c2.zero-dustapps.com
domain C2Tracked by C2 Tracker · Whois queried never
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- -
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| PushAction SMS Stealer (provisional) | b2d0efb131b1… | C2 | 2023-06-18 |
| PushAction SMS Stealer (provisional) | 6ea6ed41d622… | C2 | 2023-06-26 |
| PushAction SMS Stealer (provisional) | 810b2aa3f95f… | C2 | 2023-06-29 |
About PushAction SMS Stealer (provisional)
Long-running SMS-stealer group that ships DCloud / uni-app hybrid Android apps (main activity `io.dcloud.PandoraEntry`) disguised as e-commerce, delivery, grocery and services lures, first documented against Malaysian users by Fareed Fauzi (Dec 2022). A static `SmsReceiver` intercepts incoming SMS and calls `abortBroadcast()`; the message body, sender, Android device id and timestamp are HTTP-POSTed to the operator server, and entered banking credentials go to a separate phishing kit. The C2 base rotates across many disposable domains (mall-base-app.com, ecomall-app-ag1.info, pos-express-node.com, post-yundeck.top, zero-dustapps.com, towncenter-appsv4-0001.info, maids-app.info, productapps1011.win, hungryduit.online, …) but the exfil API path is the stable fingerprint: `https://<host>/app/(api/)action/<name>PushAction/` (defaultSmsPushAction, smsMessagePushAction, smsPermissionPushAction, deviceActivePushAction). C2 hosts are taken from those endpoints, not from a single hardcoded config string. Provisional bucket pending formal attribution.
Signing certificate
- Subject CN
- bngisthebest
- Issuer CN
- bngisthebest
- Valid
- 2023-06-25 → 2024-06-24
- Fingerprint
- 21bb7b48b2b59c5509ed71af5ce893819a7c2ad4c72b04a5c8e2bc52ec12ca00
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.