48d1fd4ed521c9472d2b67e8…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
48d1fd4ed521c9472d2b67e8e0698511cea2b4141a9632b89f26bd1d0f760e89
MD5
—

Observed

Families
DCHSpy
First seen
2025-07-21

C2 configuration (9)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
it1.comodo-vpn.com domain 1953 https DCHSpy 2025-07-21
vm1.netjustfun.com domain 8763 — DCHSpy 2025-07-21
vm2.netjustfun.com domain 8763 — DCHSpy 2025-07-21
vm3.netjustfun.com domain 8763 — DCHSpy 2025-07-21
vm4.netjustfun.com domain 8763 — DCHSpy 2025-07-21
185.252.215.129 ip 8763 — DCHSpy 2025-07-21
45.153.229.158 ip 8763 — DCHSpy 2025-07-21
45.67.229.68 ip 8763 — DCHSpy 2025-07-21
45.87.154.87 ip 8763 — DCHSpy 2025-07-21

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Fingerprint
afa47e0fc07dfae6ff1216babdec4c15c0891f8b62ff3b1a064c47c3f1a5b020

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About DCHSpy

Android surveillanceware leveraged by Iranian cyber espionage group MuddyWater (MOIS-linked), distributed via Telegram as fake VPN apps (EarthVPN, ComodoVPN, HideVPN) with activist/journalist targeting. Collects WhatsApp data, accounts, contacts, SMS, files, location, call logs, audio and photos; exfiltrates over SFTP. Shares infrastructure with SandStrike.