predictor-6b5a5.firebasestorage.app

domain C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:32:42

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
-
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
Telegram Dropper (provisional) 6a0e9b4ac963… C2 2026-10-06

About Telegram Dropper (provisional)

Android banking-malware dropper that leans on commodity cloud services for delivery and control. It pulls second-stage configuration/payloads and exfiltrates data through the Telegram Bot API (api.telegram.org) and t.me channels, with Firebase (Realtime Database / Storage) and DuckDNS hosts (e.g. binarypanel.duckdns.org) used as fallback C2/staging. Family label provisional.

Signing certificate

Subject CN
QA Team
Issuer CN
QA Team
Valid
2023-03-07 → 2050-07-23
Fingerprint
1431eedaa27b30fd846283f083e52a5fa40c0261e1a039a337a37174d699e750

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.