309523ecd0c4bc5e337005e7…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
http://www.rhubarb3.com/.Identification
- SHA-256
- 309523ecd0c4bc5e337005e71666da3711d0cda519100d5d5aa019b22dc61cbd
- MD5
- b44b91b14f176fbf93d998141931a4aa
Observed
- Families
- ZooPark
- First seen
- 2018-05-08
APK metadata
Summary
- Type
- Android · APK
- Package
- com.del.tele.acc
- Main activity
- com.del.tele.acc.main
- Internal version
- 5
- Displayed version
- 5
- Min SDK
- 5
- Target SDK
- 14
Signing certificate
- Valid from
- 2017-05-25 05:56:55
- Valid to
- 2044-10-10 05:56:55
- Serial
- 25208471
- Thumbprint
- e1326479b5ece0495aa57c92d20366ee08073937
- Subject
- C:e, CN:t, L:m, O:m, ST:f, OU:e
- Issuer
- C:e, CN:t, L:m, O:m, ST:f, OU:e
Permissions (23)
Intent filters - actions
Intent filters - categories
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| www.rhubarb3.com/ | domain | - | http | ZooPark | 2018-05-08 |
Signing certificate
- Subject CN
- t
- Issuer CN
- t
- Fingerprint
- 5635068bf7eda25aab043748243c75b5cedbabced9b510822220d380a27f3fd8
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About ZooPark
**ZooPark** is a long-running Android surveillance operation first exposed by Kaspersky in 2018, aimed at targets across the **Middle East** (Egypt, Iran, Lebanon, Morocco, Jordan). It spreads through compromised or official-looking news and political sites and Telegram channels, masquerading as government, electoral or messaging utilities (the observed entekhab10.xp3.biz lure echoes the Iranian Entekhab news brand). Capabilities grew across four generations from simple SMS/call-log theft to full spyware: exfiltration of contacts, SMS, call logs, GPS location, keylogs, camera photos and the Telegram/WhatsApp/browser databases. Stolen data is uploaded to operator dead-drop C2 web servers (androidupdaters.com, www.rhubarb2.com, www.rhubarb3.com). APT / state-aligned.