baccha-a07d9-default-rtdb.firebaseio.com

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:17:04

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
34.120.160.131, 34.120.206.254, 35.190.39.113, 35.201.97.85
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
HDFC eChallan RAT 021d92dd0026… C2 2026-07-23

About HDFC eChallan RAT

India-targeted netbanking RAT distributed with a fake RTO traffic e-challan ("eChallan") lure impersonating HDFC. A three-stage packer (XOR + AES-CBC + gunzip, loaded via InMemoryDexClassLoader with an on-device self-signing installer) drops an SMS-stealing banking trojan that harvests netbanking/UPI/card credentials and OTP SMS. Stolen data is exfiltrated to attacker Firebase Realtime Database instances; a bundled VpnService routes device DNS through attacker resolvers (seen as IP indicators such as 108.74.33.9 and 201.92.30.6).

Signing certificate

Subject CN
f07ab108b4744256
Issuer CN
f07ab108b4744256
Valid
2026-07-23 → 2053-12-08
Fingerprint
e477e7c9f338e9bef0f13a89c29a8453615e71ad2b18e6cf5e8bb2808e7003e6

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.