fir-e9e7b-default-rtdb.firebaseio.com
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-05T10:38:17
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 34.120.160.131, 34.120.206.254, 35.190.39.113, 35.201.97.85
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| SurxRat | e48d586288b4… | C2 | 2026-02-18 |
| SurxRat | f1350b9bc3b4… | C2 | 2026-02-19 |
| SurxRat | 029c00fabe5d… | C2 | 2026-02-21 |
About SurxRat
**SurxRat** is an Android RAT of the **ArsinkRAT** lineage (Cyble, Feb 2026), distributed under adult-content lures such as Hot51live (package com.sisurya.surxratv2). It abuses Accessibility services and requests about 40 permissions including SMS and RECEIVE_BOOT_COMPLETED, and ships a screen-locker component. Command-and-control runs over a Firebase Realtime Database (fir-e9e7b, surya-e2284 and xrat-sisurya projects). The internal marker string ArsinkRAT identifies the builder.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.