-load and install an embedded, encrypted second-stage APK via PackageInstaller, often alongside a VpnService. One observed build (lure More Nutrition) decrypts an asset (XOR plus GZIP) to an in-memory orchestrator DEX that extracts an encrypted archive and installs the embedded b.apk; another ships an encrypted update.enc payload. The final payload and its C2 are recoverable only by dynamic analysis (running the sample and dumping the installed APK), so samples are tracked here pending a dynamic run. Family label provisional.
Signing certificate
- Subject CN
- teste esss
- Issuer CN
- teste esss
- Valid
- 2026-08-29 → 2051-08-23
- Fingerprint
- ae4d2a29348cbbe8aaccda1d49e41bed47d4a6a97d7f98d33550a8871dcdd9e1
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.