f2a5bb87811a3cef9e81d42a…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

EventBot. Android banking trojan whose C2 URLs sit as http(s) const-strings in the static initializer of the /example/eventbot/cfg config class. Indicators: http://ora.studiolegalebasili.com/gate_cb8a5aea1ab302f0_c, http://ora.carlaarrabitoarchitetto.com/gate_cb8a5aea1ab302f0_c.

Recovered configuration

package
com.example.eventbot

Identification

SHA-256
f2a5bb87811a3cef9e81d42a27065f2c8f546d5dfbd5a121cb5f5ae57242dcd3
MD5
cc38a004ba3ec409a762d7be7acdf497

Observed

Families
EventBot
First seen
2020-03-20

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
ora.carlaarrabitoarchitetto.com/gate_cb8a5aea1ab302f0_c domain - http EventBot 2020-03-20
ora.studiolegalebasili.com/gate_cb8a5aea1ab302f0_c domain - http EventBot 2020-03-20

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About EventBot

Android banking trojan whose C2 URLs sit as http(s) const-strings in the static initializer of the /example/eventbot/cfg config class.