mediauploader.info
domainTracked by C2 Tracker · Whois queried 2026-10-04T15:56:15
Registration
- Registrar
- GoDaddy.com, LLC
- Registered
- 2018-01-11T14:36:30.893Z
- Expires
- 2027-01-11T14:36:30.893Z
DNS
- Resolves to
- —
- Nameservers
- nsa.domainservicesbydesign.com, nsb.domainservicesbydesign.com
- Status
- —
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| APT-C-23 | e14f99608a8d… | 2018-06-10 |
About APT-C-23
Android spyware operated by the Gaza-nexus actor tracked as APT-C-23 (a.k.a. Arid Viper, Two-tailed Scorpion; MITRE ATT&CK G1028), used against targets in the Middle East. Apps disguise themselves as legitimate services (chat, updates) and carry call interception, SMS exfiltration and screen-recording capability. Identification rests on a four-part fingerprint (INTERNET permission, MainActivity, receivers.CallReceiver, services.CellService); the http(s) C2 URLs sit as const-strings in the <clinit> of the update/app/a class.
Signing certificate
- Subject CN
- Jamal Hassan
- Issuer CN
- Jamal Hassan
- Valid
- 2016-04-30 → 2041-04-24
- Fingerprint
- 26768fa08ed2ec3f4ca429c1dad626548fd92bf9a3a333497ed864b72640be61
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.