172.20.10.3:4444
ip C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:17:26
Network
- Network
- PRIVATE-ADDRESS-BBLK-RFC1918-IANA-RESERVED
- CIDR
- 172.16.0.0/12
- Country
- US
Contact
- Handle
- NET-172-16-0-0-1
- Abuse
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| AndroRat | 83c7ea10e01b… | C2 | 2026-09-27 |
About AndroRat
One of the oldest open-source Android RATs (first released ~2012), still repackaged into fresh campaigns. Classic builds carry the my.app.client package; repackaged flavors ship under innocuous package names and app titles like "Google Service Framework".
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Valid
- 2016-10-23 → 2044-03-10
- Fingerprint
- 1e08a903aef9c3a721510b64ec764d01d3d094eb954161b62544ea8f187b5953
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.