27.124.3.165:8554/live/

ip not resolving

Tracked by C2 Tracker · Whois queried 2026-10-04T18:42:43

Network

Network
CTG124-2-HK
CIDR
27.124.2.0/23
Country
HK

Contact

Handle
27.124.2.0 - 27.124.7.255
Abuse
[email protected], [email protected]

Observed in malware

FamilySample SHA-256First seen
MMRat 68abbf83f53f… 2023-06-19

About MMRat

Android banking trojan carrying out bank fraud via fake app stores, abusing the RTSP stack for its C2 channel: the endpoints are rtsp:// const-strings in the <init> of the short helper classes under com/mm/user/utils/. Identified by the com.mm.user.ui.activity.WebViewActivity activity.

Signing certificate

Subject CN
123456
Issuer CN
123456
Valid
2023-04-05 → 2048-03-29
Fingerprint
e4e4b72303db373702d41505a1203eb31f5e759bab62a4c2139cc69c6baf8974

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.