be165239e4fe899b1f2eedf6…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
http://theapi.the-x-services.xyz/.Recovered configuration
Identification
- SHA-256
- be165239e4fe899b1f2eedf6459d363bca4fe6856fda87a63ba5d4e5e612e1c9
- MD5
- 48c5cab842617c00b380d2c4effd8721
Observed
- Families
- novinarya
- First seen
- 2026-10-07
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| theapi.the-x-services.xyz/ | domain | - | http | novinarya | 2026-10-07 |
Signing certificate
- Subject CN
- -
- Issuer CN
- -
- Fingerprint
- 022a1ed9feb0e6c9826df99c58350b7789a71ad51f142f40449f91d58c0278c1
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Novinarya
Iranian Android banking and crypto stealer (package ir.novinarya), distributed as a fake "Smart System Security" app. The real Basic4Android payload is sealed inside an asset behind a native EPDATA/RC4 packer (loader shell net.swiftnova.bridge); per build the asset name, native library name, RC4 key and key transform are re-randomised while the unpacked 2-dex payload stays byte-identical. It targets ~80 Iranian exchange/wallet and banking apps, steals credentials through a phishing WebView with an injected JavaScript form-grabber, and lifts account numbers, balances and SMS OTP codes via an encrypted 25-bank regex config (X_BANKS). The C2 is never a static string: an encrypted X_ROUTES manifest meta-data value (AES-CBC, key=SHA-256(X_CID)) resolves to a profile on a legitimate marketplace (basalam.com) or github.com, whose bio decrypts to the live rotating C2. Loot is AES-encrypted and POSTed as JSON to that resolved domain. Legitimate dead-drop hosts are never recorded as indicators.