210fc835b45a9201f7ed218b…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Telegram Phish Proxy (provisional). Final payload of a 4-stage “shellapp” native dropper (outer package com.coresoft.studio, horoscope “goroskopys” lure; final payload com.apexware.utils / com.base.template). Each stage decrypts and DexClassLoader-loads the next, so the real code never appears in the installed APK’s dex. The unpacking recovered statically: stage 1→2 uses a native nativeCipher = payload[16:] XOR SHA256(key) with a per-sample repeating-XOR-obfuscated key; stage 2 (a VPN “Telegram-bypass” internet blocker) carries a PayloadInstaller that AES-256-CBC-decrypts assets/payload.db; stage 3 decrypts a further asset to the stage-4 stealer. The stealer runs a ProxyService that opens a WebSocket device-relay C2 and a TelegramPhishActivity that drives a phishing WebView against an operator panel (/api/phish/start, /api/phish/verify, /api/phish/2fa) to steal Telegram logins and 2FA codes. All strings are repeating-XOR obfuscated. Family label provisional; C2 indicators are binary-verified by a full static unpack. Indicators: ws://64.188.62.110:9800.

Recovered configuration

package
com.dataflow.lite
packer
shellapp 4-stage native dropper (XOR-SHA256 stage-1, AES-256-CBC payload.db, nested shadow stage)
relay_c2
ws://64.188.62.110:9800

Identification

SHA-256
210fc835b45a9201f7ed218bd52fdae1956bbdeeb2d4d2559a2730ab4e213108
MD5
c6e2904bae1bb5fa7a64887220c5d505

Observed

Families
Telegram Phish Proxy (provisional)
First seen
2026-10-10

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
64.188.62.110 ip 9800 ws Telegram Phish Proxy (provisional) 2026-10-10

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
c8a2e9bccf597c2fb6dc66bee293fc13f2fc47ec77bc6b2b0d52c11f51192ab8

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Telegram Phish Proxy (provisional)

Final payload of a **4-stage "shellapp" native dropper** (outer package `com.coresoft.studio`, horoscope *"goroskopys"* lure; final payload `com.apexware.utils` / `com.base.template`). Each stage decrypts and `DexClassLoader`-loads the next, so the real code never appears in the installed APK's dex. The unpacking recovered statically: stage 1→2 uses a native `nativeCipher` = `payload[16:] XOR SHA256(key)` with a per-sample repeating-XOR-obfuscated key; stage 2 (a VPN "Telegram-bypass" internet blocker) carries a `PayloadInstaller` that AES-256-CBC-decrypts `assets/payload.db`; stage 3 decrypts a further asset to the stage-4 stealer. The stealer runs a `ProxyService` that opens a **WebSocket device-relay C2** and a `TelegramPhishActivity` that drives a phishing WebView against an operator panel (`/api/phish/start`, `/api/phish/verify`, `/api/phish/2fa`) to steal Telegram logins and 2FA codes. All strings are repeating-XOR obfuscated. Family label provisional; C2 indicators are binary-verified by a full static unpack.