041b9066f42b78c5f2c9ff25…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
041b9066f42b78c5f2c9ff25a3bba3155a21c21fa0ee55aea510f456b3bc1847
MD5
cf5e62ebbf4be2417b9d3849c3c3f9c9

Observed

Families
APT-C-27
First seen
2018-07-18

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
82.137.255.56 ip 1740 — APT-C-27 2018-07-18

Signing certificate

Subject CN
hmza
Issuer CN
hmza
Fingerprint
0ff88fd1031138a2f72904ca3a03ea14ffeb1d5d79d1da74b50a65cd8baa8c85

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About APT-C-27

Android spyware attributed to the Goldmouse group (ETDA tracks it as APT-C-27). Identification rests on a four-part manifest fingerprint (INTERNET permission, MainActivity, the deliberately misspelled SystemUpten receiver, and the NetService/NtService service). The C2 IP and port are stored as static fields in the static initializer of the PcketPrvidr (sic) / PacketProvider config class.