MuddyWater

Malware family · 5 sample(s) · 25 indicator record(s) · 2 signing certificate(s)

About MuddyWater

Android implant of the MuddyWater (Seedworm) actor. Four-part manifest fingerprint (INTERNET, client.Main activity, receiver.SmsReceiver, client.Client service); the C2 IP and port are static field init values of the /titan/appUtil/utils/AppField; config class (SERVER_IP / SERVER_PORT).

Indicators

IndicatorTypeSampleFirst seen
103.13.67.4:4012 ip 3bfec096c483… 2019-01-02
103.13.67.4:4012 ip dff2e39b2e00… 2018-12-31
103.13.67.4:4012 ip 26de42653034… 2018-12-31
103.13.67.4:4012 ip 9af8a93519d2… 2018-12-26
103.13.67.4:4012 ip 6b4d271a48d1… 2018-09-26
78.129.139.131:4012 ip 3bfec096c483… 2019-01-02
78.129.139.131:4012 ip dff2e39b2e00… 2018-12-31
78.129.139.131:4012 ip 26de42653034… 2018-12-31
78.129.139.131:4012 ip 9af8a93519d2… 2018-12-26
78.129.139.131:4012 ip 6b4d271a48d1… 2018-09-26
80.80.163.182:4012 ip 3bfec096c483… 2019-01-02
80.80.163.182:4012 ip dff2e39b2e00… 2018-12-31
80.80.163.182:4012 ip 26de42653034… 2018-12-31
80.80.163.182:4012 ip 9af8a93519d2… 2018-12-26
80.80.163.182:4012 ip 6b4d271a48d1… 2018-09-26
80.90.87.201:4012 ip 3bfec096c483… 2019-01-02
80.90.87.201:4012 ip dff2e39b2e00… 2018-12-31
80.90.87.201:4012 ip 26de42653034… 2018-12-31
80.90.87.201:4012 ip 9af8a93519d2… 2018-12-26
80.90.87.201:4012 ip 6b4d271a48d1… 2018-09-26
91.187.114.210:4012 ip 3bfec096c483… 2019-01-02
91.187.114.210:4012 ip dff2e39b2e00… 2018-12-31
91.187.114.210:4012 ip 26de42653034… 2018-12-31
91.187.114.210:4012 ip 9af8a93519d2… 2018-12-26
91.187.114.210:4012 ip 6b4d271a48d1… 2018-09-26