139edb1bc033725539b117f5…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

WolfRat. WolfRat is a Thai-targeting Android RAT (Cisco Talos, May 2020) built on leaked Dendroid source but adding live surveillance: screen recording via a repurposed com.serenegiant.service.ScreenRecorderService, call/phone recording and camera capture. Two build lineages are seen, a com.connect.* service namespace (package com.adobe.flash13) and a com.ActivityMain.* namespace (package com.google.services masquerading as Google Play services). Both expose a plaintext C2 web service rooted at a svcws host or path (for example https://databit.today/svcws and https://svcws.nampriknum.net) with REST endpoints such as Authen/verify_token, Filesend/upload_file and Messages/mess_update. Indicators: https://svcws.nampriknum.net.

Recovered configuration

endpoints
https://svcws.nampriknum.net, https://svcws.nampriknum.net/Authen/verify_token, https://svcws.nampriknum.net/Filesautosend/upload_file, https://svcws.nampriknum.net/Filesend/upload_file, https://svcws.nampriknum.net/Messages/mess_update
package
com.google.services
reference
https://blog.talosintelligence.com/2020/05/the-wolf-is-back.html

Identification

SHA-256
139edb1bc033725539b117f50786f3d3362ed45845c57fe1f82e7ed72b044367
MD5
9845316fa32b13d04651a704201f705a

Observed

Families
WolfRat
First seen
2020-04-27

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
svcws.nampriknum.net domain - https WolfRat 2020-04-27

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About WolfRat

**WolfRat** is a Thai-targeting Android RAT (Cisco Talos, May 2020) built on leaked Dendroid source but adding live surveillance: screen recording via a repurposed com.serenegiant.service.ScreenRecorderService, call/phone recording and camera capture. Two build lineages are seen, a com.connect.* service namespace (package com.adobe.flash13) and a com.ActivityMain.* namespace (package com.google.services masquerading as Google Play services). Both expose a plaintext C2 web service rooted at a svcws host or path (for example https://databit.today/svcws and https://svcws.nampriknum.net) with REST endpoints such as Authen/verify_token, Filesend/upload_file and Messages/mess_update.