sonxndskt.3n7wj.com/ws/device
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:17:44
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- -
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| RedHook | cc628150428e… | C2 | 2026-08-13 |
About RedHook
**RedHook** is an Android banking trojan / RAT (reported targeting Vietnamese users) that abuses Accessibility services for overlay credential capture, keylogging and remote control. Its C2 lives on a single registrable domain fronting many API subdomains (the *.3n7wj.com cluster: api, skt, sktv, sonxndskt, dlkxnxapi, eonxjdsktv) used for command polling and exfiltration.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2026-08-09 → 2053-12-25
- Fingerprint
- 4c23409cd9f13fe8d453f15df2e70df74ec086fd90a5d2b37df9dd3090ff4254
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.