8a20f9b697f962f7863b0eb5…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

PushAction SMS Stealer (provisional). Long-running SMS-stealer group that ships DCloud / uni-app hybrid Android apps (main activity io.dcloud.PandoraEntry) disguised as e-commerce, delivery, grocery and services lures, first documented against Malaysian users by Fareed Fauzi (Dec 2022). A static SmsReceiver intercepts incoming SMS and calls abortBroadcast(); the message body, sender, Android device id and timestamp are HTTP-POSTed to the operator server, and entered banking credentials go to a separate phishing kit. The C2 base rotates across many disposable domains (mall-base-app.com, ecomall-app-ag1.info, pos-express-node.com, post-yundeck.top, zero-dustapps.com, towncenter-appsv4-0001.info, maids-app.info, productapps1011.win, hungryduit.online, …) but the exfil API path is the stable fingerprint: https://<host>/app/(api/)action/<name>PushAction/ (defaultSmsPushAction, smsMessagePushAction, smsPermissionPushAction, deviceActivePushAction). C2 hosts are taken from those endpoints, not from a single hardcoded config string. Provisional bucket pending formal attribution. Indicators: sg3.mall-base-app.com.

Recovered configuration

c2_api
/app/(api/)action/*PushAction/
package
com.docktor.duck
wrapper
DCloud/uni-app (io.dcloud.PandoraEntry)

Identification

SHA-256
8a20f9b697f962f7863b0eb535b2c585d067f2c501f5a6388374f631001fdd47
MD5
ccb0e8380057a4c406996d5102079a4b

Observed

Families
PushAction SMS Stealer (provisional)
First seen
2023-01-05

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
sg3.mall-base-app.com domain - - PushAction SMS Stealer (provisional) 2023-01-05

Signing certificate

Subject CN
WJJ9RCpwJviiDlG%2F1xnnJ%2FQ2E9gOQPJeLU6HWQqkPRtB5B8FKswAhDigjnIDgCV%2B
Issuer CN
WJJ9RCpwJviiDlG%2F1xnnJ%2FQ2E9gOQPJeLU6HWQqkPRtB5B8FKswAhDigjnIDgCV%2B
Fingerprint
0d4fa0533bb9204b40523976fc1aa8abf9aa6578a82b11b03e3e10f3e11e649d

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About PushAction SMS Stealer (provisional)

Long-running SMS-stealer group that ships DCloud / uni-app hybrid Android apps (main activity `io.dcloud.PandoraEntry`) disguised as e-commerce, delivery, grocery and services lures, first documented against Malaysian users by Fareed Fauzi (Dec 2022). A static `SmsReceiver` intercepts incoming SMS and calls `abortBroadcast()`; the message body, sender, Android device id and timestamp are HTTP-POSTed to the operator server, and entered banking credentials go to a separate phishing kit. The C2 base rotates across many disposable domains (mall-base-app.com, ecomall-app-ag1.info, pos-express-node.com, post-yundeck.top, zero-dustapps.com, towncenter-appsv4-0001.info, maids-app.info, productapps1011.win, hungryduit.online, …) but the exfil API path is the stable fingerprint: `https://<host>/app/(api/)action/<name>PushAction/` (defaultSmsPushAction, smsMessagePushAction, smsPermissionPushAction, deviceActivePushAction). C2 hosts are taken from those endpoints, not from a single hardcoded config string. Provisional bucket pending formal attribution.