binarypanel.duckdns.org/api/device/auth
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:32:23
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 187.127.130.166
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Telegram Dropper (provisional) | 6a0e9b4ac963… | C2 | 2026-10-06 |
About Telegram Dropper (provisional)
Android banking-malware dropper that leans on commodity cloud services for delivery and control. It pulls second-stage configuration/payloads and exfiltrates data through the Telegram Bot API (api.telegram.org) and t.me channels, with Firebase (Realtime Database / Storage) and DuckDNS hosts (e.g. binarypanel.duckdns.org) used as fallback C2/staging. Family label provisional.
Signing certificate
- Subject CN
- QA Team
- Issuer CN
- QA Team
- Valid
- 2023-03-07 → 2050-07-23
- Fingerprint
- 1431eedaa27b30fd846283f083e52a5fa40c0261e1a039a337a37174d699e750
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.