172.252.173.36

ip C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:24

Network

Network
EGNL-1
CIDR
172.252.0.0/16
Country
US

Contact

Handle
NET-172-252-0-0-1
Abuse
-

Observed in malware

FamilySample SHA-256RoleFirst seen
Flutter SMS Stealer (provisional) 5a30d9fdfe55… C2 2026-10-03

About Flutter SMS Stealer (provisional)

A **Flutter**-built Android SMS/PII stealer of likely Chinese origin, distributed under social and adult-content app disguises. Flutter apps compile their real logic to a native Dart "snapshot" inside `lib/<abi>/libapp.so` rather than to ordinary Java/DEX, so both the behaviour and the C2 live in that `.so` file instead of in the usual Android code. **What it does** - Harvests **SMS messages, contacts, call logs and location** and exfiltrates them to the operator. - Ships under the stable packages `com.dataapp.data_collector` and `com.jlsw.jmy`, as well as randomly-named packages (e.g. `com.ncwtaakvv.rzpyvfqstgw`). - Some builds are additionally wrapped with the **Jiagu** commercial packer; the Flutter payload is identical once unpacked. **How the C2 is recovered (binary-only)** The command-and-control endpoint is a hardcoded **bare-IP HTTP** URL compiled directly into the Dart snapshot `libapp.so`, read out of that file's string pool. The cluster rotates across a small set of hosting IPs (observed `156.254.21.112`, `156.254.21.43`, `172.252.173.36`, `172.252.224.194`, `172.252.224.195`, `66.212.58.145`). Family label provisional.

Signing certificate

Subject CN
6U8GVA
Issuer CN
6U8GVA
Valid
2026-10-02 → 2027-11-05
Fingerprint
f8641f6d078403f25d1ac6055c4045ef306ccc721bed7760d903858e2a930f73

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.