466f8cd95276356ad42bedf5…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
com.coresoft.studio, horoscope “goroskopys” lure; final payload com.apexware.utils / com.base.template). Each stage decrypts and DexClassLoader-loads the next, so the real code never appears in the installed APK’s dex. The unpacking recovered statically: stage 1→2 uses a native nativeCipher = payload[16:] XOR SHA256(key) with a per-sample repeating-XOR-obfuscated key; stage 2 (a VPN “Telegram-bypass” internet blocker) carries a PayloadInstaller that AES-256-CBC-decrypts assets/payload.db; stage 3 decrypts a further asset to the stage-4 stealer. The stealer runs a ProxyService that opens a WebSocket device-relay C2 and a TelegramPhishActivity that drives a phishing WebView against an operator panel (/api/phish/start, /api/phish/verify, /api/phish/2fa) to steal Telegram logins and 2FA codes. All strings are repeating-XOR obfuscated. Family label provisional; C2 indicators are binary-verified by a full static unpack. Indicators: ws://64.188.62.110:9800.Recovered configuration
Identification
- SHA-256
- 466f8cd95276356ad42bedf5a54e4fd19c6bd07b6b4c529b73740fd45b8c9a0d
- MD5
- db68cc1c835a4361e4a9bcccfe3cd075
Observed
- Families
- Telegram Phish Proxy (provisional)
- First seen
- 2026-10-06
APK metadata
Summary
- Type
- Android · APK
- Package
- com.irondev.bridge
- Main activity
- com.template.shellapp.MainActivity
- Internal version
- 1
- Displayed version
- 1.0
- Min SDK
- 26
- Target SDK
- 35
Signing certificate
- Valid from
- 2008-04-15 22:40:50
- Valid to
- 2035-09-01 22:40:50
- Serial
- b3998086d056cffa
- Thumbprint
- 27196e386b875e76adf700e7ea84e4c6eee33dfa
- Subject
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
- Subject email
- android@android.com
- Issuer
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Permissions (18)
Intent filters — actions
Intent filters — categories
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 64.188.62.110 | ip | 9800 | ws | Telegram Phish Proxy (provisional) | 2026-10-06 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- c8a2e9bccf597c2fb6dc66bee293fc13f2fc47ec77bc6b2b0d52c11f51192ab8
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Telegram Phish Proxy (provisional)
Final payload of a **4-stage "shellapp" native dropper** (outer package `com.coresoft.studio`, horoscope *"goroskopys"* lure; final payload `com.apexware.utils` / `com.base.template`). Each stage decrypts and `DexClassLoader`-loads the next, so the real code never appears in the installed APK's dex. The unpacking recovered statically: stage 1→2 uses a native `nativeCipher` = `payload[16:] XOR SHA256(key)` with a per-sample repeating-XOR-obfuscated key; stage 2 (a VPN "Telegram-bypass" internet blocker) carries a `PayloadInstaller` that AES-256-CBC-decrypts `assets/payload.db`; stage 3 decrypts a further asset to the stage-4 stealer. The stealer runs a `ProxyService` that opens a **WebSocket device-relay C2** and a `TelegramPhishActivity` that drives a phishing WebView against an operator panel (`/api/phish/start`, `/api/phish/verify`, `/api/phish/2fa`) to steal Telegram logins and 2FA codes. All strings are repeating-XOR obfuscated. Family label provisional; C2 indicators are binary-verified by a full static unpack.