it1.comodo-vpn.com:1953
domainTracked by C2 Tracker · Whois queried 2026-10-04T20:44:33
Registration
- Registrar
- —
- Registered
- —
- Expires
- —
DNS
- Resolves to
- —
- Nameservers
- —
- Status
- —
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| DCHSpy | 48d1fd4ed521… | 2025-07-21 |
Attributed to: MuddyWater
About DCHSpy
Android surveillanceware leveraged by Iranian cyber espionage group MuddyWater (MOIS-linked), distributed via Telegram as fake VPN apps (EarthVPN, ComodoVPN, HideVPN) with activist/journalist targeting. Collects WhatsApp data, accounts, contacts, SMS, files, location, call logs, audio and photos; exfiltrates over SFTP. Shares infrastructure with SandStrike.
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Valid
- 2023-12-14 → 2053-12-06
- Fingerprint
- afa47e0fc07dfae6ff1216babdec4c15c0891f8b62ff3b1a064c47c3f1a5b020
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.