182.162.104.181/
ip C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:17:10
Network
- Network
- KIDC-KR
- CIDR
- 182.162.0.0/16
- Country
- KR
Contact
- Handle
- 182.162.0.0 - 182.162.255.255
- Abuse
- [email protected], [email protected]
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| FakeSpy | 51793a9bc21e… | C2 | 2018-12-18 |
About FakeSpy
Android spyware posing as legitimate postal/ delivery-service apps, exfiltrating SMS and contact data to a PHP panel. The panel base URL is an http:// const-string in the MyService$ReThread (or MeService$ReThread) run() loop; some builds instead carry CONFIG_URL / IP_ADDRESS / LOGS_URL as static field values of Lorg/red/cute/common/Constant;.
Signing certificate
- Subject CN
- afgsdfhsdfghj
- Issuer CN
- afgsdfhsdfghj
- Valid
- 2018-11-19 → 2043-11-13
- Fingerprint
- 48ac73636a3ebc98f7657ea47cdc200a633526ee4a80472ff5e72498cff01008
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.