38.60.241.106:8080/
ip C2Tracked by C2 Tracker Ā· Whois queried never
Network
- Network
- ā
- CIDR
- ā
- Country
- ā
Contact
- Handle
- ā
- Abuse
- ā
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Famelack Loader (provisional) | 032071c1c92d⦠| C2 | 2026-10-08 |
About Famelack Loader (provisional)
A packed Android loader campaign that hides behind fake video/TV-streaming apps (observed app labels "GOTV" and "TenXun", each padded with zero-width characters to evade string matching) and shares a common phishing backend at `https://famelack.com`. Samples are heavily protected and ship ~390 decoy manifest permissions to frustrate analysis. **Two observed variants** - A **WebView phishing loader** (`shell.loader` 3-layer XOR packer): `assets/shell_config.dat` is XORed with the SHA-256 keystream of `shell_config_key_v1` to yield a JSON config, and the encrypted DEX in `assets/encrypted/` is XOR-decrypted per-layer (keystream `SHA-256(zero-key || layer-index)`), stripped and zlib-inflated. The recovered app loads `https://famelack.com` in a JavaScript/geolocation-enabled WebView, abuses Accessibility services and can silently install secondary APKs. - A **WebSocket RAT dropper** using a custom `SVLT` "Vault" container (`assets/po70sue2.zip`, a header of magic `SVLT` + version + IV followed by a key-and-IV repeating-XOR stream; the key is the Base64-decoded AndroidManifest meta-data `vault_payload_key`). The vault yields a child RAT (`app.swift.learn`) whose OkHttp WebSocket C2 host is stored as an AES/CBC blob (PBKDF2WithHmacSHA1-derived key) that decrypts to a bare IP; at runtime it connects to `ws://<host>:8080/` after an HTTP health check, and also carries the `https://famelack.com` backend. All C2 indicators are recovered by full static unpacking of each stage (binary-verified). Family label provisional.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 ā 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking ā but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.