35fa397fa0abcbf178a31b34…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
WebSocket VNC Banker (provisional) - an Android banking trojan, self-signed as “editor”. It intercepts incoming SMS, sends SMS, abuses Accessibility Services, records audio, captures the camera, steals contacts and tracks location. Communicates with 1 operator endpoint. Android WebSocket VNC/overlay banking RAT. The C2 is built at runtime from the encrypted static field asejlgvqfpexqxbsdsm.cfmejktusyvwra = base64 “MaSi51zlvRDOF4Opektgmw==” (16-byte AES block): AES-128-CBC decrypt with key = PBKDF2WithHmacSHA1(password cc.F0 “4814780584699673”, salt cc.G0 “2894356330652558”.getBytes, 65536 iterations, 128-bit) and IV = cc.E0 “2230209522049090”.getBytes yields the host list “107.148.78.150” (split on ‘<’). Each host is DNS-resolved (cc.d = InetAddress.getByName) and, after a reachability probe to http:///yaarsa/private/log_error.php, the WebSocket C2 is ws://:8080/ -> ws://107.148.78.150:8080/. Statically recovered without Frida: the sample uses a fill-array-data element-width-17 trap plus opaque-predicate (sparse-switch on constant String.hashCode) control-flow obfuscation that breaks jadx/baksmali/androguard decompilation, so the in-APK decoders (r0.k prefix-strip, k50.a XOR, pu AES) were executed on a JVM via dex2jar + android.jar to read cc.E0/F0/G0 and the decrypted host. String obfuscation uses Arabic-presentation-form junk const-strings. Family label provisional. Indicators:
ws://107.148.78.150:8080/.Recovered configuration
aes
AES-128-CBC PBKDF2-HMAC-SHA1(pw=4814780584699673, salt=2894356330652558, 65536, 128), IV=2230209522049090
cfmejktusyvwra
MaSi51zlvRDOF4Opektgmw==
probe_url
http://107.148.78.150/yaarsa/private/log_error.php
reference
amtracker
ws_c2
ws://107.148.78.150:8080/
Identification
- SHA-256
- 35fa397fa0abcbf178a31b345ec80dfacb343df69c4b14fafa7a8301d2b22c85
- MD5
- 0922cd0398b54989cb05336e9283e0d1
Observed
- Families
- WebSocket VNC Banker (provisional)
- First seen
- –
APK metadata
Summary
- Type
- Android · APK
- Package
- -
- Main activity
- xfho.lckpcq.zorgrdo.A1
- Internal version
- -
- Displayed version
- -
- Min SDK
- -
- Target SDK
- -
Signing certificate
- Valid from
- 2016-01-10 08:03:09
- Valid to
- 2115-12-17 08:03:09
- Serial
- 231bc320
- Thumbprint
- 927ca44949d7788aa86f9d7f04d7fdacecd1dfb9
- Subject
- CN:editor
- Issuer
- CN:editor
Permissions (30)
Intent filters - actions
Intent filters - categories
android.intent.category.DEFAULT
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 107.148.78.150/ | ip | 8080 | ws | WebSocket VNC Banker (provisional) | – |
Signing certificate
- Subject CN
- editor
- Issuer CN
- editor
- Fingerprint
- 6215f00baa4bf18bab5792fc796bfc5555917240f14f7c7e672d956888d75c96
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.