sg1.mall-base-app.com
domain C2Tracked by C2 Tracker · Whois queried never
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- -
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| PushAction SMS Stealer (provisional) | 74d59c0eaa55… | C2 | 2022-11-15 |
| PushAction SMS Stealer (provisional) | 2a406ff7983d… | C2 | 2022-11-27 |
| PushAction SMS Stealer (provisional) | 8b49fe8fb684… | C2 | 2022-11-27 |
| PushAction SMS Stealer (provisional) | aa16d37a2d19… | C2 | 2022-12-06 |
| PushAction SMS Stealer (provisional) | 36f09582434c… | C2 | 2022-12-11 |
| PushAction SMS Stealer (provisional) | 6d0c359cbadd… | C2 | 2022-12-11 |
| PushAction SMS Stealer (provisional) | 513a514d553b… | C2 | 2022-12-11 |
| PushAction SMS Stealer (provisional) | 9a961af2cd63… | C2 | 2022-12-11 |
| PushAction SMS Stealer (provisional) | 7e77a9ed50fb… | C2 | 2022-12-14 |
| PushAction SMS Stealer (provisional) | e117bb9f52e7… | C2 | 2022-12-14 |
| PushAction SMS Stealer (provisional) | 633655483e23… | C2 | 2022-12-25 |
| PushAction SMS Stealer (provisional) | 9cd4d6872d8d… | C2 | 2022-12-25 |
| PushAction SMS Stealer (provisional) | ed7eb9ccbda0… | C2 | 2022-12-25 |
| PushAction SMS Stealer (provisional) | a94809f0654c… | C2 | 2022-12-31 |
About PushAction SMS Stealer (provisional)
Long-running SMS-stealer group that ships DCloud / uni-app hybrid Android apps (main activity `io.dcloud.PandoraEntry`) disguised as e-commerce, delivery, grocery and services lures, first documented against Malaysian users by Fareed Fauzi (Dec 2022). A static `SmsReceiver` intercepts incoming SMS and calls `abortBroadcast()`; the message body, sender, Android device id and timestamp are HTTP-POSTed to the operator server, and entered banking credentials go to a separate phishing kit. The C2 base rotates across many disposable domains (mall-base-app.com, ecomall-app-ag1.info, pos-express-node.com, post-yundeck.top, zero-dustapps.com, towncenter-appsv4-0001.info, maids-app.info, productapps1011.win, hungryduit.online, …) but the exfil API path is the stable fingerprint: `https://<host>/app/(api/)action/<name>PushAction/` (defaultSmsPushAction, smsMessagePushAction, smsPermissionPushAction, deviceActivePushAction). C2 hosts are taken from those endpoints, not from a single hardcoded config string. Provisional bucket pending formal attribution.
Signing certificate
- Subject CN
- s96zl3CwoigBXNy6qXE7GXOnMUKRwU0%2FK0VrPX24788mlVtqHGWYz7c6ny05QGTmgzRrHu1%2BIHIRme0ZDzohGg%3D%3D
- Issuer CN
- s96zl3CwoigBXNy6qXE7GXOnMUKRwU0%2FK0VrPX24788mlVtqHGWYz7c6ny05QGTmgzRrHu1%2BIHIRme0ZDzohGg%3D%3D
- Valid
- 2022-07-09 → 2122-06-15
- Fingerprint
- 906f76a3469e6f25ede3de907a3bfe6202026c7cb64aec0029282a565922c843
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.