173.249.50.34:12182

ip C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-10T07:44:01

Network

Network
CONTABO
CIDR
173.249.32.0/19
Country
DE

Contact

Handle
173.249.32.0 - 173.249.63.255
Abuse
[email protected]

Observed in malware

FamilySample SHA-256RoleFirst seen
CapraRat 1a425c66fb78… C2 2020-10-21

About CapraRat

Android RAT used by Transparent Tribe (a.k.a. APT36, Earth Karkaddan, ProjectM) against targets in India and Pakistan. Typically single-application spyware delivered via social engineering, with screen capture, call/SMS exfiltration and audio recording.

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Valid
2018-11-27 → 2048-11-19
Fingerprint
a8140f73130740106b48101c218989e0decd9755748661e01e5e8bc5eb314391

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.