validate.bnhmo.com/validate

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-10T15:39:55

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
104.21.69.9, 172.67.202.143
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
BNHMO SMS Trojan (provisional) 4fea1de728d0… C2 2026-10-10

About BNHMO SMS Trojan (provisional)

**BNHMO SMS Trojan (provisional)** is an Android SMS trojan ("Touch It Rikka", package `com.luk.vlu`) that requests SEND_SMS and SYSTEM_ALERT_WINDOW and sends premium/WAP messages via `SmsManager.sendTextMessage`. A check-in/validation endpoint `https://validate.bnhmo.com/validate` is invoked from a networking worker thread (`La/d0;->run`), with the host recovered as a plaintext string wired into that worker (source-to-sink). The package carries a Play reference to `com.modobom.game.defense` (Modobom monetization network), but attribution to Modobom is not confirmed. Family label provisional.

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2008-02-29 → 2035-07-17
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.