v4ag1api.ecomall-app-ag1.info
domain C2Tracked by C2 Tracker · Whois queried never
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- -
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| PushAction SMS Stealer (provisional) | cb2b6e2be2de… | C2 | 2023-04-17 |
| PushAction SMS Stealer (provisional) | c59e18e8657a… | C2 | 2023-07-03 |
| PushAction SMS Stealer (provisional) | ca659b54ae22… | C2 | 2023-11-13 |
| PushAction SMS Stealer (provisional) | d54043ddcb41… | C2 | 2023-12-01 |
| PushAction SMS Stealer (provisional) | 779f775b2a7a… | C2 | 2023-12-13 |
About PushAction SMS Stealer (provisional)
Long-running SMS-stealer group that ships DCloud / uni-app hybrid Android apps (main activity `io.dcloud.PandoraEntry`) disguised as e-commerce, delivery, grocery and services lures, first documented against Malaysian users by Fareed Fauzi (Dec 2022). A static `SmsReceiver` intercepts incoming SMS and calls `abortBroadcast()`; the message body, sender, Android device id and timestamp are HTTP-POSTed to the operator server, and entered banking credentials go to a separate phishing kit. The C2 base rotates across many disposable domains (mall-base-app.com, ecomall-app-ag1.info, pos-express-node.com, post-yundeck.top, zero-dustapps.com, towncenter-appsv4-0001.info, maids-app.info, productapps1011.win, hungryduit.online, …) but the exfil API path is the stable fingerprint: `https://<host>/app/(api/)action/<name>PushAction/` (defaultSmsPushAction, smsMessagePushAction, smsPermissionPushAction, deviceActivePushAction). C2 hosts are taken from those endpoints, not from a single hardcoded config string. Provisional bucket pending formal attribution.
Signing certificate
- Subject CN
- supermegamall
- Issuer CN
- supermegamall
- Valid
- 2023-06-20 → 2024-06-19
- Fingerprint
- 70e26d7ec6df25390cc4fca08beb258d212084daf1d3a4def606ecaa143a2301
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.