www.upeg-system-app.com/ServiceRApp/user/

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:17:43

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
3.250.92.156
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
StrongPity 596257ef017b… C2 2021-07-22

Attributed to: StrongPity

About StrongPity

**StrongPity** (aka **Promethium** / APT-C-41) is a long-running espionage actor known for watering-hole distribution of trojanized legitimate installers. Its Android branch, documented by ESET in 2023, ships a backdoored build of a real app (for example Shagle video-chat / Telegram-style apps) whose modular malicious component activates when a matching C2 is reachable. It harvests call logs, SMS, contacts, device and location data and files, records calls and enumerates installed apps, uploading to attacker infrastructure (internetwideband.com, networktopologymaps.com, www.upeg-system-app.com). Historically associated with Turkey/Syria-nexus targeting. APT / state-aligned.

Signing certificate

Subject CN
Mike Hullman
Issuer CN
Mike Hullman
Valid
2019-11-14 → 2044-11-07
Fingerprint
ba4e6d93075aec6aaf68d23a8c860505092396d107776be98d119172cc6351b7

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.