2152b98a832ce3e442b486ce…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
2152b98a832ce3e442b486ceeaa8e41a8a99657168986757913e2d916c7b1c21
MD5
187e32c89303dafcb6562d71d252ba8e

Observed

Families
CECbot
First seen
2026-09-24

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
c2kxpjr7cux7fqrfmimsz7rtq527xauw627xrjojimt66nwxqvrqbuyd.onion domain — — CECbot 2026-09-24

Signing certificate

Subject CN
Debug
Issuer CN
Debug
Fingerprint
c1e2b02373e696fbfb57a0688edf9669c5f19aa780a1387c82b4931f87038ffa

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About CECbot

Android TV box DDoS botnet - the operational successor to Katana by the same operator, but a clean-sheet Android app instead of a Mirai ELF: Java C2 layer, native JNI attack engine (11 DDoS methods incl. HTTP/2 + dynamic TLS), Curve25519 + Ed25519 + ChaCha20-Poly1305 C2 encryption, 9 persistence layers, and the first documented malware to weaponize HDMI-CEC. It maps the victim's home network (ICMP sweep + ARP correlation) and doubles as a residential proxy exit node. Bootstrap C2 strings are XOR-encrypted in the DEX; clearnet C2 domains are pushed at runtime, with a Tor .onion fallback.