egxud.com

domain C2 not resolving

Tracked by C2 Tracker ยท Whois queried never

Registration

Registrar
โ€”
Registered
โ€”
Expires
โ€”

DNS

Resolves to
โ€”
Nameservers
โ€”
Status
โ€”

Observed in malware

FamilySample SHA-256RoleFirst seen
Anubis 2c4694a79d1bโ€ฆ C2 2026-10-07

About Anubis

Android banking trojan, a long-lived descendant of the BankBot/Marcher lineage sold as malware-as-a-service. Heavy abuse of accessibility services for overlay credential theft, keylogging and SMS interception, with a ransomware module in later builds. Shipped as a packer: the real payload is an RC4-encrypted asset whose key is an int[] literal in the loader (each element & 0xff); the unpacked config carries the C2 panel and an RC4 key. Many builds use a dead drop - a Twitter/Telegram profile whose text holds the real C2 behind the key - rather than a hardcoded host.

Signing certificate

Subject CN
โ€”
Issuer CN
โ€”
Valid
2026-12-04 โ†’ 2095-05-16
Fingerprint
6cf777da9d58ca1f80a878acc5ce2d6d07e5819c10d00b43ce46a98e16365a13

Other samples signed with this certificate? That's a lead worth checking โ€” but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.