183.111.122.185:8080

ip C2 not resolving

Tracked by C2 Tracker · Whois queried never

Network

Network
-
CIDR
-
Country
-

Contact

Handle
-
Abuse
-

Observed in malware

FamilySample SHA-256RoleFirst seen
WhiteBroad cbf5b3e62ac1… C2 2018-12-29

About WhiteBroad

Android spyware family spanning several build flavors: com.red.rainbow and cn.close.vcl.play (plus repacks caught by a four-part manifest fingerprint) carry the C2 as a CompileConfig static field or ApiManager getApi() const-string shaped http://host/v1/api/...; a common/Constant; class exposes the full endpoint set (IP_ADDRESS, CONFIG_URL, *_URL). The com.android.hellon flavor moves the C2 into the .rodata of bundled libhelper/libma?sker native libraries as plain http(s) .php URLs.

Signing certificate

Subject CN
Sogou
Issuer CN
Sogou
Valid
2012-11-01 → 3012-03-04
Fingerprint
4b4b072f035de365937a1ccc9f02a0a7606326fe05920d50cc5aeee34db16f64

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.