d7da061b55d24a54988a3fca…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

ZooPark. ZooPark is a long-running Android surveillance operation first exposed by Kaspersky in 2018, aimed at targets across the Middle East (Egypt, Iran, Lebanon, Morocco, Jordan). It spreads through compromised or official-looking news and political sites and Telegram channels, masquerading as government, electoral or messaging utilities (the observed entekhab10.xp3.biz lure echoes the Iranian Entekhab news brand). Capabilities grew across four generations from simple SMS/call-log theft to full spyware: exfiltration of contacts, SMS, call logs, GPS location, keylogs, camera photos and the Telegram/WhatsApp/browser databases. Stolen data is uploaded to operator dead-drop C2 web servers (androidupdaters.com, www.rhubarb2.com, www.rhubarb3.com). APT / state-aligned. Indicators: http://www.rhubarb3.com/.

Identification

SHA-256
d7da061b55d24a54988a3fca60009da907d14c2bcd32f2e53ef13bd8085b96cc
MD5
cb67abd070ae188390fc040cbe60e677

Observed

Families
ZooPark
First seen
2017-09-24

APK metadata

Summary

Type
Android · APK
Package
com.app.referendumkurdistan
Main activity
com.app.referendumkurdistan.MainActivity
Internal version
1
Displayed version
1.0
Min SDK
8
Target SDK
14

Signing certificate

Valid from
2016-05-30 09:44:34
Valid to
2046-05-23 09:44:34
Serial
1
Thumbprint
e27d9a4681ad655aa15ee78ad7535190e6c1caff
Subject
C:US, CN:Android Debug, O:Android
Issuer
C:US, CN:Android Debug, O:Android

Permissions (12)

android.permission.ACCESS_FINE_LOCATIONandroid.permission.ACCESS_NETWORK_STATEandroid.permission.GET_ACCOUNTSandroid.permission.INTERNETandroid.permission.READ_CALL_LOGandroid.permission.READ_CONTACTSandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.WRITE_EXTERNAL_STORAGEandroid.permission.WRITE_SECURE_SETTINGSandroid.permission.WRITE_SETTINGS

Activities (1)

  • com.app.referendumkurdistan.MainActivity

Services (1)

  • com.app.referendumkurdistan.MainService

Receivers (1)

  • com.app.referendumkurdistan.BootReceiver

Intent filters - actions

android.intent.action.BOOT_COMPLETED

Intent filters - categories

android.intent.category.DEFAULT

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
www.rhubarb3.com/ domain - http ZooPark 2017-09-24

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Fingerprint
e8481264e75ca9f634da8bf5e84250b4c3d3515dc6632f0ad05022fec38fa3ed

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About ZooPark

**ZooPark** is a long-running Android surveillance operation first exposed by Kaspersky in 2018, aimed at targets across the **Middle East** (Egypt, Iran, Lebanon, Morocco, Jordan). It spreads through compromised or official-looking news and political sites and Telegram channels, masquerading as government, electoral or messaging utilities (the observed entekhab10.xp3.biz lure echoes the Iranian Entekhab news brand). Capabilities grew across four generations from simple SMS/call-log theft to full spyware: exfiltration of contacts, SMS, call logs, GPS location, keylogs, camera photos and the Telegram/WhatsApp/browser databases. Stolen data is uploaded to operator dead-drop C2 web servers (androidupdaters.com, www.rhubarb2.com, www.rhubarb3.com). APT / state-aligned.