114.66.37.132
ip C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-10T07:43:45
Network
- Network
- YLWL
- CIDR
- 114.66.32.0/19
- Country
- CN
Contact
- Handle
- 114.66.32.0 - 114.66.63.255
- Abuse
- [email protected], [email protected]
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| HK Banking Stealer (provisional) | d27a9bf383b5… | C2 | 2026-10-08 |
About HK Banking Stealer (provisional)
Packed Android banking/crypto-wallet stealer aimed at Hong Kong and mainland-China victims. Ships a three-layer payload: an AES-CBC-encrypted cfg.dat (key sK8xQ2mN7vL4pR9w) yields the config, which unlocks an AES-encrypted data.bin second stage; in-code strings are stored as ENC:<base64> blobs XOR-decrypted with a fixed key. The recovered stage exfiltrates banking and cryptocurrency-wallet data over a raw TCP socket to its C2 at 114.66.37.132. Family label provisional.
Signing certificate
- Subject CN
- ba6152c2
- Issuer CN
- ba6152c2
- Valid
- 2026-04-10 → 2126-03-17
- Fingerprint
- 83c9cec90600c6e764289f294dfb33d476b69bab5ff3fb03826ba3fb69367ad9
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.