9beab3f4aec1f751917443b6…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

HDFC Card Stealer (provisional). AES-CBC dropper disguised as “HDFC BANK CARD” (outer package com.glgcjkx.xxon). It carries its real payload encrypted in assets/PKlieZOsrGuVIl and installs it at runtime. Unpack recovered statically: the asset’s bytes 16+ are XOR-deobfuscated with SHA256(aesKey + “xor_layer”)[:16], then the first 16 bytes are the AES-CBC IV and the remainder is AES/CBC/PKCS5 ciphertext decrypted with aesKey = _KA XOR _KB (two hardcoded 16-byte arrays) -> a ZIP containing base.apk, the dropped card-stealer (package tfyxbg.zbdjpg.dytbyw, sha256 a8d9d058c46cf56995acc5092cc4aaea5175d37c7f95bda004a62b0b69434433). The dropped stealer shows a WebView card-entry phishing page and exfiltrates to the operator’s Firebase project hdfc-1-81195 - Realtime Database hdfc-1-81195-default-rtdb.firebaseio.com and Storage hdfc-1-81195.firebasestorage.app (the C2). It also uploads stolen card images to upload.imagekit.io and sends data to a Telegram bot via api.telegram.org (bot token built at runtime, not statically recoverable). Defender pivot: block/report the hdfc-1-81195 Firebase project. Label provisional. Indicators: https://hdfc-1-81195-default-rtdb.firebaseio.com, https://hdfc-1-81195.firebasestorage.app.

Recovered configuration

package
com.glgcjkx.xxon

AES-CBC dropper disguised as "HDFC BANK CARD" (outer package com.glgcjkx.xxon). It carries its real payload encrypted in assets/PKlieZOsrGuVIl and installs it at runtime. Unpack recovered statically: the asset's bytes 16+ are XOR-deobfuscated with SHA256(aesKey + "xor_layer")[:16], then the first 16 bytes are the AES-CBC IV and the remainder is AES/CBC/PKCS5 ciphertext decrypted with aesKey = _KA XOR _KB (two hardcoded 16-byte arrays) -> a ZIP containing base.apk, the dropped card-stealer (package tfyxbg.zbdjpg.dytbyw, sha256 a8d9d058c46cf56995acc5092cc4aaea5175d37c7f95bda004a62b0b69434433). The dropped stealer shows a WebView card-entry phishing page and exfiltrates to the operator's Firebase project hdfc-1-81195 - Realtime Database hdfc-1-81195-default-rtdb.firebaseio.com and Storage hdfc-1-81195.firebasestorage.app (the C2). It also uploads stolen card images to upload.imagekit.io and sends data to a Telegram bot via api.telegram.org (bot token built at runtime, not statically recoverable). Defender pivot: block/report the hdfc-1-81195 Firebase project. Label provisional.

Identification

SHA-256
9beab3f4aec1f751917443b6339abbd071cc7e9096c47410760169d858e4c637
MD5
6431c6f831677f4dd087c85c42adb2c9

Observed

Families
HDFC Card Stealer (provisional)
First seen
2026-10-03

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
hdfc-1-81195-default-rtdb.firebaseio.com domain — https HDFC Card Stealer (provisional) 2026-10-03
hdfc-1-81195.firebasestorage.app domain — https HDFC Card Stealer (provisional) 2026-10-03

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.