gpost996.online

domain C2 not resolving

Tracked by C2 Tracker · Whois queried never

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
-
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
Malaysian FPX Bank Phish (provisional) 798d24d67710… C2 2022-09-11
Malaysian FPX Bank Phish (provisional) 02fe7aa46346… C2 2022-09-13
Malaysian FPX Bank Phish (provisional) 954cf238d370… C2 2022-09-15
Malaysian FPX Bank Phish (provisional) b98cfefe2bad… C2 2022-09-30

About Malaysian FPX Bank Phish (provisional)

Malaysia-targeted banking-scam cluster (NetbyteSec, 2022) built on a SoloDroid eCommerce app template and distributed through fake lure apps — Maid4u, KleanHouz, MyPetronas, cleaning-service and island-travel apps (packages com.app.homecleaning, com.app.islandtravel, …). The APK loads a fake FPX bank-selection page (assets/FPX.html, or assets/bank.html with per-bank asset folders in sibling builds that target AU/US banks) in a WebView; entered online-banking credentials are POSTed by assets/post.js to an attacker PHP endpoint (/post.php), card data by a ccsend script, and order / victim info to the SoloDroid backend (/<agent>/api/api.php). A static SMS receiver (MyReciever) forwards incoming SMS to a separate C2 host as GET query parameters. Observed C2 roles: credential exfil (e.g. e12345.online, gpost996.online /post.php), order API (lapks.online) and SMS exfil (sgbx.online); hosts rotate across builds and are recovered from those sinks. Provisional bucket pending formal attribution.

Signing certificate

Subject CN
-
Issuer CN
-
Valid
2016-09-23 → 3015-01-25
Fingerprint
022a1ed9feb0e6c9826df99c58350b7789a71ad51f142f40449f91d58c0278c1

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.