82.137.255.56:1740
ipTracked by C2 Tracker · Whois queried 2026-10-04T17:13:02
Network
- Network
- SY-ISP-190
- CIDR
- 82.137.248.0/21
- Country
- SY
Contact
- Handle
- 82.137.248.0 - 82.137.255.255
- Abuse
- [email protected]
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| APT-C-27 | 2d0a56a34777… | 2018-07-16 |
| APT-C-27 | b15b5a1a1203… | 2018-07-16 |
| APT-C-27 | caf0f58ebe2f… | 2018-07-16 |
| APT-C-27 | 041b9066f42b… | 2018-07-18 |
| APT-C-27 | 0713ff7bb8d9… | 2018-07-22 |
About APT-C-27
Android spyware attributed to the Goldmouse group (ETDA tracks it as APT-C-27). Identification rests on a four-part manifest fingerprint (INTERNET permission, MainActivity, the deliberately misspelled SystemUpten receiver, and the NetService/NtService service). The C2 IP and port are stored as static fields in the static initializer of the PcketPrvidr (sic) / PacketProvider config class.
Signing certificate
- Subject CN
- hmza
- Issuer CN
- hmza
- Valid
- 2018-03-23 → 2043-03-17
- Fingerprint
- 0ff88fd1031138a2f72904ca3a03ea14ffeb1d5d79d1da74b50a65cd8baa8c85
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.