c2kxpjr7cux7fqrfmimsz7rtq527xauw627xrjojimt66nwxqvrqbuyd.onion
domainTracked by C2 Tracker Ā· Whois queried 2026-10-04T15:03:46
Registration
- Registrar
- ā
- Registered
- ā
- Expires
- ā
DNS
- Resolves to
- ā
- Nameservers
- ā
- Status
- ā
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| CECbot | b3c1d5fc273d⦠| 2026-03-23 |
| CECbot | 2152b98a832c⦠| 2026-09-24 |
About CECbot
Android TV box DDoS botnet - the operational successor to Katana by the same operator, but a clean-sheet Android app instead of a Mirai ELF: Java C2 layer, native JNI attack engine (11 DDoS methods incl. HTTP/2 + dynamic TLS), Curve25519 + Ed25519 + ChaCha20-Poly1305 C2 encryption, 9 persistence layers, and the first documented malware to weaponize HDMI-CEC. It maps the victim's home network (ICMP sweep + ARP correlation) and doubles as a residential proxy exit node. Bootstrap C2 strings are XOR-encrypted in the DEX; clearnet C2 domains are pushed at runtime, with a Tor .onion fallback.
Signing certificate
- Subject CN
- Debug
- Issuer CN
- Debug
- Valid
- 2026-03-16 ā 2053-08-01
- Fingerprint
- c1e2b02373e696fbfb57a0688edf9669c5f19aa780a1387c82b4931f87038ffa
Other samples signed with this certificate? That's a lead worth checking ā but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.