upload101.net/android/domains
domainTracked by C2 Tracker · Whois queried 2026-10-04T15:56:14
Registration
- Registrar
- —
- Registered
- —
- Expires
- —
DNS
- Resolves to
- —
- Nameservers
- —
- Status
- —
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| APT-C-23 | e14f99608a8d… | 2018-06-10 |
| APT-C-23 | ca87cc9898af… | 2019-08-29 |
About APT-C-23
Android spyware operated by the Gaza-nexus actor tracked as APT-C-23 (a.k.a. Arid Viper, Two-tailed Scorpion; MITRE ATT&CK G1028), used against targets in the Middle East. Apps disguise themselves as legitimate services (chat, updates) and carry call interception, SMS exfiltration and screen-recording capability. Identification rests on a four-part fingerprint (INTERNET permission, MainActivity, receivers.CallReceiver, services.CellService); the http(s) C2 URLs sit as const-strings in the <clinit> of the update/app/a class.
Signing certificate
- Subject CN
- User One
- Issuer CN
- User One
- Valid
- 2016-09-10 → 2041-09-04
- Fingerprint
- 864ffd08404c3dba5ebc92a66d1fc0cea40bf81734fa6a8285bfd797b9830340
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.