n1cdatadev-nrfru.ondigitalocean.app
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T01:18:06
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 162.159.140.98, 172.66.0.96
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Flutter Banking Overlay (provisional) | 06a47ef466f1… | C2 | 2026-08-26 |
| Flutter Banking Overlay (provisional) | c7b6c2ea5a80… | C2 | 2026-09-07 |
| Flutter Banking Overlay (provisional) | 65fc2a875abb… | C2 | 2026-10-06 |
About Flutter Banking Overlay (provisional)
A **Flutter**-built Android banking trojan distributed as a betting/casino app (observed package `com.apkhadesbet`, a "hadesbet" gambling lure). Flutter apps compile their real logic to a native Dart "snapshot" inside `lib/<abi>/libapp.so` instead of to normal Java/DEX code, so both the behaviour and the C2 live in that `.so` file rather than in the usual Android code. **What it does** - Bundles a second payload APK (`assets/bound_payload.apk`) that it installs/loads. - Uses `flutter_inappwebview` (an embedded browser) to pop **fake bank-login overlays** on top of real apps and harvest credentials. Observed targeting **Canadian** institutions - RBC (`royalbank.com`), BMO (`bmodigitalbanking.com`), CIBC, Desjardins, Domino - plus the **MuchBetter** wallet (`muchbetter.com`), behind gambling lures (`hadesbet3.com`, `betonredcasinobe.com`). **How the C2 is recovered (binary-only)** The operator backend is a single hardcoded **HTTPS** base URL compiled into the Dart snapshot `libapp.so`, read directly from that file's string pool. It sits on a throwaway PaaS host (a `*.ondigitalocean.app` subdomain) and is deliberately kept separate from (a) the overlay-target **bank** domains the trojan phishes and (b) the attribution SDKs it ships (AppsFlyer / OneLink); the decoder filters those out so only the real operator backend is recorded. Family label provisional.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.