6a0e9b4ac963ce451d92f373…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
https://binarypanel.duckdns.org/api/device/auth, https://oiigigge-default-rtdb.firebaseio.com, https://predictor-6b5a5.firebasestorage.app.Recovered configuration
Identification
- SHA-256
- 6a0e9b4ac963ce451d92f373146f040f1caf145a3d59f4b625ff009968240b8c
- MD5
- dad480cb24dc207da21bbfbdca6eaefa
Observed
- Families
- Telegram Dropper (provisional)
- First seen
- 2026-10-06
APK metadata
Summary
- Type
- Android · APK
- Package
- com.sec.android.app.finance.irara23
- Main activity
- gjh.bhnn.yuiv.Fqut9c853xz
- Internal version
- 105
- Displayed version
- 2.9.62
- Min SDK
- 24
- Target SDK
- 37
Signing certificate
- Valid from
- 2023-03-07 10:06:56
- Valid to
- 2050-07-23 10:06:56
- Serial
- 354afd4b
- Thumbprint
- 4b29afc23e39fd541aaaf2fd16b0c90c9d9ea0bb
- Subject
- C:US, CN:QA Team, L:Palo Alto, O:Mattermost Inc., ST:California, OU:qa
- Issuer
- C:US, CN:QA Team, L:Palo Alto, O:Mattermost Inc., ST:California, OU:qa
Permissions (605)
Activities (2)
- gjh.bhnn.yuiv.Fqut9c853xz
- gjh.bhnn.yuiv.ui.Kz8echyeu98s40
Services (1)
- gjh.bhnn.yuiv.vpn.Xgqbn3mvym2b
Receivers (3)
- androidx.profileinstaller.ProfileInstallReceiver
- gjh.bhnn.yuiv.installer.Gajl18rcufhsqts
- gjh.bhnn.yuiv.installer.Vs7sbvt65xs7a
Providers (2)
- androidx.core.content.FileProvider
- androidx.startup.InitializationProvider
Intent filters - actions
C2 configuration (3)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| binarypanel.duckdns.org/api/device/auth | domain | - | https | Telegram Dropper (provisional) | 2026-10-06 |
| oiigigge-default-rtdb.firebaseio.com | domain | - | https | Telegram Dropper (provisional) | 2026-10-06 |
| predictor-6b5a5.firebasestorage.app | domain | - | https | Telegram Dropper (provisional) | 2026-10-06 |
Signing certificate
- Subject CN
- QA Team
- Issuer CN
- QA Team
- Fingerprint
- 1431eedaa27b30fd846283f083e52a5fa40c0261e1a039a337a37174d699e750
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Telegram Dropper (provisional)
Android banking-malware dropper that leans on commodity cloud services for delivery and control. It pulls second-stage configuration/payloads and exfiltrates data through the Telegram Bot API (api.telegram.org) and t.me channels, with Firebase (Realtime Database / Storage) and DuckDNS hosts (e.g. binarypanel.duckdns.org) used as fallback C2/staging. Family label provisional.