185.252.215.129:8763
ipTracked by C2 Tracker · Whois queried 2026-10-04T20:44:31
Network
- Network
- MD-HOSTING-20210910
- CIDR
- 185.252.215.0/24
- Country
- DE
Contact
- Handle
- 185.252.215.0 - 185.252.215.255
- Abuse
- [email protected]
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| DCHSpy | aa656a243d20… | 2025-06-19 |
| DCHSpy | 162ce2ad2611… | 2025-07-02 |
| DCHSpy | 48d1fd4ed521… | 2025-07-21 |
| DCHSpy | a4913f52bd90… | 2025-07-21 |
Attributed to: MuddyWater
About DCHSpy
Android surveillanceware leveraged by Iranian cyber espionage group MuddyWater (MOIS-linked), distributed via Telegram as fake VPN apps (EarthVPN, ComodoVPN, HideVPN) with activist/journalist targeting. Collects WhatsApp data, accounts, contacts, SMS, files, location, call logs, audio and photos; exfiltrates over SFTP. Shares infrastructure with SandStrike.
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Valid
- 2023-12-14 → 2053-12-06
- Fingerprint
- afa47e0fc07dfae6ff1216babdec4c15c0891f8b62ff3b1a064c47c3f1a5b020
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.