ce88455c0a4b69278fe480c1…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
QQ Credential Stealer (provisional) - an Android information/credential stealer, self-signed as “xyb”. Communicates with 2 operator endpoints. QQ credential-stealer (label 秒赞神器 ‘auto-like tool’, package com.qqmagic, built with AIDE). Phishes the victim’s QQ serial/account and password and exfiltrates them by email via smtp.163.com:25 (JavaMail). The mail credentials and recipient are the SAME as sample 5aa9f206 - identical DES-encrypted config (inner-key ciphertext b64765710a1de8e7f5a2aa12f7fbe74c, sender ec2885bb…, recipient ea2ef4ef…, password a407d5de…), decrypted to sender/login 13819561419@163.com, password sr199641, recipient 13228527909@163.com - i.e. the same operator. Indicators:
13819561419@163.com, 13228527909@163.com.Recovered configuration
app_label
秒赞神器
exfil_smtp
smtp.163.com:25
package
com.qqmagic
recipient
13228527909@163.com
sender_login
13819561419@163.com
sender_password
sr199641
Identification
- SHA-256
- ce88455c0a4b69278fe480c106a6482ed295df90a516bb95dea4269febd0e997
- MD5
- 0a5d73b773d6360b5660a368cd39c6ce
Observed
- Families
- QQ Credential Stealer (provisional)
- First seen
- 2017-06-05
C2 configuration (2)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 13228527909@163.com | domain | - | - | QQ Credential Stealer (provisional) | 2017-06-05 |
| 13819561419@163.com | domain | - | - | QQ Credential Stealer (provisional) | 2017-06-05 |
Signing certificate
- Subject CN
- xyb
- Issuer CN
- xyb
- Fingerprint
- cae288b4b30995f1eb8aa8366999bef7e23551714b12bb5cc6939e1a9c5cb877
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.