tryanotherhorse.com/config.txt
domainTracked by C2 Tracker · Whois queried 2026-10-04T21:39:24
Registration
- Registrar
- —
- Registered
- —
- Expires
- —
DNS
- Resolves to
- —
- Nameservers
- —
- Status
- —
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| APT36 | 52d1cb75b782… | 2020-01-03 |
| APT36 | 0c5b37b48769… | 2020-05-02 |
Attributed to: Transparent Tribe (APT36)
About APT36
Android spyware of Transparent Tribe (APT36, "ProjectM" / "C-Major"), a Pakistan-nexus APT running South-Asia campaigns (documented by Kaspersky, Aug 2020). Simple, non-sophisticated implants with a recognizable manifest fingerprint: a `.MainS` service plus `.MyReceive` and `.CallReceive` receivers. The live C2 is not hardcoded - IOSocket carries a base64 const-string decoding to an online config URL (e.g. tryanotherhorse.com/config.txt) whose body the Config class parses for "Server IP" / "Domain Addr" at runtime.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.