656eee1ea18dee0fe926acc1…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

NFC Relay (provisional). Android NFC-relay fraud malware. Running on a victim’s phone, it reads contactless bank-card/tag data over NFC and relays it in real time over a WebSocket channel to an attacker-controlled device, which replays it at a payment terminal or ATM for fraudulent transactions (an NFSkimming / “NGate”-style technique). The relay C2 (where captured card APDUs, device status and the victim 4-digit PIN are pushed over a WebSocket) is wss://dashboard.gripe/ws-relay in the current build and ws://178.236.243.8:3050 in an earlier com.example.myemulator build. dashboardcloud.app is the operator WebView phishing-UI host (loaded via webView.loadUrl with a Portuguese ?step= flow and an “Android” JS bridge) - tracked as a panel, not the relay. api.dashboardcloud.app (painelStatusUrl) is assigned in the dex but never contacted, so it is NOT recorded as a C2. One widely repackaged build (identical classes.dex; lure label “Nfc Security”, package app.nfcsecurity.vault, Portuguese UI) stores its endpoints character-reversed and un-reverses them via UtilZ0Y480.decode, with source-to-sink bs.getWsUrl() -> SERVER_URL -> OkHttp newWebSocket(); it also carries a dormant base64+XOR alternate config (ws/web/api.cupworldcup.site) that the getters never use, so that is not treated as a live C2. Family label provisional. Indicators: ws://178.236.243.8:3050.

Recovered configuration

package
com.example.myemulator

Identification

SHA-256
656eee1ea18dee0fe926acc183d97d1ff6865e2b2cad9e2670eeb3f504e326c3
MD5
14eacab25abfb0a6afe95096fb532f55

Observed

Families
NFC Relay (provisional)
First seen
2026-10-07

APK metadata

Summary

Type
Android · APK
Package
com.example.myemulator
Main activity
com.example.myemulator.MainActivity
Internal version
2
Displayed version
1.1
Min SDK
21
Target SDK
35

Signing certificate

Valid from
2026-03-10 16:00:58
Valid to
2053-07-26 16:00:58
Serial
1384ab31e0493139
Thumbprint
a193514e533a0759c43f4a5ea3714f25e15ae921
Subject
C:GB, CN:David Brown, L:London, O:App Factory, ST:England, OU:Mobile Development
Issuer
C:GB, CN:David Brown, L:London, O:App Factory, ST:England, OU:Mobile Development

Permissions (4)

android.permission.ACCESS_NETWORK_STATEandroid.permission.INTERNETandroid.permission.NFCcom.example.myemulator.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (2)

  • com.example.myemulator.EmulatorActivity
  • com.example.myemulator.MainActivity

Services (1)

  • com.example.myemulator.MyHostApduService

Receivers (1)

  • androidx.profileinstaller.ProfileInstallReceiver

Providers (1)

  • androidx.startup.InitializationProvider

Intent filters - actions

android.nfc.cardemulation.action.HOST_APDU_SERVICEandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILE

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
178.236.243.8 ip 3050 ws NFC Relay (provisional) 2026-10-07

Signing certificate

Subject CN
David Brown
Issuer CN
David Brown
Fingerprint
93c6196f270594a3011378729ca996fe64789bf5a9644361a2214a67ce16c615

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About NFC Relay (provisional)

Android NFC-relay fraud malware. Running on a victim's phone, it reads contactless bank-card/tag data over NFC and relays it in real time over a WebSocket channel to an attacker-controlled device, which replays it at a payment terminal or ATM for fraudulent transactions (an NFSkimming / "NGate"-style technique). The relay C2 (where captured card APDUs, device status and the victim 4-digit PIN are pushed over a WebSocket) is wss://dashboard.gripe/ws-relay in the current build and ws://178.236.243.8:3050 in an earlier com.example.myemulator build. dashboardcloud.app is the operator WebView phishing-UI host (loaded via webView.loadUrl with a Portuguese ?step= flow and an "Android" JS bridge) - tracked as a panel, not the relay. api.dashboardcloud.app (painelStatusUrl) is assigned in the dex but never contacted, so it is NOT recorded as a C2. One widely repackaged build (identical classes.dex; lure label "Nfc Security", package app.nfcsecurity.vault, Portuguese UI) stores its endpoints character-reversed and un-reverses them via UtilZ0Y480.decode, with source-to-sink bs.getWsUrl() -> SERVER_URL -> OkHttp newWebSocket(); it also carries a dormant base64+XOR alternate config (ws/web/api.cupworldcup.site) that the getters never use, so that is not treated as a live C2. Family label provisional.