3107ca04e2a18a4e2c5241bc…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
SpyNote - Android spyware, self-signed as “Internet Widgits Pty Ltd”. Communicates with 1 operator endpoint. SpyNote fork disguised as ESET Mobile Security (manifest package com.eset.ems2.gp) but with the code refactored into the system.operating.dominance.proj namespace instead of yps.eton.application, so the structural decoder does not match. C2 host and port are held in separate ARSC string resources (host=91.206.32.67, port=2222) and loaded into fields M.g/M.h, which feed new Socket(M.g, M.h) in the M$c.a connect loop (same heartbeat/’nothing’ sentinel structure as SpyNote). Source->sink verified. Indicators:
91.206.32.67:2222.Recovered configuration
c2_host
91.206.32.67
c2_port
2222
code_namespace
system.operating.dominance.proj
host_resource
host
package
com.eset.ems2.gp
port_resource
port
socket
system.operating.dominance.proj.M$c.a -> new Socket(M.g, M.h)
Identification
- SHA-256
- 3107ca04e2a18a4e2c5241bc799c018d0f20276f3eea53ac88c362ac87fd3164
- MD5
- 091ca91c701c52a4b454942a40ee4ae8
Observed
- Families
- SpyNote
- First seen
- 2019-01-06
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 91.206.32.67 | ip | 2222 | - | SpyNote | 2019-01-06 |
Signing certificate
- Subject CN
- apk-icon-editor
- Issuer CN
- apk-icon-editor
- Fingerprint
- 36bf53e5d7b70098a4aa3d3dd220330b21156e863f7a1af76cca282cb6abfa6d
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.