114.66.37.132

ip C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-10T07:43:45

Network

Network
YLWL
CIDR
114.66.32.0/19
Country
CN

Contact

Handle
114.66.32.0 - 114.66.63.255
Abuse
[email protected], [email protected]

Observed in malware

FamilySample SHA-256RoleFirst seen
HK Banking Stealer (provisional) d27a9bf383b5… C2 2026-10-08

About HK Banking Stealer (provisional)

Packed Android banking/crypto-wallet stealer aimed at Hong Kong and mainland-China victims. Ships a three-layer payload: an AES-CBC-encrypted cfg.dat (key sK8xQ2mN7vL4pR9w) yields the config, which unlocks an AES-encrypted data.bin second stage; in-code strings are stored as ENC:<base64> blobs XOR-decrypted with a fixed key. The recovered stage exfiltrates banking and cryptocurrency-wallet data over a raw TCP socket to its C2 at 114.66.37.132. Family label provisional.

Signing certificate

Subject CN
ba6152c2
Issuer CN
ba6152c2
Valid
2026-04-10 → 2126-03-17
Fingerprint
83c9cec90600c6e764289f294dfb33d476b69bab5ff3fb03826ba3fb69367ad9

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.