40fc35a3b459ba1f34053963…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

APT-C-27. Android spyware attributed to the Goldmouse group (ETDA tracks it as APT-C-27). Identification rests on a four-part manifest fingerprint (INTERNET permission, MainActivity, the deliberately misspelled SystemUpten receiver, and the NetService/NtService service). The C2 IP and port are stored as static fields in the static initializer of the PcketPrvidr (sic) / PacketProvider config class. Indicators: 82.137.255.56:1740.

Recovered configuration

package
com.mobicomkit.sample

Identification

SHA-256
40fc35a3b459ba1f3405396321aab438360e78a2e5e56e8852b07e9607926e01
MD5
39a9406204c2a678689b64733fc52c73

Observed

Families
APT-C-27
First seen
2018-05-06

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
82.137.255.56 ip 1740 - APT-C-27 2018-05-06

Signing certificate

Subject CN
vip
Issuer CN
vip
Fingerprint
a0d198e40ac8a4e9e9057d7c40c9be7bb6aab3f95126cb0e0ac7e5c79552f02b

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About APT-C-27

Android spyware attributed to the Goldmouse group (ETDA tracks it as APT-C-27). Identification rests on a four-part manifest fingerprint (INTERNET permission, MainActivity, the deliberately misspelled SystemUpten receiver, and the NetService/NtService service). The C2 IP and port are stored as static fields in the static initializer of the PcketPrvidr (sic) / PacketProvider config class.