vip-panel-krish-developer.42web.io/
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:39
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 185.27.134.59
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| SMS Forwarder (provisional) | c25f721eba1d… | C2 | 2026-08-17 |
| SMS Forwarder (provisional) | 9354d54a1c6b… | C2 | 2026-08-17 |
| SMS Forwarder (provisional) | 3dbbc7a01101… | C2 | 2026-09-20 |
About SMS Forwarder (provisional)
A broad class of simple **Android OTP/SMS stealers** (packages like `com.example.smsforwarder`) that register a `RECEIVE_SMS` receiver and exfiltrate every incoming message - one-time passwords above all - to the operator. Two exfil channels are seen in the wild and both are recovered binary-only: - **Telegram bot** - the message is sent through the Telegram Bot API; the bot token(s) (`<id>:<authstring>`) and target `chat_id` are hardcoded, so `api.telegram.org` is the C2 and the **bot token is the actionable IOC** (report the bot, block the channel). A single build often carries more than one bot token (primary + fallback). - **HTTP drop** - the message is POSTed to a hardcoded endpoint, typically a bare IP with an `/sms` / `ingest` PHP handler. Family label is provisional - these are commodity builders, not a single actor.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.