gosuvpnweb.top
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-10T07:44:23
Registration
- Registrar
- Openprovider
- Registered
- 2026-10-02T10:05:45.0Z
- Expires
- 2027-10-02T10:05:45.0Z
DNS
- Resolves to
- 213.171.24.73
- Nameservers
- elly.ns.cloudflare.com., jerome.ns.cloudflare.com.
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| GosuVPN Dropper (provisional) | e3832322e716… | C2 | 2026-10-08 |
About GosuVPN Dropper (provisional)
**GosuVPN Dropper (provisional)** is an Android install-time dropper (package `com.sbyvt.qodevfkr`; REQUEST_INSTALL_PACKAGES, QUERY_ALL_PACKAGES, RECEIVE_BOOT_COMPLETED) hidden behind a "gosuvpn" VPN lure. The real child payload ships as an encrypted ~4.4 MB asset (`assets/jcvwjmntop.bin`, marker `.__wombat_payload__.`) and is installed as `genome.apk`/`g.apk`; the install UI is `assets/bloom.html` with a {{BLOOM_DOWNLOADS}} template and decoy store links. Dropper strings are obfuscated with StringFog (`com.github.megatronking.stringfog.xor`, repeating-key XOR); decoding the StringFog byte-array pairs recovers the distribution/C2 host `https://gosuvpnweb.top`. The sample also embeds a spoofed OnePlus 8 Pro build fingerprint and many decoy padding assets. C2 recovered statically via source-to-sink StringFog decode; family label provisional.
Signing certificate
- Subject CN
- com_android_nfc
- Issuer CN
- com_android_nfc
- Valid
- 2023-11-01 → 2053-11-01
- Fingerprint
- fae9122a8721d6e2a196d2224dffcf773c9127e2bb956cbddb40b009192ffdfd
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.