ora.carlaarrabitoarchitetto.com/gate_cb8a5aea1ab302f0_b
domain C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-11T02:22:15
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- 31.214.157.6
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| EventBot | 42344ae56337… | C2 | 2020-03-01 |
| EventBot | b57d2cef4419… | C2 | 2020-03-03 |
| EventBot | 7b1ac3a8caa5… | C2 | 2020-03-19 |
| EventBot | f2a5bb87811a… | C2 | 2020-03-20 |
| EventBot | fa6897c95fc9… | C2 | 2020-03-21 |
About EventBot
Android banking trojan whose C2 URLs sit as http(s) const-strings in the static initializer of the /example/eventbot/cfg config class.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.