20e41f8c7d507547f74f4f2c…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
108.74.33.9, 201.92.30.6, https://sukhdev001-68bfd-default-rtdb.firebaseio.com.Identification
- SHA-256
- 20e41f8c7d507547f74f4f2c38bef996dfeb2927554d55ad7b48c9b9fce418b1
- MD5
- 3a68ad8798c5a0b2dddd1009ec7faa3b
Observed
- Families
- HDFC eChallan RAT
- First seen
- 2026-10-04
APK metadata
Summary
- Type
- Android · APK
- Package
- org.bharatpe.connect.c5ca100e4
- Main activity
- org.bharatpe.connect.MainActivity
- Internal version
- 2489
- Displayed version
- 8.9.72
- Min SDK
- 26
- Target SDK
- 34
Signing certificate
- Valid from
- 2026-09-09 05:52:04
- Valid to
- 2054-01-25 05:52:04
- Serial
- 68de5d2583a71b3c
- Thumbprint
- 257eb348a98e060b01270fdf43dfbd96f8cc7628
- Subject
- C:IN, CN:Deepak Developers Pvt Ltd, L:Kolkata, O:Developers, ST:Karnataka, OU:Vikram Apps
- Issuer
- C:IN, CN:Deepak Developers Pvt Ltd, L:Kolkata, O:Developers, ST:Karnataka, OU:Vikram Apps
Permissions (8)
Intent filters - actions
Unpacked payload
The real payload hidden inside the packer, recovered by unwrapping the sample (3-stage eChallan packer (final banker APK)). This is the actual capability set the malware runs with - the APK metadata above is only the decoy loader shell.
Summary
- Package
- in.hdfc.platform
- Main activity
- -
- Internal version
- 1
- Displayed version
- 1.0
- Min SDK
- 24
- Target SDK
- 33
Signing certificate
- Valid from
- 2026-09-09 05:51:48
- Valid to
- 2054-01-25 05:51:48
- Serial
- b06489d9539cb1e7
- Thumbprint
- 1371575f9fdc10ac124af450aff67614bd5f9b17
- Subject
- C:IN, CN:Nikhil Developers Pvt Ltd, L:Kolkata, O:Solutions, ST:Gujarat, OU:Vikram Apps
- Issuer
- C:IN, CN:Nikhil Developers Pvt Ltd, L:Kolkata, O:Solutions, ST:Gujarat, OU:Vikram Apps
Permissions (25)
Intent filters - actions
C2 configuration (3)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| sukhdev001-68bfd-default-rtdb.firebaseio.com | domain | - | https | HDFC eChallan RAT | 2026-10-04 |
| 108.74.33.9 | ip | - | - | HDFC eChallan RAT | 2026-10-04 |
| 201.92.30.6 | ip | - | - | HDFC eChallan RAT | 2026-10-04 |
Signing certificate
- Subject CN
- Deepak Developers Pvt Ltd
- Issuer CN
- Deepak Developers Pvt Ltd
- Fingerprint
- ee10e8d1271bde022e3fd21bf381f6f1261447ee465bb8f0df270830d6314283
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About HDFC eChallan RAT
India-targeted netbanking RAT distributed with a fake RTO traffic e-challan ("eChallan") lure impersonating HDFC. A three-stage packer (XOR + AES-CBC + gunzip, loaded via InMemoryDexClassLoader with an on-device self-signing installer) drops an SMS-stealing banking trojan that harvests netbanking/UPI/card credentials and OTP SMS. Stolen data is exfiltrated to attacker Firebase Realtime Database instances; a bundled VpnService routes device DNS through attacker resolvers (seen as IP indicators such as 108.74.33.9 and 201.92.30.6).