Live C2 feed · refreshed daily
Malware C2 intelligence,
extracted & enriched daily.
Family decoders pull C2 configurations from malware samples; every domain and IP is enriched with Whois (RDAP), DNS and network attribution. Search it like a threat-intel platform.
118
samples tracked
28
families
41
extractors supported
108
unique C2s
Tracked indicators
Supply-chain & runtime detections
Matched by code marker, no endpoint inside the sample — payload arrives at runtime. All detections →
| SHA-256 | Family | Decoder note | First seen |
|---|---|---|---|
| 0713ff7bb8d9… | APT-C-27 | — | |
| 8f997e606a13… | SyrianMT | 2020-04-13 | |
| 55e8b2d87f80… | DCHSpy | Flutter-built "Hazrate Eshgh" (حضرت عشق) gallery app themed on Mahsa (Jina) Amini - a political lure matching DCHSpy's Telegram distribution to Farsi speakers. SHA-1 listed in Lookout's DCHSpy IoCs; no endpoint is statically extractable from the Flutter build (config fetched at runtime), so this is a code-/hash-level attribution. | 2024-04-13 |
| 00ba0d5aea12… | RatHat | RatHat. serverUrl is the registration/WebSocket C2; the primary FRP tunnel C2 is fetched at runtime (liblocal-service.so) and is not a static IOC. Config is ZM26-encrypted with a custom keystream; serverUrl not statically recovered for this build. | 2026-04-04 |
| cf6fab86b34e… | RatHat | RatHat. serverUrl is the registration/WebSocket C2; the primary FRP tunnel C2 is fetched at runtime (liblocal-service.so) and is not a static IOC. Config is ZM26-encrypted with a custom keystream; serverUrl not statically recovered for this build. | 2026-09-09 |
| f179f0a98187… | RatHat | RatHat. serverUrl is the registration/WebSocket C2; the primary FRP tunnel C2 is fetched at runtime (liblocal-service.so) and is not a static IOC. Config is ZM26-encrypted with a custom keystream; serverUrl not statically recovered for this build. | 2026-06-01 |
| 322b70d95c18… | Black Hawk | Black Hawk native-XOR packer variant (ApkInstallerManager .so). Banker APK recovered; its Cf.S1 C2 is behind commercial string obfuscation, so this is recorded as a detection. | 2026-09-29 |
| 99ddbde2a404… | BlistLoader | BlistLoader. Fake 'StreamingTV' dropper (com.twemcb.vhkpkuim). Same 443-dex bloat / runtime-keyed payload profile as the 'Chrome/GoogleMeet Update' samples (distinct signing cert 492682f877607ee99df2ddd2...). C2 pending dynamic analysis. | 2026-09-18 |
| 20b8abb9ffa1… | HDFC eChallan RAT | HDFC eChallan RAT. Fake RTO e-challan (traffic-fine) lure dropping an SMS-stealing netbanking RAT via a 3-stage packer (XOR+AES-CBC+gunzip, InMemoryDexClassLoader, on-device self-signing installer). C2: Firebase Realtime Database exfil (firebase_rtdb) for stolen netbanking/UPI/card/OTP credentials and SMS; the IP indicators are attacker DNS resolvers pushed through a VpnService that routes all device traffic (0.0.0.0/0). firebase_rtdb is resolved from the in-APK firebase_api_key. | — |
| 526657e1fc1d… | HDFC eChallan RAT | HDFC eChallan RAT. Fake RTO e-challan (traffic-fine) lure dropping an SMS-stealing netbanking RAT via a 3-stage packer (XOR+AES-CBC+gunzip, InMemoryDexClassLoader, on-device self-signing installer). C2: Firebase Realtime Database exfil (firebase_rtdb) for stolen netbanking/UPI/card/OTP credentials and SMS; the IP indicators are attacker DNS resolvers pushed through a VpnService that routes all device traffic (0.0.0.0/0). firebase_rtdb is resolved from the in-APK firebase_api_key. | — |
| 35fa397fa0ab… | WebSocket VNC Banker (provisional) | Accessibility-abuse banker: MediaProjection VNC, overlay phishing (acs_*.html), SMS theft, WebSocket C2 (/ws /c2 /bot). Config in encrypted assets/1-3.bt (stream cipher, key obfuscated in 7.4MB anti-decompile multidex) + 2MB XOR assets/ads.txt; C2 host not statically recoverable - needs dynamic analysis (Frida). | 2026-10-05 |