3107ca04e2a18a4e2c5241bc…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

SpyNote - Android spyware, self-signed as “Internet Widgits Pty Ltd”. Communicates with 1 operator endpoint. SpyNote fork disguised as ESET Mobile Security (manifest package com.eset.ems2.gp) but with the code refactored into the system.operating.dominance.proj namespace instead of yps.eton.application, so the structural decoder does not match. C2 host and port are held in separate ARSC string resources (host=91.206.32.67, port=2222) and loaded into fields M.g/M.h, which feed new Socket(M.g, M.h) in the M$c.a connect loop (same heartbeat/’nothing’ sentinel structure as SpyNote). Source->sink verified. Indicators: 91.206.32.67:2222.

Recovered configuration

c2_host
91.206.32.67
c2_port
2222
code_namespace
system.operating.dominance.proj
host_resource
host
package
com.eset.ems2.gp
port_resource
port
socket
system.operating.dominance.proj.M$c.a -> new Socket(M.g, M.h)

Identification

SHA-256
3107ca04e2a18a4e2c5241bc799c018d0f20276f3eea53ac88c362ac87fd3164
MD5
091ca91c701c52a4b454942a40ee4ae8

Observed

Families
SpyNote
First seen
2019-01-06

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
91.206.32.67 ip 2222 - SpyNote 2019-01-06

Signing certificate

Subject CN
apk-icon-editor
Issuer CN
apk-icon-editor
Fingerprint
36bf53e5d7b70098a4aa3d3dd220330b21156e863f7a1af76cca282cb6abfa6d

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.