WhiteBroad

Malware family · 15 sample(s) · 15 indicator record(s) · 3 signing certificate(s) · Active 2018-11-09 → 2019-03-08 (experimental)

About WhiteBroad

Android spyware family spanning several build flavors: com.red.rainbow and cn.close.vcl.play (plus repacks caught by a four-part manifest fingerprint) carry the C2 as a CompileConfig static field or ApiManager getApi() const-string shaped http://host/v1/api/…; a common/Constant; class exposes the full endpoint set (IP_ADDRESS, CONFIG_URL, *_URL). The com.android.hellon flavor moves the C2 into the .rodata of bundled libhelper/libma?sker native libraries as plain http(s) .php URLs.

Indicators

IndicatorTypeSampleFirst seen
180.150.226.122:8080 ip 2fc1f2220375… 2018-12-07
180.150.226.122:8080 ip 77efb6de7409… 2018-12-13
180.150.227.8:8080 ip eb13781968e9… 2018-12-18
180.70.134.76:8080 ip fbbe92080415… 2019-03-08
183.111.122.156:8080 ip 4b67e5db3a3a… 2018-12-05
183.111.122.185:8080 ip cbf5b3e62ac1… 2018-12-29
183.111.122.43:8080 ip 75a7ccc2e936… 2018-11-28
183.111.122.58:8080 ip 6fccc3d0ae9b… 2018-12-29
183.111.122.63:8080 ip 1d1519d511a9… 2018-12-19
183.111.122.63:8080 ip 8b3215611c7b… 2018-12-21
183.111.122.63:8080 ip b9db15b41689… 2018-12-29
27.255.64.3:8080 ip 18105bb5cc06… 2018-12-01
27.255.72.30:8080 ip f81b0c01b007… 2018-11-14
27.255.80.231:8080 ip 41db9722392f… 2018-11-30
27.255.80.231:8080 ip 4e3847d6d85d… 2018-11-09