www.rhubarb3.com/get/index.php

domain C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:00

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
-
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
ZooPark 041b4d2280ca… C2 2016-11-26
ZooPark d7da061b55d2… C2 2017-09-24
ZooPark 309523ecd0c4… C2 2018-05-08
ZooPark adc712518e21… C2 2018-05-08
ZooPark ef4d8bf8fec8… C2 2018-05-08

About ZooPark

**ZooPark** is a long-running Android surveillance operation first exposed by Kaspersky in 2018, aimed at targets across the **Middle East** (Egypt, Iran, Lebanon, Morocco, Jordan). It spreads through compromised or official-looking news and political sites and Telegram channels, masquerading as government, electoral or messaging utilities (the observed entekhab10.xp3.biz lure echoes the Iranian Entekhab news brand). Capabilities grew across four generations from simple SMS/call-log theft to full spyware: exfiltration of contacts, SMS, call logs, GPS location, keylogs, camera photos and the Telegram/WhatsApp/browser databases. Stolen data is uploaded to operator dead-drop C2 web servers (androidupdaters.com, www.rhubarb2.com, www.rhubarb3.com). APT / state-aligned.

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Valid
2016-05-30 → 2046-05-23
Fingerprint
e8481264e75ca9f634da8bf5e84250b4c3d3515dc6632f0ad05022fec38fa3ed

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.