sportypointsrewards.com

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-05T10:38:03

Registration

Registrar
OwnRegistrar, Inc.
Registered
2025-12-07T10:51:01Z
Expires
2026-12-07T10:51:01Z

DNS

Resolves to
104.21.71.193, 172.67.148.40
Nameservers
ACHIEL.NS.CLOUDFLARE.COM, VERONICA.NS.CLOUDFLARE.COM
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
GlitchSpy 80af5e921cf8… C2 2026-06-16

About GlitchSpy

**GlitchSpy** is an Accessibility-abusing Android banking RAT. Using Accessibility services it performs overlay credential theft, automated UI actions and keylogging against banking and rewards apps, self-updating through benign-looking domains (mobileappupdate.com, sportypointsrewards.com) while beaconing to hard-coded operator IPs (134.255.232.216, 87.237.53.199).

Signing certificate

Subject CN
Kooooo Release
Issuer CN
Kooooo Release
Valid
2026-03-30 → 2053-08-15
Fingerprint
8e680f86bbca985104039dad318456f974aaff3667a3e805d23e492eaed7545a

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.