526657e1fc1d717383e11b30…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

HDFC eChallan RAT. India-targeted netbanking RAT distributed with a fake RTO traffic e-challan (“eChallan”) lure impersonating HDFC. A three-stage packer (XOR + AES-CBC + gunzip, loaded via InMemoryDexClassLoader with an on-device self-signing installer) drops an SMS-stealing banking trojan that harvests netbanking/UPI/card credentials and OTP SMS. Stolen data is exfiltrated to attacker Firebase Realtime Database instances; a bundled VpnService routes device DNS through attacker resolvers (seen as IP indicators such as 108.74.33.9 and 201.92.30.6). Indicators: https://sukhdev001-68bfd-default-rtdb.firebaseio.com, motupatlu-7638e-default-rtdb.firebaseio.com.

Recovered configuration

final_app_name
American Express
firebase_api_key
AIzaSyAKqIaiLhAGmLtBi1Xol2BStnWISKN-KLs
firebase_app_id
1:630334302013:android:e50e75fd32966898aa4754
firebase_project_id
motupatlu-7638e
firebase_rtdb
https://motupatlu-7638e-default-rtdb.firebaseio.com
firebase_sender_id
630334302013

Source: 3-stage packer: loader->VpnService installer->Firebase banker

Identification

SHA-256
526657e1fc1d717383e11b3059d8f3b2e4a2bfae7b5ab99cde62b6d7f4858834
MD5
f7aec2e5ac21c80f18e0ec483a789f48

Observed

Families
HDFC eChallan RAT
First seen
–

APK metadata

Summary

Type
Android · APK
Package
com.kotak.transfer.cf1f49ae7
Main activity
com.kotak.transfer.MainActivity
Internal version
8327
Displayed version
4.3.60
Min SDK
26
Target SDK
34

Signing certificate

Valid from
2026-07-31 08:07:48
Valid to
2053-12-16 08:07:48
Serial
4d9f9b6afe7ca60
Thumbprint
5c28b2348052f9d2436060e817904467af456953
Subject
C:IN, CN:Rohit Digital Pvt Ltd, L:Lucknow, O:Developers, ST:Tamil Nadu, OU:Deepak Apps
Issuer
C:IN, CN:Rohit Digital Pvt Ltd, L:Lucknow, O:Developers, ST:Tamil Nadu, OU:Deepak Apps

Permissions (5)

Decoy loader shell - the real permission set is under Unpacked payload below.

Activities (1)

  • com.kotak.transfer.MainActivity

Services (1)

  • com.kotak.transfer.XvziaknhWorker

Intent filters - actions

android.net.VpnService

Unpacked payload

The real payload hidden inside the packer, recovered by unwrapping the sample (3-stage eChallan packer (final banker APK)). This is the actual capability set the malware runs with - the APK metadata above is only the decoy loader shell.

Summary

Package
net.smart.monitor
Main activity
-
Internal version
1
Displayed version
7.0
Min SDK
24
Target SDK
35

Signing certificate

Valid from
2026-07-31 08:07:40
Valid to
2053-12-16 08:07:40
Serial
3c2f3cc55d0f9f26
Thumbprint
fbac88a6b12573c67ab501ff5a8068e6658ba075
Subject
C:IN, CN:Ravi Developers Pvt Ltd, L:Chennai, O:Ventures, ST:Telangana, OU:Nexus Apps
Issuer
C:IN, CN:Ravi Developers Pvt Ltd, L:Chennai, O:Ventures, ST:Telangana, OU:Nexus Apps

Permissions (16)

android.permission.ACCESS_NETWORK_STATEandroid.permission.CALL_PHONEandroid.permission.FOREGROUND_SERVICEandroid.permission.INTERNETandroid.permission.MANAGE_OWN_CALLSandroid.permission.POST_NOTIFICATIONSandroid.permission.READ_PHONE_NUMBERSandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SEND_SMSandroid.permission.WAKE_LOCKcom.google.android.c2dm.permission.RECEIVEnet.smart.monitor.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (2)

  • com.example.admin.MainActivity
  • com.google.android.gms.common.api.GoogleApiActivity

Services (9)

  • androidx.room.MultiInstanceInvalidationService
  • androidx.work.impl.background.systemalarm.SystemAlarmService
  • androidx.work.impl.background.systemjob.SystemJobService
  • androidx.work.impl.foreground.SystemForegroundService
  • com.example.admin.services.MyFirebaseMessagingService
  • com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
  • com.google.firebase.components.ComponentDiscoveryService
  • com.google.firebase.messaging.FirebaseMessagingService

Receivers (13)

  • androidx.profileinstaller.ProfileInstallReceiver
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
  • androidx.work.impl.background.systemalarm.RescheduleReceiver
  • androidx.work.impl.diagnostics.DiagnosticsReceiver
  • androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
  • com.example.admin.receivers.BootReceiver
  • com.example.admin.receivers.SMSReceiver
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
  • com.google.firebase.iid.FirebaseInstanceIdReceiver

Providers (2)

  • androidx.startup.InitializationProvider
  • com.google.firebase.provider.FirebaseInitProvider

Intent filters - actions

android.intent.action.ACTION_POWER_CONNECTEDandroid.intent.action.ACTION_POWER_DISCONNECTEDandroid.intent.action.BATTERY_LOWandroid.intent.action.BATTERY_OKAYandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.DEVICE_STORAGE_LOWandroid.intent.action.DEVICE_STORAGE_OKandroid.intent.action.MY_PACKAGE_REPLACEDandroid.intent.action.QUICKBOOT_POWERONandroid.intent.action.TIMEZONE_CHANGEDandroid.intent.action.TIME_SETandroid.net.conn.CONNECTIVITY_CHANGEandroid.provider.Telephony.SMS_RECEIVEDandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEandroidx.work.diagnostics.REQUEST_DIAGNOSTICSandroidx.work.impl.background.systemalarm.UpdateProxiescom.google.android.c2dm.intent.RECEIVEcom.google.firebase.MESSAGING_EVENTcom.htc.intent.action.QUICKBOOT_POWERON

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
motupatlu-7638e-default-rtdb.firebaseio.com domain - - HDFC eChallan RAT –
sukhdev001-68bfd-default-rtdb.firebaseio.com domain - https HDFC eChallan RAT 2026-07-31

Signing certificate

Subject CN
Rohit Digital Pvt Ltd
Issuer CN
Rohit Digital Pvt Ltd
Fingerprint
9e7b2b9b18beab360987e41d3693784c21cf824a9672e5577f34dbfc9d919d9c

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About HDFC eChallan RAT

India-targeted netbanking RAT distributed with a fake RTO traffic e-challan ("eChallan") lure impersonating HDFC. A three-stage packer (XOR + AES-CBC + gunzip, loaded via InMemoryDexClassLoader with an on-device self-signing installer) drops an SMS-stealing banking trojan that harvests netbanking/UPI/card credentials and OTP SMS. Stolen data is exfiltrated to attacker Firebase Realtime Database instances; a bundled VpnService routes device DNS through attacker resolvers (seen as IP indicators such as 108.74.33.9 and 201.92.30.6).