a4913f52bd90add74b796852…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
a4913f52bd90add74b796852e2a1d9acb1d6ecffe359b5710c59c82af59483ec
MD5
48ab25bc1b06eaf2cbbdfed3c3127cea

Observed

Families
DCHSpy
First seen
2025-07-21

C2 configuration (10)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
r1.earthvpn.org/ domain 1254 https DCHSpy 2025-07-21
r2.earthvpn.org/ domain 1254 https DCHSpy 2025-07-21
vm1.netjustfun.com domain 8763 — DCHSpy 2025-07-21
vm2.netjustfun.com domain 8763 — DCHSpy 2025-07-21
vm3.netjustfun.com domain 8763 — DCHSpy 2025-07-21
vm4.netjustfun.com domain 8763 — DCHSpy 2025-07-21
185.252.215.129 ip 8763 — DCHSpy 2025-07-21
45.153.229.158 ip 8763 — DCHSpy 2025-07-21
45.67.229.68 ip 8763 — DCHSpy 2025-07-21
45.87.154.87 ip 8763 — DCHSpy 2025-07-21

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Fingerprint
cd7cf3738547a1786094274f6e8a9e20595da1b1117453f5c49f7e7dd8a22fbd

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About DCHSpy

Android surveillanceware leveraged by Iranian cyber espionage group MuddyWater (MOIS-linked), distributed via Telegram as fake VPN apps (EarthVPN, ComodoVPN, HideVPN) with activist/journalist targeting. Collects WhatsApp data, accounts, contacts, SMS, files, location, call logs, audio and photos; exfiltrates over SFTP. Shares infrastructure with SandStrike.