push.travistaone.com
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:22
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 104.21.39.47, 172.67.143.54
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| WebSocket RAT (provisional) | 0683f4361151… | C2 | 2026-10-02 |
| WebSocket RAT (provisional) | 05d48e10de68… | C2 | 2026-10-06 |
About WebSocket RAT (provisional)
Android remote-access trojan that uses a WebSocket channel for command-and-control, spreading its panels across rotating look-alike domains (observed: api.jetengine.be, g2.slachozhin.com, push.travistaone.com, sara.sfjioagjioabnjqqfmx.com). Family label provisional; grouped by shared WebSocket C2 protocol pending firmer attribution.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-04-15 → 2035-09-01
- Fingerprint
- 465983f7791f2abeb43ea2cbdc7f21a8260b72bc08a55c839fc1a43bc741a81e
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.