sukhdev001-68bfd-default-rtdb.firebaseio.com
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-05T11:13:23
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 34.120.160.131, 34.120.206.254, 35.190.39.113, 35.201.97.85
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| HDFC eChallan RAT | 526657e1fc1d… | C2 | 2026-07-31 |
| HDFC eChallan RAT | 20e41f8c7d50… | C2 | 2026-10-04 |
About HDFC eChallan RAT
India-targeted netbanking RAT distributed with a fake RTO traffic e-challan ("eChallan") lure impersonating HDFC. A three-stage packer (XOR + AES-CBC + gunzip, loaded via InMemoryDexClassLoader with an on-device self-signing installer) drops an SMS-stealing banking trojan that harvests netbanking/UPI/card credentials and OTP SMS. Stolen data is exfiltrated to attacker Firebase Realtime Database instances; a bundled VpnService routes device DNS through attacker resolvers (seen as IP indicators such as 108.74.33.9 and 201.92.30.6).
Signing certificate
- Subject CN
- Deepak Developers Pvt Ltd
- Issuer CN
- Deepak Developers Pvt Ltd
- Valid
- 2026-09-09 → 2054-01-25
- Fingerprint
- ee10e8d1271bde022e3fd21bf381f6f1261447ee465bb8f0df270830d6314283
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.