demg-5b242-default-rtdb.firebaseio.com

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-11T02:05:58

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
34.120.160.131, 34.120.206.254, 35.190.39.113, 35.201.97.85
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
Nvcgehin Banker Dropper (provisional) 271eba64c973… C2 2026-10-10

About Nvcgehin Banker Dropper (provisional)

Multi-stage Android banking-trojan dropper protected by the bespoke ‘nvcgehin’ packer — a per-build polymorphic, pure-Java crypter (no native library) that nests several AES-256-GCM layers with HKDF-derived keys to conceal and unpack a child banker DEX at runtime. The unpacked banker reports to Firebase Realtime Database instances (observed: alex-538c5, hukum-da57e, demg-5b242, maha-f60b0) and to a Telegram bot (bot token + chat id). C2s were not taken from static config: they were recovered by walking the packer’s decryption chain down to the child payload and confirming the exfil/command sinks that consume them. Provisional bucket pending formal attribution.

Signing certificate

Subject CN
Vida Remote
Issuer CN
Vida Remote
Valid
2026-07-31 → 2056-07-23
Fingerprint
48c1124e90e9d9e3090ebb65da10ca9d918df82de1bb56e65b82ee041b4975d7

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.