ab345951a3e673aec99f80d3…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
ab345951a3e673aec99f80d39fa8f9cdb0d1ac07e0322dae3497c237f7b37277
MD5
42efd88844b49e05ec19dd831354093a

Observed

Families
Xenomorph
First seen
2022-08-09

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
gogoanalytics.click domain — — Xenomorph 2022-08-09

Signing certificate

Subject CN
Milky Way
Issuer CN
Milky Way
Fingerprint
c886911f1a2e9915cbcf20c070b75e2e92142ab357039003f9aa3a6197734c6f

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Xenomorph

Android banking trojan distributed as malware-as-a-service, famous for its heavy abuse of Android accessibility services to steal credentials from dozens of banking and crypto apps. C2 domains are RC4-encrypted (key + ":::" marker) inside the DEX.