021d92dd00260dd5f96fd8d8…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- 021d92dd00260dd5f96fd8d8fedd487b6c7706348bd9f216cac40a98203143dc
- MD5
- 9ef2be98edf462e8ce51eb690fbc4ede
Observed
- Families
- HDFC eChallan RAT
- First seen
- 2026-07-23
APK metadata
Summary
- Type
- Android · APK
- Package
- com.apkshield.installer.c8d4bbe6a
- Main activity
- com.apkshield.installer.MainActivity
- Internal version
- 1
- Displayed version
- 1.0
- Min SDK
- 26
- Target SDK
- 34
Signing certificate
- Valid from
- 2026-07-23 13:10:58
- Valid to
- 2053-12-08 13:10:58
- Serial
- 5023b33dda8cce12
- Thumbprint
- f35d30c89d2849533278c87c3979eed6a801a207
- Subject
- C:US, CN:f07ab108b4744256, L:US, O:1ec7e44f, ST:CA, OU:7d52bbc9
- Issuer
- C:US, CN:f07ab108b4744256, L:US, O:1ec7e44f, ST:CA, OU:7d52bbc9
Permissions (5)
Intent filters — actions
Unpacked payload
The real payload hidden inside the packer, recovered by unwrapping the sample (3-stage eChallan packer (final banker APK)). This is the actual capability set the malware runs with — the APK metadata above is only the decoy loader shell.
Summary
- Package
- com.example.admin.mry3hckwa
- Main activity
- com.example.admin.mry3hckwa.MainActivity
- Internal version
- 1
- Displayed version
- 7.0
- Min SDK
- 24
- Target SDK
- 35
Signing certificate
- Valid from
- 2026-07-23 13:10:58
- Valid to
- 2053-12-08 13:10:58
- Serial
- 5023b33dda8cce12
- Thumbprint
- f35d30c89d2849533278c87c3979eed6a801a207
- Subject
- C:US, CN:f07ab108b4744256, L:US, O:1ec7e44f, ST:CA, OU:7d52bbc9
- Issuer
- C:US, CN:f07ab108b4744256, L:US, O:1ec7e44f, ST:CA, OU:7d52bbc9
Permissions (16)
Intent filters — actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| baccha-a07d9-default-rtdb.firebaseio.com | domain | — | — | HDFC eChallan RAT | 2026-07-23 |
Signing certificate
- Subject CN
- f07ab108b4744256
- Issuer CN
- f07ab108b4744256
- Fingerprint
- e477e7c9f338e9bef0f13a89c29a8453615e71ad2b18e6cf5e8bb2808e7003e6
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.