ora.studiolegalebasili.com/gate_cb8a5aea1ab302f0_b

domain C2 resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-11T02:22:15

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
34.41.139.193
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
EventBot 42344ae56337… C2 2020-03-01
EventBot b57d2cef4419… C2 2020-03-03
EventBot 7b1ac3a8caa5… C2 2020-03-19
EventBot f2a5bb87811a… C2 2020-03-20
EventBot fa6897c95fc9… C2 2020-03-21

About EventBot

Android banking trojan whose C2 URLs sit as http(s) const-strings in the static initializer of the /example/eventbot/cfg config class.

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2008-02-29 → 2035-07-17
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.