80.241.209.53:12182
ipTracked by C2 Tracker · Whois queried 2026-10-04T12:51:52
Network
- Network
- CONTABO
- CIDR
- 80.241.208.0/21
- Country
- DE
Contact
- Handle
- 80.241.208.0 - 80.241.215.255
- Abuse
- [email protected]
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| CapraRat | d62705186c48… | 2019-04-27 |
About CapraRat
Android RAT used by Transparent Tribe (a.k.a. APT36, Earth Karkaddan, ProjectM) against targets in India and Pakistan. Typically single-application spyware delivered via social engineering, with screen capture, call/SMS exfiltration and audio recording.
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Valid
- 2018-11-27 → 2048-11-19
- Fingerprint
- a8140f73130740106b48101c218989e0decd9755748661e01e5e8bc5eb314391
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.