mproxs.info
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:17:08
Registration
- Registrar
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Registered
- 2026-01-31T11:39:50.445Z
- Expires
- 2027-01-31T11:39:50.445Z
DNS
- Resolves to
- 104.21.34.110, 172.67.159.165
- Nameservers
- eoin.ns.cloudflare.com, liberty.ns.cloudflare.com
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| TaxiSpy RAT | cbf0b7a742ad… | C2 | 2026-02-19 |
| TaxiSpy RAT | 550ca70e1d0c… | C2 | 2026-02-22 |
| TaxiSpy RAT | 610cc1ca02e3… | C2 | 2026-02-23 |
| TaxiSpy RAT | dfe26af80da4… | C2 | 2026-02-25 |
| TaxiSpy RAT | 9457bd1ff25c… | C2 | 2026-02-26 |
About TaxiSpy RAT
**TaxiSpy** is a Russian-nexus Android banking RAT that combines SMS theft, hidden VNC remote control and overlays to run on-device fraud. It intercepts and forwards incoming SMS (OTP and bank codes), gives the operator a live VNC view/control channel to drive the infected device directly, and beacons to its C2 at mproxs.info. Used against Russian-speaking targets.
Signing certificate
- Subject CN
- Google Inc
- Issuer CN
- Google Inc
- Valid
- 2026-02-06 → 2053-06-24
- Fingerprint
- e5e1a101b0d951d4114be8593fa42ff8d05eef1e2340c72914bd9ab67056ef57
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.