Metasploit

Malware family · 2 sample(s) · 2 indicator record(s) · 2 signing certificate(s)

About Metasploit

Android payloads generated by the Metasploit Framework’s msfvenom (package com.metasploit.stage, the stock android/meterpreter stager). A small bootstrap APK pulls the meterpreter stage from a handler (LHOST:LPORT, default port 4444) and grants a remote operator full device control - SMS, contacts, call logs, camera, microphone and file access. Metasploit is a legitimate penetration-testing framework, so samples range from red-team/training builds (non-routable test LHOSTs such as 10.0.2.15 or 192.168.x, recorded here as placeholders) to real intrusions; the family tag marks the tool, and each sample’s handler address is the indicator when it is a routable one.

Indicators

IndicatorTypeSampleFirst seen
10.0.2.15:4444 ip c6ad7e66f7fb… 2026-10-08
192.168.27.128:4444 ip b6dc251ea9ce… 2026-10-08

Detected samples without extractable endpoint (1)

Family matched by code marker or hash attribution, but no C2 is statically extractable — the endpoint arrives at runtime.

SHA-256PackageNoteFirst seen
ec4c271f1d04… com.metasploit.stage Metasploit Android meterpreter stage (com.metasploit.stage). No embedded LHOST recovered in plaintext (staged payload fetches its handler at runtime); recorded as a family detection with no actionable C2. 2026-10-08