fir-e9e7b-default-rtdb.firebaseio.com

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-05T10:38:17

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
34.120.160.131, 34.120.206.254, 35.190.39.113, 35.201.97.85
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
SurxRat e48d586288b4… C2 2026-02-18
SurxRat f1350b9bc3b4… C2 2026-02-19
SurxRat 029c00fabe5d… C2 2026-02-21

About SurxRat

**SurxRat** is an Android RAT of the **ArsinkRAT** lineage (Cyble, Feb 2026), distributed under adult-content lures such as Hot51live (package com.sisurya.surxratv2). It abuses Accessibility services and requests about 40 permissions including SMS and RECEIVE_BOOT_COMPLETED, and ships a screen-locker component. Command-and-control runs over a Firebase Realtime Database (fir-e9e7b, surya-e2284 and xrat-sisurya projects). The internal marker string ArsinkRAT identifies the builder.

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2008-02-29 → 2035-07-17
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.