gdebenz.ru

domain resolving

Tracked by C2 Tracker · Updated as of 2026-10-07 · Whois queried 2026-10-07T13:21:12

Registration

Registrar
—
Registered
—
Expires
—

DNS

Resolves to
95.129.237.95
Nameservers
—
Status
—

Observed in malware

FamilySample SHA-256First seen
Telegram Phish Proxy (provisional) 3d2b06645150… 2026-10-07

About Telegram Phish Proxy (provisional)

Final payload of a **4-stage "shellapp" native dropper** (outer package `com.coresoft.studio`, horoscope *"goroskopys"* lure; final payload `com.apexware.utils` / `com.base.template`). Each stage decrypts and `DexClassLoader`-loads the next, so the real code never appears in the installed APK's dex. The unpacking recovered statically: stage 1→2 uses a native `nativeCipher` = `payload[16:] XOR SHA256(key)` with a per-sample repeating-XOR-obfuscated key; stage 2 (a VPN "Telegram-bypass" internet blocker) carries a `PayloadInstaller` that AES-256-CBC-decrypts `assets/payload.db`; stage 3 decrypts a further asset to the stage-4 stealer. The stealer runs a `ProxyService` that opens a **WebSocket device-relay C2** and a `TelegramPhishActivity` that drives a phishing WebView against an operator panel (`/api/phish/start`, `/api/phish/verify`, `/api/phish/2fa`) to steal Telegram logins and 2FA codes. All strings are repeating-XOR obfuscated. Family label provisional; C2 indicators are binary-verified by a full static unpack.

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2008-04-15 → 2035-09-01
Fingerprint
c8a2e9bccf597c2fb6dc66bee293fc13f2fc47ec77bc6b2b0d52c11f51192ab8

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.