www.upeg-system-app.com/ServiceRApp/user/
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:17:43
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 3.250.92.156
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| StrongPity | 596257ef017b… | C2 | 2021-07-22 |
Attributed to: StrongPity
About StrongPity
**StrongPity** (aka **Promethium** / APT-C-41) is a long-running espionage actor known for watering-hole distribution of trojanized legitimate installers. Its Android branch, documented by ESET in 2023, ships a backdoored build of a real app (for example Shagle video-chat / Telegram-style apps) whose modular malicious component activates when a matching C2 is reachable. It harvests call logs, SMS, contacts, device and location data and files, records calls and enumerates installed apps, uploading to attacker infrastructure (internetwideband.com, networktopologymaps.com, www.upeg-system-app.com). Historically associated with Turkey/Syria-nexus targeting. APT / state-aligned.
Signing certificate
- Subject CN
- Mike Hullman
- Issuer CN
- Mike Hullman
- Valid
- 2019-11-14 → 2044-11-07
- Fingerprint
- ba4e6d93075aec6aaf68d23a8c860505092396d107776be98d119172cc6351b7
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.