ca87cc9898af3883eca81aca…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
ca87cc9898af3883eca81aca658109fdd7ca2529dfbd45a25e0c6e7cf0b526e5
MD5
2a7576c896bb6f7710e9f41e0a25ce14

Observed

Families
APT-C-23
First seen
2019-08-29

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
upload101.net/android/domains domain — http APT-C-23 2019-08-29
upload999.info domain — http APT-C-23 2019-08-29

Signing certificate

Subject CN
User One
Issuer CN
User One
Fingerprint
864ffd08404c3dba5ebc92a66d1fc0cea40bf81734fa6a8285bfd797b9830340

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About APT-C-23

Android spyware operated by the Gaza-nexus actor tracked as APT-C-23 (a.k.a. Arid Viper, Two-tailed Scorpion; MITRE ATT&CK G1028), used against targets in the Middle East. Apps disguise themselves as legitimate services (chat, updates) and carry call interception, SMS exfiltration and screen-recording capability. Identification rests on a four-part fingerprint (INTERNET permission, MainActivity, receivers.CallReceiver, services.CellService); the http(s) C2 URLs sit as const-strings in the <clinit> of the update/app/a class.