4afee3039ddde0cf9b2d2c46…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
ws://167.86.110.102:8080/, http://191.96.79.100:5000.Recovered configuration
Identification
- SHA-256
- 4afee3039ddde0cf9b2d2c46aa69c8a25fc9b6ca5386896dfcf409aab4fd0765
- MD5
- 64b5f078f29a2ba86e0c02acaa33e489
Observed
- Families
- WebSocket VNC Banker (provisional)
- First seen
- 2026-10-09
C2 configuration (2)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 167.86.110.102/ | ip | 8080 | ws | WebSocket VNC Banker (provisional) | 2026-10-09 |
| 191.96.79.100 | ip | 5000 | http | WebSocket VNC Banker (provisional) | 2026-10-09 |
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Fingerprint
- 1e08a903aef9c3a721510b64ec764d01d3d094eb954161b62544ea8f187b5953
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About WebSocket VNC Banker (provisional)
**WebSocket VNC Banker (provisional)** is an Android overlay/VNC banking trojan that talks to its operator over a WebSocket channel. The C2 endpoint is ws://<host>:8080/, where the host is held as an AES-128-CBC-encrypted, base64-encoded field decrypted at runtime with a PBKDF2-HMAC-SHA1 key (password, salt, 65536 iterations, 128-bit) and a string IV, then DNS-resolved before connecting (after an HTTP reachability probe). It injects overlays for credential theft, intercepts SMS and one-time passwords, pins a custom CA, and sends device headers (X-Device-Id, X-Device-Model, X-Api-Level). Strings are hidden behind a byte-array XOR decoder plus opaque-predicate (hashCode sparse-switch) control-flow obfuscation and a fill-array-data element-width-17 trap that breaks jadx/baksmali/androguard, so the C2 is recovered by running the sample decoders on a JVM. Seen both as a standalone app and as the payload of a Brazilian Correios-lure dropper (child package dune.firefly.imagine). Observed C2s include 107.148.78.150:8080 and 190.2.184.130:8080. Family label provisional.