internetwideband.com/user/
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:17:41
Registration
- Registrar
- Dynadot Inc
- Registered
- 2023-02-16T14:37:43Z
- Expires
- 2027-02-16T14:37:43Z
DNS
- Resolves to
- 34.229.166.50
- Nameservers
- NS1.CSOF.NET, NS2.CSOF.NET, NS3.CSOF.NET, NS4.CSOF.NET
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| StrongPity | fd1aac87399a… | C2 | 2021-05-24 |
Attributed to: StrongPity
About StrongPity
**StrongPity** (aka **Promethium** / APT-C-41) is a long-running espionage actor known for watering-hole distribution of trojanized legitimate installers. Its Android branch, documented by ESET in 2023, ships a backdoored build of a real app (for example Shagle video-chat / Telegram-style apps) whose modular malicious component activates when a matching C2 is reachable. It harvests call logs, SMS, contacts, device and location data and files, records calls and enumerates installed apps, uploading to attacker infrastructure (internetwideband.com, networktopologymaps.com, www.upeg-system-app.com). Historically associated with Turkey/Syria-nexus targeting. APT / state-aligned.
Signing certificate
- Subject CN
- Elizabeth Mckinsen
- Issuer CN
- Elizabeth Mckinsen
- Valid
- 2020-07-16 → 2045-07-10
- Fingerprint
- da944f2879dcb7f7061754f3cec1d59da1eabb78e6b1ba96cfd5daf0acad029f
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.