egxud.com
domain C2Tracked by C2 Tracker ยท Whois queried never
Registration
- Registrar
- โ
- Registered
- โ
- Expires
- โ
DNS
- Resolves to
- โ
- Nameservers
- โ
- Status
- โ
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Anubis | 2c4694a79d1bโฆ | C2 | 2026-10-07 |
About Anubis
Android banking trojan, a long-lived descendant of the BankBot/Marcher lineage sold as malware-as-a-service. Heavy abuse of accessibility services for overlay credential theft, keylogging and SMS interception, with a ransomware module in later builds. Shipped as a packer: the real payload is an RC4-encrypted asset whose key is an int[] literal in the loader (each element & 0xff); the unpacked config carries the C2 panel and an RC4 key. Many builds use a dead drop - a Twitter/Telegram profile whose text holds the real C2 behind the key - rather than a hardcoded host.
Signing certificate
- Subject CN
- โ
- Issuer CN
- โ
- Valid
- 2026-12-04 โ 2095-05-16
- Fingerprint
- 6cf777da9d58ca1f80a878acc5ce2d6d07e5819c10d00b43ce46a98e16365a13
Other samples signed with this certificate? That's a lead worth checking โ but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.