ce88455c0a4b69278fe480c1…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

QQ Credential Stealer (provisional) - an Android information/credential stealer, self-signed as “xyb”. Communicates with 2 operator endpoints. QQ credential-stealer (label 秒赞神器 ‘auto-like tool’, package com.qqmagic, built with AIDE). Phishes the victim’s QQ serial/account and password and exfiltrates them by email via smtp.163.com:25 (JavaMail). The mail credentials and recipient are the SAME as sample 5aa9f206 - identical DES-encrypted config (inner-key ciphertext b64765710a1de8e7f5a2aa12f7fbe74c, sender ec2885bb…, recipient ea2ef4ef…, password a407d5de…), decrypted to sender/login 13819561419@163.com, password sr199641, recipient 13228527909@163.com - i.e. the same operator. Indicators: 13819561419@163.com, 13228527909@163.com.

Recovered configuration

app_label
秒赞神器
exfil_smtp
smtp.163.com:25
package
com.qqmagic
recipient
13228527909@163.com
sender_login
13819561419@163.com
sender_password
sr199641

Identification

SHA-256
ce88455c0a4b69278fe480c106a6482ed295df90a516bb95dea4269febd0e997
MD5
0a5d73b773d6360b5660a368cd39c6ce

Observed

Families
QQ Credential Stealer (provisional)
First seen
2017-06-05

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
13228527909@163.com domain - - QQ Credential Stealer (provisional) 2017-06-05
13819561419@163.com domain - - QQ Credential Stealer (provisional) 2017-06-05

Signing certificate

Subject CN
xyb
Issuer CN
xyb
Fingerprint
cae288b4b30995f1eb8aa8366999bef7e23551714b12bb5cc6939e1a9c5cb877

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.