62c6b65fabcf0e3e5c8a4f39…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
io.dcloud.PandoraEntry) disguised as e-commerce, delivery, grocery and services lures, first documented against Malaysian users by Fareed Fauzi (Dec 2022). A static SmsReceiver intercepts incoming SMS and calls abortBroadcast(); the message body, sender, Android device id and timestamp are HTTP-POSTed to the operator server, and entered banking credentials go to a separate phishing kit. The C2 base rotates across many disposable domains (mall-base-app.com, ecomall-app-ag1.info, pos-express-node.com, post-yundeck.top, zero-dustapps.com, towncenter-appsv4-0001.info, maids-app.info, productapps1011.win, hungryduit.online, …) but the exfil API path is the stable fingerprint: https://<host>/app/(api/)action/<name>PushAction/ (defaultSmsPushAction, smsMessagePushAction, smsPermissionPushAction, deviceActivePushAction). C2 hosts are taken from those endpoints, not from a single hardcoded config string. Provisional bucket pending formal attribution. Indicators: api.post-yundeck.top.Recovered configuration
Identification
- SHA-256
- 62c6b65fabcf0e3e5c8a4f39eb1d8cba5b72f31e72fe80d08fe75f23d2b490c2
- MD5
- 02c080da7a111f7b51e1adfa313a17af
Observed
- Families
- PushAction SMS Stealer (provisional)
- First seen
- 2024-12-04
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| api.post-yundeck.top | domain | - | - | PushAction SMS Stealer (provisional) | 2024-12-04 |
Signing certificate
- Subject CN
- thackerayesque
- Issuer CN
- thackerayesque
- Fingerprint
- 945107ef781e6217906181470708bf6ac375e8b09df388af6855a68059961f94
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About PushAction SMS Stealer (provisional)
Long-running SMS-stealer group that ships DCloud / uni-app hybrid Android apps (main activity `io.dcloud.PandoraEntry`) disguised as e-commerce, delivery, grocery and services lures, first documented against Malaysian users by Fareed Fauzi (Dec 2022). A static `SmsReceiver` intercepts incoming SMS and calls `abortBroadcast()`; the message body, sender, Android device id and timestamp are HTTP-POSTed to the operator server, and entered banking credentials go to a separate phishing kit. The C2 base rotates across many disposable domains (mall-base-app.com, ecomall-app-ag1.info, pos-express-node.com, post-yundeck.top, zero-dustapps.com, towncenter-appsv4-0001.info, maids-app.info, productapps1011.win, hungryduit.online, …) but the exfil API path is the stable fingerprint: `https://<host>/app/(api/)action/<name>PushAction/` (defaultSmsPushAction, smsMessagePushAction, smsPermissionPushAction, deviceActivePushAction). C2 hosts are taken from those endpoints, not from a single hardcoded config string. Provisional bucket pending formal attribution.