2.117.118.97:5555
ip C2Tracked by C2 Tracker · Updated as of 2026-10-10 · Whois queried 2026-10-10T10:02:35
Network
- Network
- BOSSICTRANSITISPA
- CIDR
- 2.117.118.96/29
- Country
- IT
Contact
- Handle
- 2.117.118.96 - 2.117.118.103
- Abuse
- abuse@business.telecomitalia.it
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| AndroRat | f26658419a91… | C2 | 2016-06-06 |
About AndroRat
One of the oldest open-source Android RATs (first released ~2012), still repackaged into fresh campaigns. Classic builds carry the my.app.client package; repackaged flavors ship under innocuous package names and app titles like "Google Service Framework".
Signing certificate
- Subject CN
- Tre
- Issuer CN
- Tre
- Valid
- 2015-08-27 → 2115-08-03
- Fingerprint
- a3525c7ea4b703f1d4752f07b00cefbfe99e5f3e282de0ce7da35f2196fa5958
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.