271eba64c973d8ba4004413c…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Nvcgehin Banker Dropper (provisional). Multi-stage Android banking-trojan dropper protected by the bespoke ‘nvcgehin’ packer — a per-build polymorphic, pure-Java crypter (no native library) that nests several AES-256-GCM layers with HKDF-derived keys to conceal and unpack a child banker DEX at runtime. The unpacked banker reports to Firebase Realtime Database instances (observed: alex-538c5, hukum-da57e, demg-5b242, maha-f60b0) and to a Telegram bot (bot token + chat id). C2s were not taken from static config: they were recovered by walking the packer’s decryption chain down to the child payload and confirming the exfil/command sinks that consume them. Provisional bucket pending formal attribution. Indicators: https://demg-5b242-default-rtdb.firebaseio.com, https://maha-f60b0-default-rtdb.firebaseio.com, tg://7863871516:aahjwkraboj1yia-h3x8i1ph3k6kj-az2f8.

Recovered configuration

banker_lure
PM AWAS YOJNA
banker_package
org.eastsd.westeh
dropper_package
bpcsgr.nvisncy
firebase_rtdb
demg-5b242-default-rtdb.firebaseio.com, maha-f60b0-default-rtdb.firebaseio.com
package
bpcsgr.nvisncy
telegram_bot
7863871516:AAHjwKRAboJ1yiA-h3X8i1PH3K6Kj-AZ2f8

Identification

SHA-256
271eba64c973d8ba4004413c16d1607907888ffd32db7c420770c75eeb25a0db
MD5
8b79eb86fe43319e7f0a6d44d7cf01af

Observed

Families
Nvcgehin Banker Dropper (provisional)
First seen
2026-10-10

C2 configuration (3)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

Signing certificate

Subject CN
Vida Remote
Issuer CN
Vida Remote
Fingerprint
48c1124e90e9d9e3090ebb65da10ca9d918df82de1bb56e65b82ee041b4975d7

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Nvcgehin Banker Dropper (provisional)

Multi-stage Android banking-trojan dropper protected by the bespoke ‘nvcgehin’ packer — a per-build polymorphic, pure-Java crypter (no native library) that nests several AES-256-GCM layers with HKDF-derived keys to conceal and unpack a child banker DEX at runtime. The unpacked banker reports to Firebase Realtime Database instances (observed: alex-538c5, hukum-da57e, demg-5b242, maha-f60b0) and to a Telegram bot (bot token + chat id). C2s were not taken from static config: they were recovered by walking the packer’s decryption chain down to the child payload and confirming the exfil/command sinks that consume them. Provisional bucket pending formal attribution.