2d0a56a347779ffdc3250dea…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- 2d0a56a347779ffdc3250deadda50008d6fae9b080c20892714348f8a44fca4b
- MD5
- 5de80e4b174f17776b07193a2280b252
Observed
- Families
- APT-C-27
- First seen
- 2018-07-16
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 82.137.255.56 | ip | 1740 | — | APT-C-27 | 2018-07-16 |
Signing certificate
- Subject CN
- hmza
- Issuer CN
- hmza
- Fingerprint
- 0ff88fd1031138a2f72904ca3a03ea14ffeb1d5d79d1da74b50a65cd8baa8c85
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About APT-C-27
Android spyware attributed to the Goldmouse group (ETDA tracks it as APT-C-27). Identification rests on a four-part manifest fingerprint (INTERNET permission, MainActivity, the deliberately misspelled SystemUpten receiver, and the NetService/NtService service). The C2 IP and port are stored as static fields in the static initializer of the PcketPrvidr (sic) / PacketProvider config class.