10.0.2.15:8080
ip C2 template placeholderTracked by C2 Tracker · Updated as of 2026-10-08 · Whois queried 2026-10-07T08:17:40
Network
- Network
- -
- CIDR
- -
- Country
- -
Contact
- Handle
- -
- Abuse
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| SpyMax (provisional) | 01e64248c29f… | C2 | 2025-02-11 |
| AndroRat | 0a5363b89cdb… | C2 | 2026-09-28 |
| Metasploit | c6ad7e66f7fb… | C2 | 2026-10-08 |
About AndroRat
One of the oldest open-source Android RATs (first released ~2012), still repackaged into fresh campaigns. Classic builds carry the my.app.client package; repackaged flavors ship under innocuous package names and app titles like "Google Service Framework".
About Metasploit
Android payloads generated by Metasploit / msfvenom (meterpreter and command stages), running under the package com.metasploit.stage. The payload dials back to LHOST:LPORT, which is the C2. Two config formats appear in the wild. In the older/plain format the transport URL (tcp://, ssl:// or https://LHOST:LPORT) is a const-string in the DEX. In the newer format the stage carries a protobuf TransportConfig in the static byte array Payload.a, parsed by an embedded protobuf-lite runtime (com.metasploit.a); that array is XOR-masked with a per-build 4-byte key, and because the buffer is zero-padded the leading bytes leak the key, so XORing the array by key[i mod 4] recovers the protobuf and its transport URL. Many samples are red-team or test builds pointing at LAN, loopback or 0.0.0.0 addresses (recorded verbatim); live ones use public IPs or tunnel fronts such as *.lhr.life (localhost.run) and *.loca.lt (localtunnel).
About SpyMax (provisional)
**SpyMax (provisional)** is a commercial Android spyware/RAT of the SpyNote family (SpyMax lineage), built from a public builder and repackaged under game and utility lures (for example "Proxy hs" and "Google Translate") with randomised package and class names per build. The C2 is stored as base64 static fields initializeService.ClientHost and ClientPort (decoded at runtime by a Base64 helper) and reached as a raw TCP socket to ClientHost:ClientPort; builds also carry a ConnectionKey. It runs a full surveillance stack: live screen streaming via MediaProjection (Screen_Sender / SecondarySocket), live camera capture (CameraHandler socket), keylogging (KeyboardService), an Accessibility service (AccessService), a FloatingView overlay, geolocation (LocationService plus Yandex static-maps), SMS theft and app installation (REQUEST_INSTALL_PACKAGES). Some builds ship a LAN/test C2 (for example 192.168.18.46) left by the operator or a red-teamer. Family label provisional.
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Valid
- 2016-10-23 → 2044-03-10
- Fingerprint
- 1e08a903aef9c3a721510b64ec764d01d3d094eb954161b62544ea8f187b5953
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.