orange-times-join.loca.lt:4444

domain C2 not resolving

Tracked by C2 Tracker · Whois queried never

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
-
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
Metasploit e7ccdd997a28… C2 2026-10-10

About Metasploit

Android payloads generated by Metasploit / msfvenom (meterpreter and command stages), running under the package com.metasploit.stage. The payload dials back to LHOST:LPORT, which is the C2. Two config formats appear in the wild. In the older/plain format the transport URL (tcp://, ssl:// or https://LHOST:LPORT) is a const-string in the DEX. In the newer format the stage carries a protobuf TransportConfig in the static byte array Payload.a, parsed by an embedded protobuf-lite runtime (com.metasploit.a); that array is XOR-masked with a per-build 4-byte key, and because the buffer is zero-padded the leading bytes leak the key, so XORing the array by key[i mod 4] recovers the protobuf and its transport URL. Many samples are red-team or test builds pointing at LAN, loopback or 0.0.0.0 addresses (recorded verbatim); live ones use public IPs or tunnel fronts such as *.lhr.life (localhost.run) and *.loca.lt (localtunnel).

Signing certificate

Subject CN
apksigner sign --ks /home/robin-hood/my-release-key.keystore --out /home/robin-hood/LottoPredict_SANTUARIO.apk /home/robin-hood/LottoPredict_FINAL.apk
Issuer CN
apksigner sign --ks /home/robin-hood/my-release-key.keystore --out /home/robin-hood/LottoPredict_SANTUARIO.apk /home/robin-hood/LottoPredict_FINAL.apk
Valid
2026-10-10 → 2054-02-25
Fingerprint
b9b6f971c19df5d55e3f515aa79ae3251708d9bf43e8b3c8e6727208af32f43b

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.