sg1.mall-base-app.com

domain C2 not resolving

Tracked by C2 Tracker · Whois queried never

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
-
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
PushAction SMS Stealer (provisional) 74d59c0eaa55… C2 2022-11-15
PushAction SMS Stealer (provisional) 2a406ff7983d… C2 2022-11-27
PushAction SMS Stealer (provisional) 8b49fe8fb684… C2 2022-11-27
PushAction SMS Stealer (provisional) aa16d37a2d19… C2 2022-12-06
PushAction SMS Stealer (provisional) 36f09582434c… C2 2022-12-11
PushAction SMS Stealer (provisional) 6d0c359cbadd… C2 2022-12-11
PushAction SMS Stealer (provisional) 513a514d553b… C2 2022-12-11
PushAction SMS Stealer (provisional) 9a961af2cd63… C2 2022-12-11
PushAction SMS Stealer (provisional) 7e77a9ed50fb… C2 2022-12-14
PushAction SMS Stealer (provisional) e117bb9f52e7… C2 2022-12-14
PushAction SMS Stealer (provisional) 633655483e23… C2 2022-12-25
PushAction SMS Stealer (provisional) 9cd4d6872d8d… C2 2022-12-25
PushAction SMS Stealer (provisional) ed7eb9ccbda0… C2 2022-12-25
PushAction SMS Stealer (provisional) a94809f0654c… C2 2022-12-31

About PushAction SMS Stealer (provisional)

Long-running SMS-stealer group that ships DCloud / uni-app hybrid Android apps (main activity `io.dcloud.PandoraEntry`) disguised as e-commerce, delivery, grocery and services lures, first documented against Malaysian users by Fareed Fauzi (Dec 2022). A static `SmsReceiver` intercepts incoming SMS and calls `abortBroadcast()`; the message body, sender, Android device id and timestamp are HTTP-POSTed to the operator server, and entered banking credentials go to a separate phishing kit. The C2 base rotates across many disposable domains (mall-base-app.com, ecomall-app-ag1.info, pos-express-node.com, post-yundeck.top, zero-dustapps.com, towncenter-appsv4-0001.info, maids-app.info, productapps1011.win, hungryduit.online, …) but the exfil API path is the stable fingerprint: `https://<host>/app/(api/)action/<name>PushAction/` (defaultSmsPushAction, smsMessagePushAction, smsPermissionPushAction, deviceActivePushAction). C2 hosts are taken from those endpoints, not from a single hardcoded config string. Provisional bucket pending formal attribution.

Signing certificate

Subject CN
s96zl3CwoigBXNy6qXE7GXOnMUKRwU0%2FK0VrPX24788mlVtqHGWYz7c6ny05QGTmgzRrHu1%2BIHIRme0ZDzohGg%3D%3D
Issuer CN
s96zl3CwoigBXNy6qXE7GXOnMUKRwU0%2FK0VrPX24788mlVtqHGWYz7c6ny05QGTmgzRrHu1%2BIHIRme0ZDzohGg%3D%3D
Valid
2022-07-09 → 2122-06-15
Fingerprint
906f76a3469e6f25ede3de907a3bfe6202026c7cb64aec0029282a565922c843

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.