0c5b37b48769df1f88d84137…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- 0c5b37b48769df1f88d84137c2084bd023b7d6d44a3bdc62ef8c370f3c15fec5
- MD5
- 681ff974adb54692e61551f9640f76bf
Observed
- Families
- APT36
- First seen
- 2020-05-02
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| tryanotherhorse.com/config.txt | domain | — | http | APT36 | 2020-05-02 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About APT36
Android spyware of Transparent Tribe (APT36, "ProjectM" / "C-Major"), a Pakistan-nexus APT running South-Asia campaigns (documented by Kaspersky, Aug 2020). Simple, non-sophisticated implants with a recognizable manifest fingerprint: a `.MainS` service plus `.MyReceive` and `.CallReceive` receivers. The live C2 is not hardcoded - IOSocket carries a base64 const-string decoding to an online config URL (e.g. tryanotherhorse.com/config.txt) whose body the Config class parses for "Server IP" / "Domain Addr" at runtime.