0601fc10951b780efb7da41b…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

ZooPark. ZooPark is a long-running Android surveillance operation first exposed by Kaspersky in 2018, aimed at targets across the Middle East (Egypt, Iran, Lebanon, Morocco, Jordan). It spreads through compromised or official-looking news and political sites and Telegram channels, masquerading as government, electoral or messaging utilities (the observed entekhab10.xp3.biz lure echoes the Iranian Entekhab news brand). Capabilities grew across four generations from simple SMS/call-log theft to full spyware: exfiltration of contacts, SMS, call logs, GPS location, keylogs, camera photos and the Telegram/WhatsApp/browser databases. Stolen data is uploaded to operator dead-drop C2 web servers (androidupdaters.com, www.rhubarb2.com, www.rhubarb3.com). APT / state-aligned. Indicators: http://entekhab10.xp3.biz/ent/index.php.

Identification

SHA-256
0601fc10951b780efb7da41b25f1e41fdb347374e81858cc894e8d8fd2106b7b
MD5
5efddd7f0fc2125e78a2ca18b68464ec

Observed

Families
ZooPark
First seen
2018-05-03

APK metadata

Summary

Type
Android · APK
Package
com.app.entekhab10
Main activity
com.app.entekhab10.MainActivity
Internal version
3
Displayed version
3.0
Min SDK
8
Target SDK
17

Signing certificate

Valid from
2015-06-20 06:01:47
Valid to
2045-06-12 06:01:47
Serial
55f872cb
Thumbprint
b5c759aea06ead171113bf211fd350a15ebb143f
Subject
C:US, CN:Android Debug, O:Android
Issuer
C:US, CN:Android Debug, O:Android

Permissions (4)

android.permission.ACCESS_NETWORK_STATEandroid.permission.GET_ACCOUNTSandroid.permission.INTERNETandroid.permission.READ_CONTACTS

Activities (4)

  • com.app.entekhab10.AmarActivity
  • com.app.entekhab10.DavatActivity
  • com.app.entekhab10.MainActivity
  • com.app.entekhab10.SelectSActivity

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
entekhab10.xp3.biz/ent/index.php domain - http ZooPark 2018-05-03

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Fingerprint
9fda4b172aed8ae576216134265f3b31f5d4506540fda893240234d4783f2c44

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About ZooPark

**ZooPark** is a long-running Android surveillance operation first exposed by Kaspersky in 2018, aimed at targets across the **Middle East** (Egypt, Iran, Lebanon, Morocco, Jordan). It spreads through compromised or official-looking news and political sites and Telegram channels, masquerading as government, electoral or messaging utilities (the observed entekhab10.xp3.biz lure echoes the Iranian Entekhab news brand). Capabilities grew across four generations from simple SMS/call-log theft to full spyware: exfiltration of contacts, SMS, call logs, GPS location, keylogs, camera photos and the Telegram/WhatsApp/browser databases. Stolen data is uploaded to operator dead-drop C2 web servers (androidupdaters.com, www.rhubarb2.com, www.rhubarb3.com). APT / state-aligned.