theapi.the-x-services.xyz/

domain C2 not resolving

Tracked by C2 Tracker · Whois queried never

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
-
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
novinarya be165239e4fe… C2 2026-10-07

About Novinarya

Iranian Android banking and crypto stealer (package ir.novinarya), distributed as a fake "Smart System Security" app. The real Basic4Android payload is sealed inside an asset behind a native EPDATA/RC4 packer (loader shell net.swiftnova.bridge); per build the asset name, native library name, RC4 key and key transform are re-randomised while the unpacked 2-dex payload stays byte-identical. It targets ~80 Iranian exchange/wallet and banking apps, steals credentials through a phishing WebView with an injected JavaScript form-grabber, and lifts account numbers, balances and SMS OTP codes via an encrypted 25-bank regex config (X_BANKS). The C2 is never a static string: an encrypted X_ROUTES manifest meta-data value (AES-CBC, key=SHA-256(X_CID)) resolves to a profile on a legitimate marketplace (basalam.com) or github.com, whose bio decrypts to the live rotating C2. Loot is AES-encrypted and POSTed as JSON to that resolved domain. Legitimate dead-drop hosts are never recorded as indicators.

Signing certificate

Subject CN
-
Issuer CN
-
Valid
2016-09-23 → 3015-01-25
Fingerprint
022a1ed9feb0e6c9826df99c58350b7789a71ad51f142f40449f91d58c0278c1

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.