526657e1fc1d717383e11b30…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
526657e1fc1d717383e11b3059d8f3b2e4a2bfae7b5ab99cde62b6d7f4858834
MD5
f7aec2e5ac21c80f18e0ec483a789f48

Observed

Families
HDFC eChallan RAT
First seen
2026-07-31

APK metadata

Summary

Type
Android · APK
Package
com.kotak.transfer.cf1f49ae7
Main activity
com.kotak.transfer.MainActivity
Internal version
8327
Displayed version
4.3.60
Min SDK
26
Target SDK
34

Signing certificate

Valid from
2026-07-31 08:07:48
Valid to
2053-12-16 08:07:48
Serial
4d9f9b6afe7ca60
Thumbprint
5c28b2348052f9d2436060e817904467af456953
Subject
C:IN, CN:Rohit Digital Pvt Ltd, L:Lucknow, O:Developers, ST:Tamil Nadu, OU:Deepak Apps
Issuer
C:IN, CN:Rohit Digital Pvt Ltd, L:Lucknow, O:Developers, ST:Tamil Nadu, OU:Deepak Apps

Permissions (5)

Decoy loader shell — the real permission set is under Unpacked payload below.

Activities (1)

  • com.kotak.transfer.MainActivity

Services (1)

  • com.kotak.transfer.XvziaknhWorker

Intent filters — actions

android.net.VpnService

Unpacked payload

The real payload hidden inside the packer, recovered by unwrapping the sample (3-stage eChallan packer (final banker APK)). This is the actual capability set the malware runs with — the APK metadata above is only the decoy loader shell.

Summary

Package
net.smart.monitor
Main activity
—
Internal version
1
Displayed version
7.0
Min SDK
24
Target SDK
35

Signing certificate

Valid from
2026-07-31 08:07:40
Valid to
2053-12-16 08:07:40
Serial
3c2f3cc55d0f9f26
Thumbprint
fbac88a6b12573c67ab501ff5a8068e6658ba075
Subject
C:IN, CN:Ravi Developers Pvt Ltd, L:Chennai, O:Ventures, ST:Telangana, OU:Nexus Apps
Issuer
C:IN, CN:Ravi Developers Pvt Ltd, L:Chennai, O:Ventures, ST:Telangana, OU:Nexus Apps

Permissions (16)

android.permission.ACCESS_NETWORK_STATEandroid.permission.CALL_PHONEandroid.permission.FOREGROUND_SERVICEandroid.permission.INTERNETandroid.permission.MANAGE_OWN_CALLSandroid.permission.POST_NOTIFICATIONSandroid.permission.READ_PHONE_NUMBERSandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SEND_SMSandroid.permission.WAKE_LOCKcom.google.android.c2dm.permission.RECEIVEnet.smart.monitor.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (2)

  • com.example.admin.MainActivity
  • com.google.android.gms.common.api.GoogleApiActivity

Services (9)

  • androidx.room.MultiInstanceInvalidationService
  • androidx.work.impl.background.systemalarm.SystemAlarmService
  • androidx.work.impl.background.systemjob.SystemJobService
  • androidx.work.impl.foreground.SystemForegroundService
  • com.example.admin.services.MyFirebaseMessagingService
  • com.google.android.datatransport.runtime.backends.TransportBackendDiscovery
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.JobInfoSchedulerService
  • com.google.firebase.components.ComponentDiscoveryService
  • com.google.firebase.messaging.FirebaseMessagingService

Receivers (13)

  • androidx.profileinstaller.ProfileInstallReceiver
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
  • androidx.work.impl.background.systemalarm.RescheduleReceiver
  • androidx.work.impl.diagnostics.DiagnosticsReceiver
  • androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
  • com.example.admin.receivers.BootReceiver
  • com.example.admin.receivers.SMSReceiver
  • com.google.android.datatransport.runtime.scheduling.jobscheduling.AlarmManagerSchedulerBroadcastReceiver
  • com.google.firebase.iid.FirebaseInstanceIdReceiver

Providers (2)

  • androidx.startup.InitializationProvider
  • com.google.firebase.provider.FirebaseInitProvider

Intent filters — actions

android.intent.action.ACTION_POWER_CONNECTEDandroid.intent.action.ACTION_POWER_DISCONNECTEDandroid.intent.action.BATTERY_LOWandroid.intent.action.BATTERY_OKAYandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.DEVICE_STORAGE_LOWandroid.intent.action.DEVICE_STORAGE_OKandroid.intent.action.MY_PACKAGE_REPLACEDandroid.intent.action.QUICKBOOT_POWERONandroid.intent.action.TIMEZONE_CHANGEDandroid.intent.action.TIME_SETandroid.net.conn.CONNECTIVITY_CHANGEandroid.provider.Telephony.SMS_RECEIVEDandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEandroidx.work.diagnostics.REQUEST_DIAGNOSTICSandroidx.work.impl.background.systemalarm.UpdateProxiescom.google.android.c2dm.intent.RECEIVEcom.google.firebase.MESSAGING_EVENTcom.htc.intent.action.QUICKBOOT_POWERON

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
sukhdev001-68bfd-default-rtdb.firebaseio.com domain — — HDFC eChallan RAT 2026-07-31

Signing certificate

Subject CN
Rohit Digital Pvt Ltd
Issuer CN
Rohit Digital Pvt Ltd
Fingerprint
9e7b2b9b18beab360987e41d3693784c21cf824a9672e5577f34dbfc9d919d9c

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.