211.169.248.242/

ip C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:17:11

Network

Network
BORANET-KR
CIDR
211.168.0.0/14
Country
KR

Contact

Handle
211.168.0.0 - 211.171.255.255
Abuse
[email protected], [email protected]

Observed in malware

FamilySample SHA-256RoleFirst seen
FakeSpy 4c41274f3927… C2 2018-11-19

About FakeSpy

Android spyware posing as legitimate postal/ delivery-service apps, exfiltrating SMS and contact data to a PHP panel. The panel base URL is an http:// const-string in the MyService$ReThread (or MeService$ReThread) run() loop; some builds instead carry CONFIG_URL / IP_ADDRESS / LOGS_URL as static field values of Lorg/red/cute/common/Constant;.

Signing certificate

Subject CN
oeofjkdk
Issuer CN
oeofjkdk
Valid
2018-11-18 → 2043-11-12
Fingerprint
1429bb5704ae437a33f7f591f9cd05d761db3e103617a097e3a5128b52a88d36

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.