aa656a243d2008327e06fd5b…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
aa656a243d2008327e06fd5bbad919eea99aa271132dbaeabb146e22effbfd1b
MD5
3682be86f3ae1d874e40fb4e282527a9

Observed

Families
DCHSpy
First seen
2025-06-19

C2 configuration (10)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
r1.earthvpn.org/ domain 1254 https DCHSpy 2025-06-19
r2.earthvpn.org/ domain 1254 https DCHSpy 2025-06-19
vm1.netjustfun.com domain 8763 — DCHSpy 2025-06-19
vm2.netjustfun.com domain 8763 — DCHSpy 2025-06-19
vm3.netjustfun.com domain 8763 — DCHSpy 2025-06-19
vm4.netjustfun.com domain 8763 — DCHSpy 2025-06-19
185.252.215.129 ip 8763 — DCHSpy 2025-06-19
45.153.229.158 ip 8763 — DCHSpy 2025-06-19
45.67.229.68 ip 8763 — DCHSpy 2025-06-19
45.87.154.87 ip 8763 — DCHSpy 2025-06-19

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Fingerprint
cd7cf3738547a1786094274f6e8a9e20595da1b1117453f5c49f7e7dd8a22fbd

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About DCHSpy

Android surveillanceware leveraged by Iranian cyber espionage group MuddyWater (MOIS-linked), distributed via Telegram as fake VPN apps (EarthVPN, ComodoVPN, HideVPN) with activist/journalist targeting. Collects WhatsApp data, accounts, contacts, SMS, files, location, call logs, audio and photos; exfiltrates over SFTP. Shares infrastructure with SandStrike.