172.24.135.166:4444
ip C2Tracked by C2 Tracker · Whois queried never
Network
- Network
- -
- CIDR
- -
- Country
- -
Contact
- Handle
- -
- Abuse
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Metasploit | 583c04d8726d… | C2 | 2026-10-10 |
| Metasploit | 60fc70f8ab38… | C2 | 2026-10-10 |
| Metasploit | 94aa198303b7… | C2 | 2026-10-10 |
| Metasploit | deb7baae8601… | C2 | 2026-10-10 |
About Metasploit
Android payloads generated by Metasploit / msfvenom (meterpreter and command stages), running under the package com.metasploit.stage. The payload dials back to LHOST:LPORT, which is the C2. Two config formats appear in the wild. In the older/plain format the transport URL (tcp://, ssl:// or https://LHOST:LPORT) is a const-string in the DEX. In the newer format the stage carries a protobuf TransportConfig in the static byte array Payload.a, parsed by an embedded protobuf-lite runtime (com.metasploit.a); that array is XOR-masked with a per-build 4-byte key, and because the buffer is zero-padded the leading bytes leak the key, so XORing the array by key[i mod 4] recovers the protobuf and its transport URL. Many samples are red-team or test builds pointing at LAN, loopback or 0.0.0.0 addresses (recorded verbatim); live ones use public IPs or tunnel fronts such as *.lhr.life (localhost.run) and *.loca.lt (localtunnel).
Signing certificate
- Subject CN
- -
- Issuer CN
- -
- Valid
- 2026-03-29 → 2035-04-26
- Fingerprint
- 744b3678e67ee94e6e8c5ce6f95e6bc9fd715179629e5be91133627fff98fd5d
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.