dashboard.gripe/ws-relay
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:32:18
Registration
- Registrar
- Cloudflare, Inc
- Registered
- 2026-09-18T02:54:02.193Z
- Expires
- 2027-09-18T02:54:02.193Z
DNS
- Resolves to
- 104.21.62.119, 172.67.223.131
- Nameservers
- rob.ns.cloudflare.com, elaine.ns.cloudflare.com
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| NFC Relay (provisional) | 289c1cb66d01… | C2 | 2026-10-02 |
| NFC Relay (provisional) | 95dc6098c8b0… | C2 | 2026-10-04 |
| NFC Relay (provisional) | 20ba7a54e5dc… | C2 | 2026-10-04 |
| NFC Relay (provisional) | 8968d6ed113b… | C2 | 2026-10-08 |
| NFC Relay (provisional) | ba7332459a0e… | C2 | 2026-10-08 |
| NFC Relay (provisional) | 1b8e91037937… | C2 | 2026-10-10 |
| NFC Relay (provisional) | 43e62fa4bcd0… | C2 | 2026-10-10 |
| NFC Relay (provisional) | 6027091577ef… | C2 | 2026-10-10 |
| NFC Relay (provisional) | 6085ae687218… | C2 | 2026-10-11 |
| NFC Relay (provisional) | aed16211d04c… | C2 | 2026-10-11 |
| NFC Relay (provisional) | d811ea66deb1… | C2 | 2026-10-11 |
| NFC Relay (provisional) | 2b8943840529… | C2 | 2026-10-11 |
About NFC Relay (provisional)
Android NFC-relay fraud malware. Running on a victim's phone, it reads contactless bank-card/tag data over NFC and relays it in real time over a WebSocket channel to an attacker-controlled device, which replays it at a payment terminal or ATM for fraudulent transactions (an NFSkimming / "NGate"-style technique). The relay C2 (where captured card APDUs, device status and the victim 4-digit PIN are pushed over a WebSocket) is wss://dashboard.gripe/ws-relay in the current build and ws://178.236.243.8:3050 in an earlier com.example.myemulator build. dashboardcloud.app is the operator WebView phishing-UI host (loaded via webView.loadUrl with a Portuguese ?step= flow and an "Android" JS bridge) - tracked as a panel, not the relay. api.dashboardcloud.app (painelStatusUrl) is assigned in the dex but never contacted, so it is NOT recorded as a C2. One widely repackaged build (identical classes.dex; lure label "Nfc Security", package app.nfcsecurity.vault, Portuguese UI) stores its endpoints character-reversed and un-reverses them via UtilZ0Y480.decode, with source-to-sink bs.getWsUrl() -> SERVER_URL -> OkHttp newWebSocket(); it also carries a dormant base64+XOR alternate config (ws/web/api.cupworldcup.site) that the getters never use, so that is not treated as a live C2. Family label provisional.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2026-10-02 → 2054-02-17
- Fingerprint
- 2a550bfbc06d670e5ecc3c231c7dbd16180888ba9a5d3c2982726b29d5c0bacc
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.