b3c1d5fc273d19556b09f935…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- b3c1d5fc273d19556b09f935b9b09b782b113b98a8a010ebcbb5de5bfce77e67
- MD5
- e750c27b9a4fcaa6a048d86c4d011c92
Observed
- Families
- CECbot
- First seen
- 2026-03-23
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| c2kxpjr7cux7fqrfmimsz7rtq527xauw627xrjojimt66nwxqvrqbuyd.onion | domain | — | — | CECbot | 2026-03-23 |
Signing certificate
- Subject CN
- System Update
- Issuer CN
- System Update
- Fingerprint
- fd46caca706cb70e3cdb222f23c4c99ac379b355cee60a256867430cdbd506b7
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About CECbot
Android TV box DDoS botnet - the operational successor to Katana by the same operator, but a clean-sheet Android app instead of a Mirai ELF: Java C2 layer, native JNI attack engine (11 DDoS methods incl. HTTP/2 + dynamic TLS), Curve25519 + Ed25519 + ChaCha20-Poly1305 C2 encryption, 9 persistence layers, and the first documented malware to weaponize HDMI-CEC. It maps the victim's home network (ICMP sweep + ARP correlation) and doubles as a residential proxy exit node. Bootstrap C2 strings are XOR-encrypted in the DEX; clearnet C2 domains are pushed at runtime, with a Tor .onion fallback.