116.205.4.18:33889/control/

ip not resolving

Tracked by C2 Tracker · Whois queried 2026-10-04T15:33:46

Network

Network
HWCSNET
CIDR
116.205.0.0/17
Country
CN

Contact

Handle
116.205.0.0 - 116.205.127.255
Abuse
[email protected], [email protected]

Observed in malware

FamilySample SHA-256First seen
APT41 b66847d571e4… 2019-09-15
APT41 1107200102a2… 2024-03-08
APT41 391d22d89fc8… 2024-03-08
APT41 48e3f32e770f… 2024-03-08
APT41 4e5379745f10… 2024-03-08

About APT41

Android surveillanceware (Lookout calls the two documented strains WyrmSpy and Dragonegg) attributed to the China-nexus actor APT41. Highly permission-hungry implants focused on call logs, SMS, contacts, audio capture and location tracking, masquerading as legitimate apps (e.g. fake security updates or romanticesque apps) and persist via a BootReceiver. The C2 server, password, version and a CustomId sit as meta-data in the manifest; additional http(s) C2 URLs hide as const-strings in a *Root class's DownRootPlan() method.

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2023-08-30 → 2078-06-02
Fingerprint
cc8c0d961d882f2bd8b8f7ef7d24eb92598749e7dc226a91f121293d8637775a

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.