deploy229.cehtech.net

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T14:01:13

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
104.21.37.12, 172.67.202.102
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
UPI OTP Stealer (provisional) f720caa316e6… C2 2026-10-07

About UPI OTP Stealer (provisional)

India-targeted Android banking stealer focused on UPI (Unified Payments Interface) fraud. Delivered as a dropper, it abuses SMS access to intercept one-time passcodes and harvests UPI/banking credentials, exfiltrating them to its backend (observed at deploy229.cehtech.net). Family label provisional.

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2008-02-29 → 2035-07-17
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.