e14f99608a8d16cdd17786d2…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- e14f99608a8d16cdd17786d218e173b44bbf9d5e30387d949a72604ec29cc4c6
- MD5
- 21ad6eed6cc52a723f51fc425035067b
Observed
- Families
- APT-C-23
- First seen
- 2018-06-10
C2 configuration (2)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| mediauploader.info | domain | — | http | APT-C-23 | 2018-06-10 |
| upload101.net/android/domains | domain | — | http | APT-C-23 | 2018-06-10 |
Signing certificate
- Subject CN
- Jamal Hassan
- Issuer CN
- Jamal Hassan
- Fingerprint
- 26768fa08ed2ec3f4ca429c1dad626548fd92bf9a3a333497ed864b72640be61
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About APT-C-23
Android spyware operated by the Gaza-nexus actor tracked as APT-C-23 (a.k.a. Arid Viper, Two-tailed Scorpion; MITRE ATT&CK G1028), used against targets in the Middle East. Apps disguise themselves as legitimate services (chat, updates) and carry call interception, SMS exfiltration and screen-recording capability. Identification rests on a four-part fingerprint (INTERNET permission, MainActivity, receivers.CallReceiver, services.CellService); the http(s) C2 URLs sit as const-strings in the <clinit> of the update/app/a class.