minipeka.info/down/
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-10T07:43:59
Registration
- Registrar
- Global Domain Group LLC
- Registered
- 2026-04-26T10:37:01.897Z
- Expires
- 2027-04-26T10:37:01.897Z
DNS
- Resolves to
- 185.203.240.187
- Nameservers
- ns1.globaldomaingroup.com, ns2.globaldomaingroup.com
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Store Lure Dropper (provisional) | d6aeeba8aa65… | C2 | 2026-08-26 |
About Store Lure Dropper (provisional)
**Store Lure Dropper** (provisional) is a Russian-nexus Android dropper that disguises itself as an app-store / app-install page to trick victims into side-loading a second-stage payload. The lure and install flow phone home to minipeka.info. Provisional label, classified by delivery behaviour (phishing store lure plus install-packages dropper).
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.