1b8e91037937886b59582a1e…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
wss://dashboard.gripe/ws-relay, https://dashboardcloud.app, https://api.dashboardcloud.app/api/status.Recovered configuration
Source: string-reversed URLs in dex (bs config, UtilZ0Y480.decode = reverse)
Identification
- SHA-256
- 1b8e91037937886b59582a1eb14f0fa597811ab0884f44285c0c4a88cec99e86
- MD5
- f8a0677ce4ec1af77e29e4c61d829779
Observed
- Families
- NFC Relay (provisional)
- First seen
- 2026-10-10
C2 configuration (3)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| api.dashboardcloud.app/api/status | domain | - | https | NFC Relay (provisional) | 2026-10-10 |
| dashboard.gripe/ws-relay | domain | - | wss | NFC Relay (provisional) | 2026-10-10 |
| dashboardcloud.app | domain | - | https | NFC Relay (provisional) | 2026-10-10 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- 0781333c7202530437e9304722e36c9f9ddb01746e805fb0da690fc74d0b71ed
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About NFC Relay (provisional)
Android NFC-relay fraud malware. Running on a victim's phone, it reads contactless bank-card/tag data over NFC and relays it in real time over a WebSocket channel to an attacker-controlled device, which replays it at a payment terminal or ATM for fraudulent transactions (an NFSkimming / "NGate"-style technique). Observed C2 infrastructure includes dashboardcloud.app / api.dashboardcloud.app, dashboard.gripe and 178.236.243.8. Family label provisional.