2c4694a79d1ba0fe36651f59…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Anubis. Android banking trojan, a long-lived descendant of the BankBot/Marcher lineage sold as malware-as-a-service. Heavy abuse of accessibility services for overlay credential theft, keylogging and SMS interception, with a ransomware module in later builds. Shipped as a packer: the real payload is an RC4-encrypted asset whose key is an int[] literal in the loader (each element & 0xff); the unpacked config carries the C2 panel and an RC4 key. Many builds use a dead drop - a Twitter/Telegram profile whose text holds the real C2 behind the key - rather than a hardcoded host. Indicators: http://198.144.149.130:12380/hello, egxud.com, knaver.sayoutube.sldfjl.com.

Recovered configuration

alt_c2
knaver.sayoutube.sldfjl.com
deaddrop_fallbacks
blogspot/vk/imgur/instagram/x/youtube
disguise
Chrome (ghy.cif.rentaapps), 181 MB padded
dns_txt_deaddrop
egxud.com@txt
package
ghy.cif.rentaapps
packer
native DEX loader (libcabbage.so m2: XOR 0x87 + zlib -> com.Loader)
primary_c2
http://198.144.149.130:12380/hello?id=<device>

Identification

SHA-256
2c4694a79d1ba0fe36651f5991b3cd7b67eb54337526d944905f008f6b45d545
MD5
f7548904e0f1857143578fe27a2abe52

Observed

Families
Anubis
First seen
2026-10-07

APK metadata

Summary

Type
Android · APK
Package
ghy.cif.rentaapps
Main activity
com.launcher.mango.Launcher3
Internal version
1
Displayed version
1.0
Min SDK
29
Target SDK
36

Signing certificate

Valid from
2026-12-04 01:45:59
Valid to
2095-05-16 01:45:59
Serial
331f77727fb3c8cd
Thumbprint
8cd026ab96a5755a6dee4a317ae4dbeb7c043a96
Subject
C:CI
Issuer
C:CI

Permissions (21)

android.permission.ACCESS_NETWORK_STATEandroid.permission.ACCESS_WIFI_STATEandroid.permission.CHANGE_NETWORK_STATEandroid.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_MEDIA_PLAYBACKandroid.permission.INTERNETandroid.permission.MODIFY_AUDIO_SETTINGSandroid.permission.PACKAGE_USAGE_STATSandroid.permission.POST_NOTIFICATIONSandroid.permission.READ_EXTERNAL_STORAGEandroid.permission.READ_PHONE_NUMBERSandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SEND_SMSandroid.permission.SET_WALLPAPER_HINTSandroid.permission.WAKE_LOCKandroid.permission.WRITE_EXTERNAL_STORAGEcom.android.launcher.permission.READ_SETTINGS

Activities (8)

  • com.launcher.mango.Launcher3
  • com.launcher.mango.SettingsActivity
  • com.launcher.mango.dragndrop.AddItemActivity
  • pyramid.jx
  • pyramid.nd
  • pyramid.qg
  • pyramid.us
  • pyramid.ys

Services (4)

  • com.launcher.mango.compat.WallpaperManagerCompatVL$ColorExtractionService
  • com.launcher.mango.dynamicui.ColorExtractionService
  • pyramid.ad
  • pyramid.fx

Receivers (5)

  • androidx.profileinstaller.ProfileInstallReceiver
  • com.launcher.mango.AppWidgetsRestoredReceiver
  • com.launcher.mango.InstallShortcutReceiver
  • com.launcher.mango.SessionCommitReceiver
  • pyramid.ya

Providers (1)

  • com.launcher.mango.LauncherProvider

Intent filters — actions

android.appwidget.action.APPWIDGET_HOST_RESTOREDandroid.content.pm.action.SESSION_COMMITTEDandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEcom.android.launcher.action.INSTALL_SHORTCUT

C2 configuration (3)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
egxud.com domain — — Anubis 2026-10-07
knaver.sayoutube.sldfjl.com domain — — Anubis 2026-10-07
198.144.149.130/hello ip 12380 http Anubis 2026-10-07

Signing certificate

Subject CN
—
Issuer CN
—
Fingerprint
6cf777da9d58ca1f80a878acc5ce2d6d07e5819c10d00b43ce46a98e16365a13

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Anubis

Android banking trojan, a long-lived descendant of the BankBot/Marcher lineage sold as malware-as-a-service. Heavy abuse of accessibility services for overlay credential theft, keylogging and SMS interception, with a ransomware module in later builds. Shipped as a packer: the real payload is an RC4-encrypted asset whose key is an int[] literal in the loader (each element & 0xff); the unpacked config carries the C2 panel and an RC4 key. Many builds use a dead drop - a Twitter/Telegram profile whose text holds the real C2 behind the key - rather than a hardcoded host.