gdebenz.ru
domainTracked by C2 Tracker · Updated as of 2026-10-07 · Whois queried 2026-10-07T13:21:12
Registration
- Registrar
- —
- Registered
- —
- Expires
- —
DNS
- Resolves to
- 95.129.237.95
- Nameservers
- —
- Status
- —
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| Telegram Phish Proxy (provisional) | 3d2b06645150… | 2026-10-07 |
About Telegram Phish Proxy (provisional)
Final payload of a **4-stage "shellapp" native dropper** (outer package `com.coresoft.studio`, horoscope *"goroskopys"* lure; final payload `com.apexware.utils` / `com.base.template`). Each stage decrypts and `DexClassLoader`-loads the next, so the real code never appears in the installed APK's dex. The unpacking recovered statically: stage 1→2 uses a native `nativeCipher` = `payload[16:] XOR SHA256(key)` with a per-sample repeating-XOR-obfuscated key; stage 2 (a VPN "Telegram-bypass" internet blocker) carries a `PayloadInstaller` that AES-256-CBC-decrypts `assets/payload.db`; stage 3 decrypts a further asset to the stage-4 stealer. The stealer runs a `ProxyService` that opens a **WebSocket device-relay C2** and a `TelegramPhishActivity` that drives a phishing WebView against an operator panel (`/api/phish/start`, `/api/phish/verify`, `/api/phish/2fa`) to steal Telegram logins and 2FA codes. All strings are repeating-XOR obfuscated. Family label provisional; C2 indicators are binary-verified by a full static unpack.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-04-15 → 2035-09-01
- Fingerprint
- c8a2e9bccf597c2fb6dc66bee293fc13f2fc47ec77bc6b2b0d52c11f51192ab8
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.