fd1aac87399ad22234c503d8…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
https://internetwideband.com/user/.Identification
- SHA-256
- fd1aac87399ad22234c503d8adb2ae9f0d950b6edf4456b1515a30100b5656a7
- MD5
- d9d34d6627ae3150bd574b6523995d9a
Observed
- Families
- StrongPity
- First seen
- 2021-05-24
APK metadata
Summary
- Type
- Android · APK
- Package
- com.egov.app
- Main activity
- com.egov.app.ui.SplashActivity
- Internal version
- 4
- Displayed version
- 1.3
- Min SDK
- 22
- Target SDK
- 22
Signing certificate
- Valid from
- 2020-07-16 16:04:53
- Valid to
- 2045-07-10 16:04:53
- Serial
- 1774a69b
- Thumbprint
- 6714ebd436f81da8a7795f47d74801330c69f189
- Subject
- C:CA, CN:Elizabeth Mckinsen, L:Toronto, O:Mobility, ST:Toronto, OU:Android Dev Team
- Issuer
- C:CA, CN:Elizabeth Mckinsen, L:Toronto, O:Mobility, ST:Toronto, OU:Android Dev Team
Permissions (10)
Intent filters - actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| internetwideband.com/user/ | domain | - | https | StrongPity | 2021-05-24 |
Signing certificate
- Subject CN
- Elizabeth Mckinsen
- Issuer CN
- Elizabeth Mckinsen
- Fingerprint
- da944f2879dcb7f7061754f3cec1d59da1eabb78e6b1ba96cfd5daf0acad029f
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About StrongPity
**StrongPity** (aka **Promethium** / APT-C-41) is a long-running espionage actor known for watering-hole distribution of trojanized legitimate installers. Its Android branch, documented by ESET in 2023, ships a backdoored build of a real app (for example Shagle video-chat / Telegram-style apps) whose modular malicious component activates when a matching C2 is reachable. It harvests call logs, SMS, contacts, device and location data and files, records calls and enumerates installed apps, uploading to attacker infrastructure (internetwideband.com, networktopologymaps.com, www.upeg-system-app.com). Historically associated with Turkey/Syria-nexus targeting. APT / state-aligned.