83a4718fd650f78bf1aed4a5…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
CapraRat. Android RAT used by Transparent Tribe (a.k.a. APT36, Earth Karkaddan, ProjectM) against targets in India and Pakistan. Typically single-application spyware delivered via social engineering, with screen capture, call/SMS exfiltration and audio recording. Indicators:
80.241.209.53:12182, shareboxs.net:12182.Recovered configuration
version
A.D.0.2
Identification
- SHA-256
- 83a4718fd650f78bf1aed4a5eb560950aab8bc2ea432598402c38568f7e462ab
- MD5
- 4a7a22d90ead6ffa86ef704958b57aab
Observed
- Families
- CapraRat
- First seen
- 2019-07-31
APK metadata
Summary
- Type
- Android · APK
- Package
- com.newapps.gallery.galleryapp
- Main activity
- com.example.appcode.appcode.MainActivity
- Internal version
- —
- Displayed version
- —
- Min SDK
- 16
- Target SDK
- 21
Signing certificate
- Valid from
- 2018-11-27 19:20:04
- Valid to
- 2048-11-19 19:20:04
- Serial
- 1
- Thumbprint
- 765d239766e8f7c3d6c50e69d1b95a69cdbc2bb1
- Subject
- C:US, CN:Android Debug, O:Android
- Issuer
- C:US, CN:Android Debug, O:Android
Permissions (25)
Intent filters — actions
Intent filters — categories
android.intent.category.DEFAULT
C2 configuration (2)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| shareboxs.net | domain | 12182 | — | CapraRat | 2019-07-31 |
| 80.241.209.53 | ip | 12182 | — | CapraRat | 2019-07-31 |
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Fingerprint
- a8140f73130740106b48101c218989e0decd9755748661e01e5e8bc5eb314391
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About CapraRat
Android RAT used by Transparent Tribe (a.k.a. APT36, Earth Karkaddan, ProjectM) against targets in India and Pakistan. Typically single-application spyware delivered via social engineering, with screen capture, call/SMS exfiltration and audio recording.