e14f99608a8d16cdd17786d2…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
e14f99608a8d16cdd17786d218e173b44bbf9d5e30387d949a72604ec29cc4c6
MD5
21ad6eed6cc52a723f51fc425035067b

Observed

Families
APT-C-23
First seen
2018-06-10

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
mediauploader.info domain — http APT-C-23 2018-06-10
upload101.net/android/domains domain — http APT-C-23 2018-06-10

Signing certificate

Subject CN
Jamal Hassan
Issuer CN
Jamal Hassan
Fingerprint
26768fa08ed2ec3f4ca429c1dad626548fd92bf9a3a333497ed864b72640be61

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About APT-C-23

Android spyware operated by the Gaza-nexus actor tracked as APT-C-23 (a.k.a. Arid Viper, Two-tailed Scorpion; MITRE ATT&CK G1028), used against targets in the Middle East. Apps disguise themselves as legitimate services (chat, updates) and carry call interception, SMS exfiltration and screen-recording capability. Identification rests on a four-part fingerprint (INTERNET permission, MainActivity, receivers.CallReceiver, services.CellService); the http(s) C2 URLs sit as const-strings in the <clinit> of the update/app/a class.