gosuvpnweb.top

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-10T07:44:23

Registration

Registrar
Openprovider
Registered
2026-10-02T10:05:45.0Z
Expires
2027-10-02T10:05:45.0Z

DNS

Resolves to
213.171.24.73
Nameservers
elly.ns.cloudflare.com., jerome.ns.cloudflare.com.
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
GosuVPN Dropper (provisional) e3832322e716… C2 2026-10-08

About GosuVPN Dropper (provisional)

**GosuVPN Dropper (provisional)** is an Android install-time dropper (package `com.sbyvt.qodevfkr`; REQUEST_INSTALL_PACKAGES, QUERY_ALL_PACKAGES, RECEIVE_BOOT_COMPLETED) hidden behind a "gosuvpn" VPN lure. The real child payload ships as an encrypted ~4.4 MB asset (`assets/jcvwjmntop.bin`, marker `.__wombat_payload__.`) and is installed as `genome.apk`/`g.apk`; the install UI is `assets/bloom.html` with a {{BLOOM_DOWNLOADS}} template and decoy store links. Dropper strings are obfuscated with StringFog (`com.github.megatronking.stringfog.xor`, repeating-key XOR); decoding the StringFog byte-array pairs recovers the distribution/C2 host `https://gosuvpnweb.top`. The sample also embeds a spoofed OnePlus 8 Pro build fingerprint and many decoy padding assets. C2 recovered statically via source-to-sink StringFog decode; family label provisional.

Signing certificate

Subject CN
com_android_nfc
Issuer CN
com_android_nfc
Valid
2023-11-01 → 2053-11-01
Fingerprint
fae9122a8721d6e2a196d2224dffcf773c9127e2bb956cbddb40b009192ffdfd

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.