ca87cc9898af3883eca81aca…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- ca87cc9898af3883eca81aca658109fdd7ca2529dfbd45a25e0c6e7cf0b526e5
- MD5
- 2a7576c896bb6f7710e9f41e0a25ce14
Observed
- Families
- APT-C-23
- First seen
- 2019-08-29
C2 configuration (2)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| upload101.net/android/domains | domain | — | http | APT-C-23 | 2019-08-29 |
| upload999.info | domain | — | http | APT-C-23 | 2019-08-29 |
Signing certificate
- Subject CN
- User One
- Issuer CN
- User One
- Fingerprint
- 864ffd08404c3dba5ebc92a66d1fc0cea40bf81734fa6a8285bfd797b9830340
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About APT-C-23
Android spyware operated by the Gaza-nexus actor tracked as APT-C-23 (a.k.a. Arid Viper, Two-tailed Scorpion; MITRE ATT&CK G1028), used against targets in the Middle East. Apps disguise themselves as legitimate services (chat, updates) and carry call interception, SMS exfiltration and screen-recording capability. Identification rests on a four-part fingerprint (INTERNET permission, MainActivity, receivers.CallReceiver, services.CellService); the http(s) C2 URLs sit as const-strings in the <clinit> of the update/app/a class.