Android Installer Dropper (provisional)
Malware family · 2 sample(s) · 2 indicator record(s) · 1 signing certificate(s)
About Android Installer Dropper (provisional)
Android Installer Dropper (provisional) is a label for multi-stage Android droppers whose job is to side-load and install an embedded, encrypted second-stage APK via PackageInstaller, often alongside a VpnService. One observed build (lure More Nutrition) decrypts an asset (XOR plus GZIP) to an in-memory orchestrator DEX that extracts an encrypted archive and installs the embedded b.apk; another ships an encrypted update.enc payload. The final payload and its C2 are recoverable only by dynamic analysis (running the sample and dumping the installed APK), so samples are tracked here pending a dynamic run. Family label provisional.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| raw.githubusercontent.com/mohanqquiku/Private-Database/main/lel.pah6y.ypoq.y1i0.bin | domain | 68335e8d9073… | 2026-10-10 |
| raw.githubusercontent.com/mohanqquiku/Private-Database/main/alp.df0rf.elq1.yk1o.bin | domain | 9e88db0dda56… | 2026-10-10 |
Detected samples without extractable endpoint (2)
Family matched by code marker or hash attribution, but no C2 is statically extractable - the endpoint arrives at runtime.
| SHA-256 | Package | Note | First seen |
|---|---|---|---|
| 52a98b6f60635e19461aa2aa4ba375f5e47388906bc0fe8a4e08ce4adb2e199f | - | Packed Android dropper (manifest stripped - androguard reports no package; a vpn service keh.kkfkk.dyf.vpn.* is declared). Ships a 4.2 MB encrypted payload assets/update.enc plus assets/di5puti6t8dsi.oam across 15 dex; the real payload is unpacked/installed at runtime. Payload is fully encrypted (entropy ~8.0) and the loader is not fully reversed; C2 not statically recoverable at reasonable cost - requires dynamic analysis. KIV - documented, C2 pending dynamic run. Family label provisional. source | 2026-10-09 |
| c31aedd2e16e528951f6e338185a9e220da800119ac3e4fa57de3bc9ba276e40 | com.addgqrec.xkc | Multi-layer PackageInstaller dropper (outer package com.yxpz.egbhp.uplzvjgnb.npenoart, lure 'More Nutrition'). Chain reversed statically: (1) Application.attachBaseContext decrypts assets/onUQLhOhOz (skip 24 bytes, big-endian int length, per byte (((b^0x38)-28)^0x70)&0xFF, then GZIP) to an in-memory DEX (com.shell.a orchestrator) loaded via InMemoryDexClassLoader and hooked in as the app classloader (ActivityThread mClassLoader reflection); (2) onCreate -> mfvetmxj extracts the assets/xPANlcnWnbe archive to filesDir/assets_i/; (3) com.shell.a installs the embedded assets_i/b.apk via PackageInstaller and runs a PpVpn VpnService. The real banker is b.apk inside xPANlcnWnbe, which is fully stream-encrypted (24-byte header + keystream XOR, no plaintext names/magic). C2 lives in b.apk and is NOT statically recoverable at reasonable cost; requires dynamic analysis (run + dump assets_i/b.apk or hook the installer). KIV - documented, C2 pending dynamic run. Family label provisional. source | 2026-10-09 |