sgbx.online
domain C2Tracked by C2 Tracker · Whois queried never
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- -
- Nameservers
- -
- Status
- -
Observed in malware
About Malaysian FPX Bank Phish (provisional)
Malaysia-targeted banking-scam cluster (NetbyteSec, 2022) built on a SoloDroid eCommerce app template and distributed through fake lure apps — Maid4u, KleanHouz, MyPetronas, cleaning-service and island-travel apps (packages com.app.homecleaning, com.app.islandtravel, …). The APK loads a fake FPX bank-selection page (assets/FPX.html, or assets/bank.html with per-bank asset folders in sibling builds that target AU/US banks) in a WebView; entered online-banking credentials are POSTed by assets/post.js to an attacker PHP endpoint (/post.php), card data by a ccsend script, and order / victim info to the SoloDroid backend (/<agent>/api/api.php). A static SMS receiver (MyReciever) forwards incoming SMS to a separate C2 host as GET query parameters. Observed C2 roles: credential exfil (e.g. e12345.online, gpost996.online /post.php), order API (lapks.online) and SMS exfil (sgbx.online); hosts rotate across builds and are recovered from those sinks. Provisional bucket pending formal attribution.
Signing certificate
- Subject CN
- -
- Issuer CN
- -
- Valid
- 2016-09-23 → 3015-01-25
- Fingerprint
- 022a1ed9feb0e6c9826df99c58350b7789a71ad51f142f40449f91d58c0278c1
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.