internetwideband.com/user/

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:17:41

Registration

Registrar
Dynadot Inc
Registered
2023-02-16T14:37:43Z
Expires
2027-02-16T14:37:43Z

DNS

Resolves to
34.229.166.50
Nameservers
NS1.CSOF.NET, NS2.CSOF.NET, NS3.CSOF.NET, NS4.CSOF.NET
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
StrongPity fd1aac87399a… C2 2021-05-24

Attributed to: StrongPity

About StrongPity

**StrongPity** (aka **Promethium** / APT-C-41) is a long-running espionage actor known for watering-hole distribution of trojanized legitimate installers. Its Android branch, documented by ESET in 2023, ships a backdoored build of a real app (for example Shagle video-chat / Telegram-style apps) whose modular malicious component activates when a matching C2 is reachable. It harvests call logs, SMS, contacts, device and location data and files, records calls and enumerates installed apps, uploading to attacker infrastructure (internetwideband.com, networktopologymaps.com, www.upeg-system-app.com). Historically associated with Turkey/Syria-nexus targeting. APT / state-aligned.

Signing certificate

Subject CN
Elizabeth Mckinsen
Issuer CN
Elizabeth Mckinsen
Valid
2020-07-16 → 2045-07-10
Fingerprint
da944f2879dcb7f7061754f3cec1d59da1eabb78e6b1ba96cfd5daf0acad029f

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.