4935988e625e28c5f14f5d40…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

WebSocket VNC Banker (provisional). WebSocket VNC Banker (provisional) is an Android overlay/VNC banking trojan that talks to its operator over a WebSocket channel. The C2 endpoint is ws://:8080/, where the host is held as an AES-128-CBC-encrypted, base64-encoded field decrypted at runtime with a PBKDF2-HMAC-SHA1 key (password, salt, 65536 iterations, 128-bit) and a string IV, then DNS-resolved before connecting (after an HTTP reachability probe). It injects overlays for credential theft, intercepts SMS and one-time passwords, pins a custom CA, and sends device headers (X-Device-Id, X-Device-Model, X-Api-Level). Strings are hidden behind a byte-array XOR decoder plus opaque-predicate (hashCode sparse-switch) control-flow obfuscation and a fill-array-data element-width-17 trap that breaks jadx/baksmali/androguard, so the C2 is recovered by running the sample decoders on a JVM. Seen both as a standalone app and as the payload of a Brazilian Correios-lure dropper (child package dune.firefly.imagine). Observed C2s include 107.148.78.150:8080 and 190.2.184.130:8080. Family label provisional. Indicators: ws://151.243.218.93:8080/, ws://207.180.3.224:8080/, ws://212.69.5.117:8080/, ws://212.38.89.110:8080/, http://190.102.41.210:5000.

Recovered configuration

banker_hosts
151.243.218.93, 207.180.3.224, 212.69.5.117, 212.38.89.110
banker_package
com.tapassistant.autoclicker
decoy
https://ativarchipvirtualapk.lovable.app
dropper_package
com.smartkeeper.sync
lcg_seed
247640105
package
com.smartkeeper.sync
probe_path
/yaarsa/private/
webrtc_owner
hblwzr
webrtc_panel
http://190.102.41.210:5000

Identification

SHA-256
4935988e625e28c5f14f5d403c8895a90fb289aea3fbc9af42743c1c086d28c9
MD5
bb28ca26303ae2d42e2a2547ecc0cf97

Observed

Families
WebSocket VNC Banker (provisional)
First seen
2026-10-08

C2 configuration (5)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
151.243.218.93/ ip 8080 ws WebSocket VNC Banker (provisional) 2026-10-08
190.102.41.210 ip 5000 http WebSocket VNC Banker (provisional) 2026-10-08
207.180.3.224/ ip 8080 ws WebSocket VNC Banker (provisional) 2026-10-08
212.38.89.110/ ip 8080 ws WebSocket VNC Banker (provisional) 2026-10-08
212.69.5.117/ ip 8080 ws WebSocket VNC Banker (provisional) 2026-10-08

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Fingerprint
1e08a903aef9c3a721510b64ec764d01d3d094eb954161b62544ea8f187b5953

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About WebSocket VNC Banker (provisional)

**WebSocket VNC Banker (provisional)** is an Android overlay/VNC banking trojan that talks to its operator over a WebSocket channel. The C2 endpoint is ws://<host>:8080/, where the host is held as an AES-128-CBC-encrypted, base64-encoded field decrypted at runtime with a PBKDF2-HMAC-SHA1 key (password, salt, 65536 iterations, 128-bit) and a string IV, then DNS-resolved before connecting (after an HTTP reachability probe). It injects overlays for credential theft, intercepts SMS and one-time passwords, pins a custom CA, and sends device headers (X-Device-Id, X-Device-Model, X-Api-Level). Strings are hidden behind a byte-array XOR decoder plus opaque-predicate (hashCode sparse-switch) control-flow obfuscation and a fill-array-data element-width-17 trap that breaks jadx/baksmali/androguard, so the C2 is recovered by running the sample decoders on a JVM. Seen both as a standalone app and as the payload of a Brazilian Correios-lure dropper (child package dune.firefly.imagine). Observed C2s include 107.148.78.150:8080 and 190.2.184.130:8080. Family label provisional.