happyuzbekblog.xyz
domain C2Tracked by C2 Tracker · Whois queried never
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- -
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Uzbek News Lure Dropper (provisional) | a8d62f377576… | C2 | 2026-10-08 |
About Uzbek News Lure Dropper (provisional)
**Uzbek News Lure Dropper** (provisional) is an Uzbekistan-targeting Android dropper that shows a genuine Uzbek news article (from vzglyad.uz) as a decoy while side-loading an AES-encrypted second-stage payload (basa.apk) via REQUEST_INSTALL_PACKAGES. Its strings are hidden behind a multi-decoder obfuscator (Base64 plus a per-class XOR); the payload-distribution / C2 host happyuzbekblog.xyz is recovered by replicating those decoders. Provisional label.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-04-15 → 2035-09-01
- Fingerprint
- c8a2e9bccf597c2fb6dc66bee293fc13f2fc47ec77bc6b2b0d52c11f51192ab8
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.