35fa397fa0abcbf178a31b34…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

WebSocket VNC Banker (provisional) - an Android banking trojan, self-signed as “editor”. It intercepts incoming SMS, sends SMS, abuses Accessibility Services, records audio, captures the camera, steals contacts and tracks location. Communicates with 1 operator endpoint. Android WebSocket VNC/overlay banking RAT. The C2 is built at runtime from the encrypted static field asejlgvqfpexqxbsdsm.cfmejktusyvwra = base64 “MaSi51zlvRDOF4Opektgmw==” (16-byte AES block): AES-128-CBC decrypt with key = PBKDF2WithHmacSHA1(password cc.F0 “4814780584699673”, salt cc.G0 “2894356330652558”.getBytes, 65536 iterations, 128-bit) and IV = cc.E0 “2230209522049090”.getBytes yields the host list “107.148.78.150” (split on ‘<’). Each host is DNS-resolved (cc.d = InetAddress.getByName) and, after a reachability probe to http:///yaarsa/private/log_error.php, the WebSocket C2 is ws://:8080/ -> ws://107.148.78.150:8080/. Statically recovered without Frida: the sample uses a fill-array-data element-width-17 trap plus opaque-predicate (sparse-switch on constant String.hashCode) control-flow obfuscation that breaks jadx/baksmali/androguard decompilation, so the in-APK decoders (r0.k prefix-strip, k50.a XOR, pu AES) were executed on a JVM via dex2jar + android.jar to read cc.E0/F0/G0 and the decrypted host. String obfuscation uses Arabic-presentation-form junk const-strings. Family label provisional. Indicators: ws://107.148.78.150:8080/.

Recovered configuration

aes
AES-128-CBC PBKDF2-HMAC-SHA1(pw=4814780584699673, salt=2894356330652558, 65536, 128), IV=2230209522049090
cfmejktusyvwra
MaSi51zlvRDOF4Opektgmw==
probe_url
http://107.148.78.150/yaarsa/private/log_error.php
reference
amtracker
ws_c2
ws://107.148.78.150:8080/

Identification

SHA-256
35fa397fa0abcbf178a31b345ec80dfacb343df69c4b14fafa7a8301d2b22c85
MD5
0922cd0398b54989cb05336e9283e0d1

Observed

Families
WebSocket VNC Banker (provisional)
First seen
–

APK metadata

Summary

Type
Android · APK
Package
-
Main activity
xfho.lckpcq.zorgrdo.A1
Internal version
-
Displayed version
-
Min SDK
-
Target SDK
-

Signing certificate

Valid from
2016-01-10 08:03:09
Valid to
2115-12-17 08:03:09
Serial
231bc320
Thumbprint
927ca44949d7788aa86f9d7f04d7fdacecd1dfb9
Subject
CN:editor
Issuer
CN:editor

Permissions (30)

android.permission.ACCESS_COARSE_LOCATIONandroid.permission.ACCESS_FINE_LOCATIONandroid.permission.ACCESS_NETWORK_STATEandroid.permission.BIND_ACCESSIBILITY_SERVICEandroid.permission.BIND_DEVICE_ADMINandroid.permission.BIND_DREAM_SERVICEandroid.permission.BIND_JOB_SERVICEandroid.permission.CALL_PHONEandroid.permission.CAMERAandroid.permission.DUMPandroid.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_DATA_SYNCandroid.permission.FOREGROUND_SERVICE_MEDIA_PROJECTIONandroid.permission.INTERNETandroid.permission.MANAGE_EXTERNAL_STORAGEandroid.permission.POST_NOTIFICATIONSandroid.permission.READ_CONTACTSandroid.permission.READ_EXTERNAL_STORAGEandroid.permission.READ_PHONE_NUMBERSandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECORD_AUDIOandroid.permission.REQUEST_DELETE_PACKAGESandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SEND_SMSandroid.permission.WAKE_LOCKandroid.permission.WRITE_CONTACTSandroid.permission.WRITE_EXTERNAL_STORAGEcom.android.alarm.permission.SET_ALARMxfho.lckpcq.zorgrdo.permission.TDOS_DIAGNOSE_BROADCAST

Activities (32)

