mproxs.info

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:17:08

Registration

Registrar
NICENIC INTERNATIONAL GROUP CO., LIMITED
Registered
2026-01-31T11:39:50.445Z
Expires
2027-01-31T11:39:50.445Z

DNS

Resolves to
104.21.34.110, 172.67.159.165
Nameservers
eoin.ns.cloudflare.com, liberty.ns.cloudflare.com
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
TaxiSpy RAT cbf0b7a742ad… C2 2026-02-19
TaxiSpy RAT 550ca70e1d0c… C2 2026-02-22
TaxiSpy RAT 610cc1ca02e3… C2 2026-02-23
TaxiSpy RAT dfe26af80da4… C2 2026-02-25
TaxiSpy RAT 9457bd1ff25c… C2 2026-02-26

About TaxiSpy RAT

**TaxiSpy** is a Russian-nexus Android banking RAT that combines SMS theft, hidden VNC remote control and overlays to run on-device fraud. It intercepts and forwards incoming SMS (OTP and bank codes), gives the operator a live VNC view/control channel to drive the infected device directly, and beacons to its C2 at mproxs.info. Used against Russian-speaking targets.

Signing certificate

Subject CN
Google Inc
Issuer CN
Google Inc
Valid
2026-02-06 → 2053-06-24
Fingerprint
e5e1a101b0d951d4114be8593fa42ff8d05eef1e2340c72914bd9ab67056ef57

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.