DCHSpy

Malware family · 4 sample(s) · 39 indicator record(s) · 2 signing certificate(s)

About DCHSpy

Android surveillanceware leveraged by Iranian cyber espionage group MuddyWater (MOIS-linked), distributed via Telegram as fake VPN apps (EarthVPN, ComodoVPN, HideVPN) with activist/journalist targeting. Collects WhatsApp data, accounts, contacts, SMS, files, location, call logs, audio and photos; exfiltrates over SFTP. Shares infrastructure with SandStrike.

Indicators

IndicatorTypeSampleFirst seen
it1.comodo-vpn.com:1953 domain 48d1fd4ed521… 2025-07-21
r1.earthvpn.org:3413/ domain 162ce2ad2611… 2025-07-02
r1.earthvpn.org:1254/ domain a4913f52bd90… 2025-07-21
r1.earthvpn.org:1254/ domain aa656a243d20… 2025-06-19
r2.earthvpn.org:3413/ domain 162ce2ad2611… 2025-07-02
r2.earthvpn.org:1254/ domain a4913f52bd90… 2025-07-21
r2.earthvpn.org:1254/ domain aa656a243d20… 2025-06-19
vm1.netjustfun.com:8763 domain 162ce2ad2611… 2025-07-02
vm1.netjustfun.com:8763 domain 48d1fd4ed521… 2025-07-21
vm1.netjustfun.com:8763 domain a4913f52bd90… 2025-07-21
vm1.netjustfun.com:8763 domain aa656a243d20… 2025-06-19
vm2.netjustfun.com:8763 domain 162ce2ad2611… 2025-07-02
vm2.netjustfun.com:8763 domain 48d1fd4ed521… 2025-07-21
vm2.netjustfun.com:8763 domain a4913f52bd90… 2025-07-21
vm2.netjustfun.com:8763 domain aa656a243d20… 2025-06-19
vm3.netjustfun.com:8763 domain 162ce2ad2611… 2025-07-02
vm3.netjustfun.com:8763 domain 48d1fd4ed521… 2025-07-21
vm3.netjustfun.com:8763 domain a4913f52bd90… 2025-07-21
vm3.netjustfun.com:8763 domain aa656a243d20… 2025-06-19
vm4.netjustfun.com:8763 domain 162ce2ad2611… 2025-07-02
vm4.netjustfun.com:8763 domain 48d1fd4ed521… 2025-07-21
vm4.netjustfun.com:8763 domain a4913f52bd90… 2025-07-21
vm4.netjustfun.com:8763 domain aa656a243d20… 2025-06-19
185.252.215.129:8763 ip 162ce2ad2611… 2025-07-02
185.252.215.129:8763 ip 48d1fd4ed521… 2025-07-21
185.252.215.129:8763 ip a4913f52bd90… 2025-07-21
185.252.215.129:8763 ip aa656a243d20… 2025-06-19
45.153.229.158:8763 ip 162ce2ad2611… 2025-07-02
45.153.229.158:8763 ip 48d1fd4ed521… 2025-07-21
45.153.229.158:8763 ip a4913f52bd90… 2025-07-21
45.153.229.158:8763 ip aa656a243d20… 2025-06-19
45.67.229.68:8763 ip 162ce2ad2611… 2025-07-02
45.67.229.68:8763 ip 48d1fd4ed521… 2025-07-21
45.67.229.68:8763 ip a4913f52bd90… 2025-07-21
45.67.229.68:8763 ip aa656a243d20… 2025-06-19
45.87.154.87:8763 ip 162ce2ad2611… 2025-07-02
45.87.154.87:8763 ip 48d1fd4ed521… 2025-07-21
45.87.154.87:8763 ip a4913f52bd90… 2025-07-21
45.87.154.87:8763 ip aa656a243d20… 2025-06-19

Detected samples without extractable endpoint (1)

Family matched by code marker or hash attribution, but no C2 is statically extractable — the endpoint arrives at runtime.

SHA-256PackageNoteFirst seen
55e8b2d87f80… hazrateeshgh.apk Flutter-built "Hazrate Eshgh" (حضرت عشق) gallery app themed on Mahsa (Jina) Amini - a political lure matching DCHSpy's Telegram distribution to Farsi speakers. SHA-1 listed in Lookout's DCHSpy IoCs; no endpoint is statically extractable from the Flutter build (config fetched at runtime), so this is a code-/hash-level attribution. source 2024-04-13