upload999.info

domain not resolving

Tracked by C2 Tracker · Whois queried 2026-10-04T15:56:15

Registration

Registrar
—
Registered
—
Expires
—

DNS

Resolves to
—
Nameservers
—
Status
—

Observed in malware

FamilySample SHA-256First seen
APT-C-23 ca87cc9898af… 2019-08-29

About APT-C-23

Android spyware operated by the Gaza-nexus actor tracked as APT-C-23 (a.k.a. Arid Viper, Two-tailed Scorpion; MITRE ATT&CK G1028), used against targets in the Middle East. Apps disguise themselves as legitimate services (chat, updates) and carry call interception, SMS exfiltration and screen-recording capability. Identification rests on a four-part fingerprint (INTERNET permission, MainActivity, receivers.CallReceiver, services.CellService); the http(s) C2 URLs sit as const-strings in the <clinit> of the update/app/a class.

Signing certificate

Subject CN
User One
Issuer CN
User One
Valid
2016-09-10 → 2041-09-04
Fingerprint
864ffd08404c3dba5ebc92a66d1fc0cea40bf81734fa6a8285bfd797b9830340

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.