162ce2ad2611626988c85203…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
162ce2ad2611626988c8520366f1f76feca2c75505a3686c955ecc25f4946442
MD5
—

Observed

Families
DCHSpy
First seen
2025-07-02

C2 configuration (10)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
r1.earthvpn.org/ domain 3413 https DCHSpy 2025-07-02
r2.earthvpn.org/ domain 3413 https DCHSpy 2025-07-02
vm1.netjustfun.com domain 8763 — DCHSpy 2025-07-02
vm2.netjustfun.com domain 8763 — DCHSpy 2025-07-02
vm3.netjustfun.com domain 8763 — DCHSpy 2025-07-02
vm4.netjustfun.com domain 8763 — DCHSpy 2025-07-02
185.252.215.129 ip 8763 — DCHSpy 2025-07-02
45.153.229.158 ip 8763 — DCHSpy 2025-07-02
45.67.229.68 ip 8763 — DCHSpy 2025-07-02
45.87.154.87 ip 8763 — DCHSpy 2025-07-02

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Fingerprint
afa47e0fc07dfae6ff1216babdec4c15c0891f8b62ff3b1a064c47c3f1a5b020

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About DCHSpy

Android surveillanceware leveraged by Iranian cyber espionage group MuddyWater (MOIS-linked), distributed via Telegram as fake VPN apps (EarthVPN, ComodoVPN, HideVPN) with activist/journalist targeting. Collects WhatsApp data, accounts, contacts, SMS, files, location, call logs, audio and photos; exfiltrates over SFTP. Shares infrastructure with SandStrike.