dwz.junwfk.com/1JcMi
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T00:58:57
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 127.0.0.1
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Script-Bot Dropper (provisional) | 8bd23d6635f1… | C2 | 2026-10-01 |
About Script-Bot Dropper (provisional)
**Script-Bot Dropper** (provisional, package com.mmtjb3) is a thin Android stub whose real logic is delivered as a hot-updated Lua/script bundle, so almost nothing malicious ships inside the APK itself. It polls an Alibaba Cloud OSS bucket (maomaotoujioben.oss-cn-hangzhou.aliyuncs.com) and a short-link resolver (dwz.junwfk.com) for its script payload and commands. Behaviour is click-fraud / automation botting driven entirely by the remotely served scripts.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.