  • xfho.lckpcq.zorgrdo.CallBacker
  • xfho.lckpcq.zorgrdo.HomeSIM
  • xfho.lckpcq.zorgrdo.HomeSmsung
  • xfho.lckpcq.zorgrdo.HomeWallp
  • xfho.lckpcq.zorgrdo.Inputkfwjftrkvikcgibcbs
  • xfho.lckpcq.zorgrdo.PlayS
  • xfho.lckpcq.zorgrdo.RequestAdm
  • xfho.lckpcq.zorgrdo.Splasher
  • xfho.lckpcq.zorgrdo.Toastit
  • xfho.lckpcq.zorgrdo.bcmnkirxazycpbppa
  • xfho.lckpcq.zorgrdo.cnjagkgs
  • xfho.lckpcq.zorgrdo.dlqfdfzzuzxdrxz
  • xfho.lckpcq.zorgrdo.eqcoddkogdilcppqefo
  • xfho.lckpcq.zorgrdo.ieznjtzgryvay
  • xfho.lckpcq.zorgrdo.jinfshmjtu
  • xfho.lckpcq.zorgrdo.jsonqzzjge
  • xfho.lckpcq.zorgrdo.kfwjftrkvikcgibcbs
  • xfho.lckpcq.zorgrdo.kiebhdaifmbtj
  • xfho.lckpcq.zorgrdo.kxndbfjwav
  • xfho.lckpcq.zorgrdo.lggwrrcarauv
  • xfho.lckpcq.zorgrdo.mgbbpoggivgyk
  • xfho.lckpcq.zorgrdo.pyotqmptdyorz
  • xfho.lckpcq.zorgrdo.rndnhjub
  • xfho.lckpcq.zorgrdo.speakit
  • xfho.lckpcq.zorgrdo.sskumqfntmimf
  • xfho.lckpcq.zorgrdo.tofront
  • xfho.lckpcq.zorgrdo.vhfwqfpqgmqdt
  • xfho.lckpcq.zorgrdo.wfmggnlbclzqcp
  • xfho.lckpcq.zorgrdo.yeapcgctkazkk
  • xfho.lckpcq.zorgrdo.ygfluixkknbhtcdff
  • xfho.lckpcq.zorgrdo.ykbrbmconzwrtr
  • xfho.lckpcq.zorgrdo.zxoftffryitmdwheyu

Services (17)

  • .jkcfsolampgbcjbyea
  • androidx.room.MultiInstanceInvalidationService
  • androidx.work.impl.background.systemalarm.SystemAlarmService
  • androidx.work.impl.background.systemjob.SystemJobService
  • androidx.work.impl.foreground.SystemForegroundService
  • xfho.lckpcq.zorgrdo.DownloadForegroundService
  • xfho.lckpcq.zorgrdo.Msss
  • xfho.lckpcq.zorgrdo.dlrmpfruvsnyvzu
  • xfho.lckpcq.zorgrdo.gmrkbtliokxjl
  • xfho.lckpcq.zorgrdo.ioblfkifk
  • xfho.lckpcq.zorgrdo.iuehrfcuxr
  • xfho.lckpcq.zorgrdo.minserv
  • xfho.lckpcq.zorgrdo.saoergubru
  • xfho.lckpcq.zorgrdo.tbavaycrxgjo
  • xfho.lckpcq.zorgrdo.vkdrfmekbnydutgfwvu
  • xfho.lckpcq.zorgrdo.xtystqsbk
  • xfho.lckpcq.zorgrdo.zjeayspzvtbbrgycj

Receivers (13)

  • .MyDeviceAdminReceiver
  • androidx.profileinstaller.ProfileInstallReceiver
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryChargingProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$BatteryNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$NetworkStateProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxy$StorageNotLowProxy
  • androidx.work.impl.background.systemalarm.ConstraintProxyUpdateReceiver
  • androidx.work.impl.background.systemalarm.RescheduleReceiver
  • androidx.work.impl.diagnostics.DiagnosticsReceiver
  • androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver
  • xfho.lckpcq.zorgrdo.BootReceiver
  • xfho.lckpcq.zorgrdo.ResetServices
  • xfho.lckpcq.zorgrdo.alarme

Providers (2)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider

Intent filters - actions

AppAlarmandroid.accessibilityservice.AccessibilityServiceandroid.app.action.DEVICE_ADMIN_DISABLEDandroid.app.action.DEVICE_ADMIN_ENABLEDandroid.intent.action.ACTION_POWER_CONNECTEDandroid.intent.action.ACTION_POWER_DISCONNECTEDandroid.intent.action.ACTION_SHUTDOWNandroid.intent.action.AIRPLANE_MODEandroid.intent.action.BATTERY_LOWandroid.intent.action.BATTERY_OKAYandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.DEVICE_STORAGE_LOWandroid.intent.action.DEVICE_STORAGE_OKandroid.intent.action.QUICKBOOT_POWERONandroid.intent.action.REBOOTandroid.intent.action.TIMEZONE_CHANGEDandroid.intent.action.TIME_SETandroid.net.conn.CONNECTIVITY_CHANGEandroid.service.dreams.DreamServiceandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEandroidx.work.diagnostics.REQUEST_DIAGNOSTICSandroidx.work.impl.background.systemalarm.UpdateProxiescom.htc.intent.action.QUICKBOOT_POWERON

Intent filters - categories

android.intent.category.DEFAULT

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
107.148.78.150/ ip 8080 ws WebSocket VNC Banker (provisional) –

Signing certificate

Subject CN
editor
Issuer CN
editor
Fingerprint
6215f00baa4bf18bab5792fc796bfc5555917240f14f7c7e672d956888d75c96

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.