f720caa316e62abe5b5bc69d…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
UPI OTP Stealer (provisional). India-targeted Android banking stealer focused on UPI (Unified Payments Interface) fraud. Delivered as a dropper, it abuses SMS access to intercept one-time passcodes and harvests UPI/banking credentials, exfiltrating them to its backend (observed at deploy229.cehtech.net). Family label provisional. Indicators:
https://deploy229.cehtech.net.Recovered configuration
package
com.twvcudx.heamtn.nqrp
Identification
- SHA-256
- f720caa316e62abe5b5bc69d89b76e7b704b82355e23847bd1439f2edc50af89
- MD5
- cab9f7ac767de47c84483c3cee53e576
Observed
- Families
- UPI OTP Stealer (provisional)
- First seen
- 2026-10-07
APK metadata
Summary
- Type
- Android · APK
- Package
- com.twvcudx.heamtn.nqrp
- Main activity
- com.twvcudx.heamtn.nqrp.CwonJuzks
- Internal version
- 1
- Displayed version
- 1.0
- Min SDK
- 24
- Target SDK
- 35
Signing certificate
- Valid from
- 2008-02-29 01:33:46
- Valid to
- 2035-07-17 01:33:46
- Serial
- 936eacbe07f201df
- Thumbprint
- 61ed377e85d386a8dfee6b864bd85b0bfaa5af81
- Subject
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
- Subject email
- [email protected]
- Issuer
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
Permissions (7)
Intent filters - actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| deploy229.cehtech.net | domain | - | https | UPI OTP Stealer (provisional) | 2026-10-07 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About UPI OTP Stealer (provisional)
India-targeted Android banking stealer focused on UPI (Unified Payments Interface) fraud. Delivered as a dropper, it abuses SMS access to intercept one-time passcodes and harvests UPI/banking credentials, exfiltrating them to its backend (observed at deploy229.cehtech.net). Family label provisional.