2c4694a79d1ba0fe36651f59…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
http://198.144.149.130:12380/hello, egxud.com, knaver.sayoutube.sldfjl.com.Recovered configuration
Identification
- SHA-256
- 2c4694a79d1ba0fe36651f5991b3cd7b67eb54337526d944905f008f6b45d545
- MD5
- f7548904e0f1857143578fe27a2abe52
Observed
- Families
- Anubis
- First seen
- 2026-10-07
APK metadata
Summary
- Type
- Android · APK
- Package
- ghy.cif.rentaapps
- Main activity
- com.launcher.mango.Launcher3
- Internal version
- 1
- Displayed version
- 1.0
- Min SDK
- 29
- Target SDK
- 36
Signing certificate
- Valid from
- 2026-12-04 01:45:59
- Valid to
- 2095-05-16 01:45:59
- Serial
- 331f77727fb3c8cd
- Thumbprint
- 8cd026ab96a5755a6dee4a317ae4dbeb7c043a96
- Subject
- C:CI
- Issuer
- C:CI
Permissions (21)
Intent filters — actions
C2 configuration (3)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| egxud.com | domain | — | — | Anubis | 2026-10-07 |
| knaver.sayoutube.sldfjl.com | domain | — | — | Anubis | 2026-10-07 |
| 198.144.149.130/hello | ip | 12380 | http | Anubis | 2026-10-07 |
Signing certificate
- Subject CN
- —
- Issuer CN
- —
- Fingerprint
- 6cf777da9d58ca1f80a878acc5ce2d6d07e5819c10d00b43ce46a98e16365a13
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Anubis
Android banking trojan, a long-lived descendant of the BankBot/Marcher lineage sold as malware-as-a-service. Heavy abuse of accessibility services for overlay credential theft, keylogging and SMS interception, with a ransomware module in later builds. Shipped as a packer: the real payload is an RC4-encrypted asset whose key is an int[] literal in the loader (each element & 0xff); the unpacked config carries the C2 panel and an RC4 key. Many builds use a dead drop - a Twitter/Telegram profile whose text holds the real C2 behind the key - rather than a hardcoded host.