0ae424b7b2c1c8dd9a076f8b…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
213.21.237.176:7771.Recovered configuration
Identification
- SHA-256
- 0ae424b7b2c1c8dd9a076f8bf1ee65139cdc1a511d3b1d4914829e28aa6817d7
- MD5
- f84f1f2ca5db25fddf38b42cf32083f0
Observed
- Families
- SpyMax (provisional)
- First seen
- 2025-05-28
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 213.21.237.176 | ip | 7771 | - | SpyMax (provisional) | 2025-05-28 |
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Fingerprint
- 1e08a903aef9c3a721510b64ec764d01d3d094eb954161b62544ea8f187b5953
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About SpyMax (provisional)
**SpyMax (provisional)** is a commercial Android spyware/RAT of the SpyNote family (SpyMax lineage), built from a public builder and repackaged under game and utility lures (for example "Proxy hs" and "Google Translate") with randomised package and class names per build. The C2 is stored as base64 static fields initializeService.ClientHost and ClientPort (decoded at runtime by a Base64 helper) and reached as a raw TCP socket to ClientHost:ClientPort; builds also carry a ConnectionKey. It runs a full surveillance stack: live screen streaming via MediaProjection (Screen_Sender / SecondarySocket), live camera capture (CameraHandler socket), keylogging (KeyboardService), an Accessibility service (AccessService), a FloatingView overlay, geolocation (LocationService plus Yandex static-maps), SMS theft and app installation (REQUEST_INSTALL_PACKAGES). Some builds ship a LAN/test C2 (for example 192.168.18.46) left by the operator or a red-teamer. Family label provisional.