motupatlu-7638e-default-rtdb.firebaseio.com

domain C2 not resolving

Tracked by C2 Tracker · Whois queried never

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
-
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
HDFC eChallan RAT 526657e1fc1d… C2 –

About HDFC eChallan RAT

India-targeted netbanking RAT distributed with a fake RTO traffic e-challan ("eChallan") lure impersonating HDFC. A three-stage packer (XOR + AES-CBC + gunzip, loaded via InMemoryDexClassLoader with an on-device self-signing installer) drops an SMS-stealing banking trojan that harvests netbanking/UPI/card credentials and OTP SMS. Stolen data is exfiltrated to attacker Firebase Realtime Database instances; a bundled VpnService routes device DNS through attacker resolvers (seen as IP indicators such as 108.74.33.9 and 201.92.30.6).

Signing certificate

Subject CN
Rohit Digital Pvt Ltd
Issuer CN
Rohit Digital Pvt Ltd
Valid
2026-07-31 → 2053-12-16
Fingerprint
9e7b2b9b18beab360987e41d3693784c21cf824a9672e5577f34dbfc9d919d9c

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.