65c655663b9bd756864591a6…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
65c655663b9bd756864591a605ab935e52e5295735cb8d31d16e1a6bc2c19c28
MD5
ac96ffa987aa725ebcf8f93039a7d66d

Observed

Families
Xenomorph
First seen
2022-07-28

C2 configuration (4)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
datasciensonline.us domain — — Xenomorph 2022-07-28
gogoanalytics.click domain — — Xenomorph 2022-07-28
mybizzl.com domain — — Xenomorph 2022-07-28
sallaka.com domain — — Xenomorph 2022-07-28

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Xenomorph

Android banking trojan distributed as malware-as-a-service, famous for its heavy abuse of Android accessibility services to steal credentials from dozens of banking and crypto apps. C2 domains are RC4-encrypted (key + ":::" marker) inside the DEX.