0683f43611510c9325203676…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
http://api.jetengine.be, http://sara.sfjioagjioabnjqqfmx.com, https://push.travistaone.com.Recovered configuration
Source: Java-Random keystream-XOR packer -> in-memory inner DEX
Identification
- SHA-256
- 0683f43611510c9325203676b2ff4991700bd4fd652bd54716ecd94d3ae17eec
- MD5
- b841117fbe250303d3b3a2f2997c2756
Observed
- Families
- WebSocket RAT (provisional)
- First seen
- 2026-10-02
APK metadata
Summary
- Type
- Android · APK
- Package
- com.bolo.callertheme
- Main activity
- —
- Internal version
- 1472
- Displayed version
- 788.6.310
- Min SDK
- 28
- Target SDK
- 36
Signing certificate
- Valid from
- 2008-04-15 23:40:57
- Valid to
- 2035-09-01 23:40:57
- Serial
- f2b98e6123572c4e
- Thumbprint
- b79df4a82e90b57ea76525ab7037ab238a42f5d3
- Subject
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
- Subject email
- android@android.com
- Issuer
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Permissions (50)
Intent filters — actions
C2 configuration (3)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| api.jetengine.be | domain | — | http | WebSocket RAT (provisional) | 2026-10-02 |
| push.travistaone.com | domain | — | https | WebSocket RAT (provisional) | 2026-10-02 |
| sara.sfjioagjioabnjqqfmx.com | domain | — | http | WebSocket RAT (provisional) | 2026-10-02 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- 465983f7791f2abeb43ea2cbdc7f21a8260b72bc08a55c839fc1a43bc741a81e
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About WebSocket RAT (provisional)
Android remote-access trojan that uses a WebSocket channel for command-and-control, spreading its panels across rotating look-alike domains (observed: api.jetengine.be, g2.slachozhin.com, push.travistaone.com, sara.sfjioagjioabnjqqfmx.com). Family label provisional; grouped by shared WebSocket C2 protocol pending firmer attribution.