ab345951a3e673aec99f80d3…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- ab345951a3e673aec99f80d39fa8f9cdb0d1ac07e0322dae3497c237f7b37277
- MD5
- 42efd88844b49e05ec19dd831354093a
Observed
- Families
- Xenomorph
- First seen
- 2022-08-09
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| gogoanalytics.click | domain | — | — | Xenomorph | 2022-08-09 |
Signing certificate
- Subject CN
- Milky Way
- Issuer CN
- Milky Way
- Fingerprint
- c886911f1a2e9915cbcf20c070b75e2e92142ab357039003f9aa3a6197734c6f
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Xenomorph
Android banking trojan distributed as malware-as-a-service, famous for its heavy abuse of Android accessibility services to steal credentials from dozens of banking and crypto apps. C2 domains are RC4-encrypted (key + ":::" marker) inside the DEX.