021d92dd00260dd5f96fd8d8…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
021d92dd00260dd5f96fd8d8fedd487b6c7706348bd9f216cac40a98203143dc
MD5
9ef2be98edf462e8ce51eb690fbc4ede

Observed

Families
HDFC eChallan RAT
First seen
2026-07-23

APK metadata

Summary

Type
Android · APK
Package
com.apkshield.installer.c8d4bbe6a
Main activity
com.apkshield.installer.MainActivity
Internal version
1
Displayed version
1.0
Min SDK
26
Target SDK
34

Signing certificate

Valid from
2026-07-23 13:10:58
Valid to
2053-12-08 13:10:58
Serial
5023b33dda8cce12
Thumbprint
f35d30c89d2849533278c87c3979eed6a801a207
Subject
C:US, CN:f07ab108b4744256, L:US, O:1ec7e44f, ST:CA, OU:7d52bbc9
Issuer
C:US, CN:f07ab108b4744256, L:US, O:1ec7e44f, ST:CA, OU:7d52bbc9

Permissions (5)

Decoy loader shell — the real permission set is under Unpacked payload below.

Activities (1)

  • com.apkshield.installer.MainActivity

Services (1)

  • com.apkshield.installer.ApkShieldVpnService

Intent filters — actions

android.net.VpnService

Unpacked payload

The real payload hidden inside the packer, recovered by unwrapping the sample (3-stage eChallan packer (final banker APK)). This is the actual capability set the malware runs with — the APK metadata above is only the decoy loader shell.

Summary

Package
com.example.admin.mry3hckwa
Main activity
com.example.admin.mry3hckwa.MainActivity
Internal version
1
Displayed version
7.0
Min SDK
24
Target SDK
35

Signing certificate

Valid from
2026-07-23 13:10:58
Valid to
2053-12-08 13:10:58
Serial
5023b33dda8cce12
Thumbprint
f35d30c89d2849533278c87c3979eed6a801a207
Subject
C:US, CN:f07ab108b4744256, L:US, O:1ec7e44f, ST:CA, OU:7d52bbc9
Issuer
C:US, CN:f07ab108b4744256, L:US, O:1ec7e44f, ST:CA, OU:7d52bbc9

Permissions (16)

android.permission.ACCESS_NETWORK_STATEandroid.permission.CALL_PHONEandroid.permission.FOREGROUND_SERVICEandroid.permission.INTERNETandroid.permission.MANAGE_OWN_CALLSandroid.permission.POST_NOTIFICATIONSandroid.permission.READ_PHONE_NUMBERSandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SEND_SMSandroid.permission.WAKE_LOCKcom.example.admin.mry3hckwa.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSIONcom.google.android.c2dm.permission.RECEIVE

Activities (2)

  • com.example.admin.mry3hckwa.MainActivity
  • com.google.android.gms.common.api.GoogleApiActivity

Services (9)

  • androidx.room.MultiInstanceInvalidationService
  • androidx.work.impl.background.systemalarm.SystemAlarmService
  • androidx.work.impl.background.systemjob.SystemJobService
  • androidx.work.impl.foreground.SystemForegroundService
  • com.example.admin.mry3hckwa.services.MyFirebaseMessagingService
  • com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
  • com.google.firebase.components.ComponentDiscoveryService
  • com.google.firebase.messaging.FirebaseMessagingService

Receivers (13)

  • androidx.profileinstaller.ProfileInstallReceiver
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
  • androidx.work.impl.background.systemalarm.RescheduleReceiver
  • androidx.work.impl.diagnostics.DiagnosticsReceiver
  • androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
  • com.example.admin.mry3hckwa.receivers.FZFErprvire
  • com.example.admin.mry3hckwa.receivers.ObbgErprvire
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
  • com.google.firebase.iid.FirebaseInstanceIdReceiver

Providers (2)

  • androidx.startup.InitializationProvider
  • com.google.firebase.provider.FirebaseInitProvider

Intent filters — actions

android.intent.action.ACTION_POWER_CONNECTEDandroid.intent.action.ACTION_POWER_DISCONNECTEDandroid.intent.action.BATTERY_LOWandroid.intent.action.BATTERY_OKAYandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.DEVICE_STORAGE_LOWandroid.intent.action.DEVICE_STORAGE_OKandroid.intent.action.MY_PACKAGE_REPLACEDandroid.intent.action.QUICKBOOT_POWERONandroid.intent.action.TIMEZONE_CHANGEDandroid.intent.action.TIME_SETandroid.net.conn.CONNECTIVITY_CHANGEandroid.provider.Telephony.SMS_RECEIVEDandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEandroidx.work.diagnostics.REQUEST_DIAGNOSTICSandroidx.work.impl.background.systemalarm.UpdateProxiescom.google.android.c2dm.intent.RECEIVEcom.google.firebase.MESSAGING_EVENTcom.htc.intent.action.QUICKBOOT_POWERON

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
baccha-a07d9-default-rtdb.firebaseio.com domain — — HDFC eChallan RAT 2026-07-23

Signing certificate

Subject CN
f07ab108b4744256
Issuer CN
f07ab108b4744256
Fingerprint
e477e7c9f338e9bef0f13a89c29a8453615e71ad2b18e6cf5e8bb2808e7003e6

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.