0c5b37b48769df1f88d84137…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
0c5b37b48769df1f88d84137c2084bd023b7d6d44a3bdc62ef8c370f3c15fec5
MD5
681ff974adb54692e61551f9640f76bf

Observed

Families
APT36
First seen
2020-05-02

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
tryanotherhorse.com/config.txt domain — http APT36 2020-05-02

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About APT36

Android spyware of Transparent Tribe (APT36, "ProjectM" / "C-Major"), a Pakistan-nexus APT running South-Asia campaigns (documented by Kaspersky, Aug 2020). Simple, non-sophisticated implants with a recognizable manifest fingerprint: a `.MainS` service plus `.MyReceive` and `.CallReceive` receivers. The live C2 is not hardcoded - IOSocket carries a base64 const-string decoding to an online config URL (e.g. tryanotherhorse.com/config.txt) whose body the Config class parses for "Server IP" / "Domain Addr" at runtime.