SandroRat

Malware family · 3 sample(s) · 3 indicator record(s) · 1 signing certificate(s)

About SandroRat

Android remote-access trojan sold as "DroidJack", repackaged under many names over the years. Its config (host + port) hides in the static initializer of an obfuscated helper class referenced from MainActivity.onCreate via an sget-byte field read.

Indicators

IndicatorTypeSampleFirst seen
bbog777.zapto.org:1337 domain 7ac44c185497… 2019-09-21
madani13.ddns.net:1177 domain bbe4bd357ed2… 2019-01-17
82.137.218.185:1999 ip b0e5bde5c6c6… 2017-12-31