hukum-da57e-default-rtdb.asia-southeast1.firebasedatabase.app
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-11T02:05:58
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 35.186.236.207
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Nvcgehin Banker Dropper (provisional) | ded45838e957… | C2 | 2026-10-10 |
About Nvcgehin Banker Dropper (provisional)
Multi-stage Android banking-trojan dropper protected by the bespoke ‘nvcgehin’ packer — a per-build polymorphic, pure-Java crypter (no native library) that nests several AES-256-GCM layers with HKDF-derived keys to conceal and unpack a child banker DEX at runtime. The unpacked banker reports to Firebase Realtime Database instances (observed: alex-538c5, hukum-da57e, demg-5b242, maha-f60b0) and to a Telegram bot (bot token + chat id). C2s were not taken from static config: they were recovered by walking the packer’s decryption chain down to the child payload and confirming the exfil/command sinks that consume them. Provisional bucket pending formal attribution.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.