6a0e9b4ac963ce451d92f373ā¦
sampleTracked by C2 Tracker Ā· indicators & metadata only, the APK itself is never published
Analyst notes
Telegram Dropper (provisional). Native multi-stage dropper (same 4-stage packer family as the Telegram Dropper), disguised as “Desi Tales” - outer package com.sec.android.app.finance.irara23 with 605 padding permissions for anti-analysis. Fully unpacked statically:
- Stage 1: AES-CBC decrypt of assets/ndq2bevn8bqft.q8k with key = fromhex(group1) XOR fromhex(group2) XOR SHA256(packageName); the hex “groups” are StringFog-obfuscated static fields (XOR byte 0x54) -> gzip -> stage-2 loader.
- Stage 2: native lib libzhzcdgrjq.so holds a printable XOR key that deobfuscates assets/qbd4php35i8.enc -> a split-APK set (base.apk + split_config.dex.apk).
- Stage 3: base.apk is packed the same way, keyed on the dropped package com.desi.app; its stub uses a 3-group key (StringFog XOR byte 0xd2) -> gzip -> the final payload (sha256 4d95c0c5319344c8665720862b4eb42f80ea729b50d9851c13cba0d59dd3692d).
The final payload is an Android credential/banking stealer that exfiltrates over MULTIPLE channels: the primary C2 is an operator panel at binarypanel.duckdns.org (/api/device/auth); it also uses a Firebase project (Realtime Database oiigigge-default-rtdb.firebaseio.com + Storage predictor-6b5a5.firebasestorage.app) and a Telegram bot (api.telegram.org, token built at runtime, not statically recoverable). It phishes login.live.com / yahoo / paypal / facebook / linkedin. Recovered by fully unpacking the dropper statically; family label provisional.
Indicators:
https://binarypanel.duckdns.org/api/device/auth,https://oiigigge-default-rtdb.firebaseio.com,https://predictor-6b5a5.firebasestorage.app.
Recovered configuration
Native multi-stage dropper (same 4-stage packer family as the Telegram Dropper), disguised as "Desi Tales" - outer package com.sec.android.app.finance.irara23 with 605 padding permissions for anti-analysis. Fully unpacked statically: - Stage 1: AES-CBC decrypt of assets/ndq2bevn8bqft.q8k with key = fromhex(group1) XOR fromhex(group2) XOR SHA256(packageName); the hex "groups" are StringFog-obfuscated static fields (XOR byte 0x54) -> gzip -> stage-2 loader. - Stage 2: native lib libzhzcdgrjq.so holds a printable XOR key that deobfuscates assets/qbd4php35i8.enc -> a split-APK set (base.apk + split_config.dex.apk). - Stage 3: base.apk is packed the same way, keyed on the dropped package com.desi.app; its stub uses a 3-group key (StringFog XOR byte 0xd2) -> gzip -> the final payload (sha256 4d95c0c5319344c8665720862b4eb42f80ea729b50d9851c13cba0d59dd3692d). The final payload is an Android credential/banking stealer that exfiltrates over MULTIPLE channels: the primary C2 is an operator panel at binarypanel.duckdns.org (/api/device/auth); it also uses a Firebase project (Realtime Database oiigigge-default-rtdb.firebaseio.com + Storage predictor-6b5a5.firebasestorage.app) and a Telegram bot (api.telegram.org, token built at runtime, not statically recoverable). It phishes login.live.com / yahoo / paypal / facebook / linkedin. Recovered by fully unpacking the dropper statically; family label provisional.
Identification
- SHA-256
- 6a0e9b4ac963ce451d92f373146f040f1caf145a3d59f4b625ff009968240b8c
- MD5
- dad480cb24dc207da21bbfbdca6eaefa
Observed
- Families
- Telegram Dropper (provisional)
- First seen
- 2026-10-06
APK metadata
Summary
- Type
- Android Ā· APK
- Package
- com.sec.android.app.finance.irara23
- Main activity
- gjh.bhnn.yuiv.Fqut9c853xz
- Internal version
- 105
- Displayed version
- 2.9.62
- Min SDK
- 24
- Target SDK
- 37
Signing certificate
- Valid from
- 2023-03-07 10:06:56
- Valid to
- 2050-07-23 10:06:56
- Serial
- 354afd4b
- Thumbprint
- 4b29afc23e39fd541aaaf2fd16b0c90c9d9ea0bb
- Subject
- C:US, CN:QA Team, L:Palo Alto, O:Mattermost Inc., ST:California, OU:qa
- Issuer
- C:US, CN:QA Team, L:Palo Alto, O:Mattermost Inc., ST:California, OU:qa
Permissions (605)
Intent filters ā actions
C2 configuration (3)
Every indicator extracted from this sample. One row per C2 ā each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| binarypanel.duckdns.org/api/device/auth | domain | ā | https | Telegram Dropper (provisional) | 2026-10-06 |
| oiigigge-default-rtdb.firebaseio.com | domain | ā | https | Telegram Dropper (provisional) | 2026-10-06 |
| predictor-6b5a5.firebasestorage.app | domain | ā | https | Telegram Dropper (provisional) | 2026-10-06 |
Signing certificate
- Subject CN
- QA Team
- Issuer CN
- QA Team
- Fingerprint
- 1431eedaa27b30fd846283f083e52a5fa40c0261e1a039a337a37174d699e750
Relationships
Sample ā C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.