stats.googlems.cc
domain C2Tracked by C2 Tracker · Whois queried never
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- -
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Orbit Shop Phish (provisional) | 40d1db89934b… | C2 | 2026-10-08 |
About Orbit Shop Phish (provisional)
Phishing/fake-app payload delivered inside an SVLT "shelltemplate" vault dropper (outer package net.ocean.mail; the same vault packer as the AtlasBridge sample, differing only in that the decryption key sits in AndroidManifest application meta-data, vault_payload_key, rather than a plaintext config asset). The decrypted vault carries a vault-config.json, an upgrade-template/ phishing WebView, and a child.apk (org.orbit.shop). The config stats.apiUrl is the telemetry/C2 on a Google typosquat domain (googlems.cc). The loader is Chinese-authored (Chinese log strings; a jobName campaign tag using 群, group). C2 recovered by a full static unpack of the vault; family label provisional, hash-attributed.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.