vip-panel-krish-developer.42web.io/

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:39

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
185.27.134.59
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
SMS Forwarder (provisional) c25f721eba1d… C2 2026-08-17
SMS Forwarder (provisional) 9354d54a1c6b… C2 2026-08-17
SMS Forwarder (provisional) 3dbbc7a01101… C2 2026-09-20

About SMS Forwarder (provisional)

A broad class of simple **Android OTP/SMS stealers** (packages like `com.example.smsforwarder`) that register a `RECEIVE_SMS` receiver and exfiltrate every incoming message - one-time passwords above all - to the operator. Two exfil channels are seen in the wild and both are recovered binary-only: - **Telegram bot** - the message is sent through the Telegram Bot API; the bot token(s) (`<id>:<authstring>`) and target `chat_id` are hardcoded, so `api.telegram.org` is the C2 and the **bot token is the actionable IOC** (report the bot, block the channel). A single build often carries more than one bot token (primary + fallback). - **HTTP drop** - the message is POSTed to a hardcoded endpoint, typically a bare IP with an `/sms` / `ingest` PHP handler. Family label is provisional - these are commodity builders, not a single actor.

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2008-02-29 → 2035-07-17
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.