giwyeje.top/api/ws/
domain C2Tracked by C2 Tracker · Updated as of 2026-10-10 · Whois queried 2026-10-10T08:43:52
Registration
- Registrar
- NameSilo,LLC
- Registered
- 2026-03-04T16:24:28.0Z
- Expires
- 2027-03-04T16:24:28.0Z
DNS
- Resolves to
- 192.163.166.132
- Nameservers
- ns2.dnsowl.com., ns3.dnsowl.com., ns1.dnsowl.com.
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| SecretShoot Crypto Drainer (provisional) | 9b12eaf52eae… | C2 | 2026-08-14 |
About SecretShoot Crypto Drainer (provisional)
Chinese accessibility-driven crypto-wallet drainer disguised as an adult-video app (秘色视频). An AccessibilityService automates on-device crypto withdrawals against targeted wallet/exchange apps (Gate.io, Trust Wallet, imToken) and PhonePe, reading and filling fund-password, amount and SMS/email 2FA fields and tapping confirm, while a WebView JS bridge and a WebSocket channel talk to the operator. Strings are per-string XOR-obfuscated; the build layers decoy services, staged .bt assets and ad-SDK noise. C2 is a wss:// command channel plus an HTTPS error-reporting endpoint on the same operator domain, recovered by decoding the obfuscated config. Family label provisional.
Signing certificate
- Subject CN
- William Martinez
- Issuer CN
- William Martinez
- Valid
- 2026-03-22 → 2051-03-16
- Fingerprint
- e71dc140696344e437a4ec54f29da9cf429b54d5030ed9ea6e840651aafc6836
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.