ilovepng.info:8443/control

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:03

Registration

Registrar
PDR Ltd. d/b/a PublicDomainRegistry.com
Registered
2026-03-02T19:47:14.508Z
Expires
2027-03-02T19:47:14.508Z

DNS

Resolves to
178.16.55.7
Nameservers
dns1.regway.com, dns2.regway.com, dns3.regway.com, dns4.regway.com
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
Mirax 29577570d184… C2 2025-12-10
Mirax 88e6e4a5478a… C2 2026-04-10

About Mirax

**Mirax** is an Android RAT that turns the infected device into a SOCKS5 proxy node while also providing remote-control and stealer functionality. It is delivered both directly and as the payload of other droppers (for example the Black Hawk twin-asset dropper). Proxy/C2 coordination is at ilovepng.info. The family packs its real payload inside heavily obfuscated, sometimes deliberately malformed APK containers to resist static analysis.

Signing certificate

Subject CN
Facebook Corporation
Issuer CN
Facebook Corporation
Valid
2026-03-08 → 2053-07-24
Fingerprint
f0f08f923e390c0a1830ac3a4d2084f723d982b2dc17aeee8da6159b0a057c4f

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.