aa656a243d2008327e06fd5b…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- aa656a243d2008327e06fd5bbad919eea99aa271132dbaeabb146e22effbfd1b
- MD5
- 3682be86f3ae1d874e40fb4e282527a9
Observed
- Families
- DCHSpy
- First seen
- 2025-06-19
C2 configuration (10)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| r1.earthvpn.org/ | domain | 1254 | https | DCHSpy | 2025-06-19 |
| r2.earthvpn.org/ | domain | 1254 | https | DCHSpy | 2025-06-19 |
| vm1.netjustfun.com | domain | 8763 | — | DCHSpy | 2025-06-19 |
| vm2.netjustfun.com | domain | 8763 | — | DCHSpy | 2025-06-19 |
| vm3.netjustfun.com | domain | 8763 | — | DCHSpy | 2025-06-19 |
| vm4.netjustfun.com | domain | 8763 | — | DCHSpy | 2025-06-19 |
| 185.252.215.129 | ip | 8763 | — | DCHSpy | 2025-06-19 |
| 45.153.229.158 | ip | 8763 | — | DCHSpy | 2025-06-19 |
| 45.67.229.68 | ip | 8763 | — | DCHSpy | 2025-06-19 |
| 45.87.154.87 | ip | 8763 | — | DCHSpy | 2025-06-19 |
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Fingerprint
- cd7cf3738547a1786094274f6e8a9e20595da1b1117453f5c49f7e7dd8a22fbd
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About DCHSpy
Android surveillanceware leveraged by Iranian cyber espionage group MuddyWater (MOIS-linked), distributed via Telegram as fake VPN apps (EarthVPN, ComodoVPN, HideVPN) with activist/journalist targeting. Collects WhatsApp data, accounts, contacts, SMS, files, location, call logs, audio and photos; exfiltrates over SFTP. Shares infrastructure with SandStrike.