theapi.the-x-services.xyz/
domain C2Tracked by C2 Tracker · Whois queried never
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- -
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| novinarya | be165239e4fe… | C2 | 2026-10-07 |
About Novinarya
Iranian Android banking and crypto stealer (package ir.novinarya), distributed as a fake "Smart System Security" app. The real Basic4Android payload is sealed inside an asset behind a native EPDATA/RC4 packer (loader shell net.swiftnova.bridge); per build the asset name, native library name, RC4 key and key transform are re-randomised while the unpacked 2-dex payload stays byte-identical. It targets ~80 Iranian exchange/wallet and banking apps, steals credentials through a phishing WebView with an injected JavaScript form-grabber, and lifts account numbers, balances and SMS OTP codes via an encrypted 25-bank regex config (X_BANKS). The C2 is never a static string: an encrypted X_ROUTES manifest meta-data value (AES-CBC, key=SHA-256(X_CID)) resolves to a profile on a legitimate marketplace (basalam.com) or github.com, whose bio decrypts to the live rotating C2. Loot is AES-encrypted and POSTed as JSON to that resolved domain. Legitimate dead-drop hosts are never recorded as indicators.
Signing certificate
- Subject CN
- -
- Issuer CN
- -
- Valid
- 2016-09-23 → 3015-01-25
- Fingerprint
- 022a1ed9feb0e6c9826df99c58350b7789a71ad51f142f40449f91d58c0278c1
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.