6c9c5f1e08fd793c477e0c1b…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Telegram Phish Proxy (provisional). Final payload of a 4-stage “shellapp” native dropper (outer package com.coresoft.studio, horoscope “goroskopys” lure; final payload com.apexware.utils / com.base.template). Each stage decrypts and DexClassLoader-loads the next, so the real code never appears in the installed APK’s dex. The unpacking recovered statically: stage 1→2 uses a native nativeCipher = payload[16:] XOR SHA256(key) with a per-sample repeating-XOR-obfuscated key; stage 2 (a VPN “Telegram-bypass” internet blocker) carries a PayloadInstaller that AES-256-CBC-decrypts assets/payload.db; stage 3 decrypts a further asset to the stage-4 stealer. The stealer runs a ProxyService that opens a WebSocket device-relay C2 and a TelegramPhishActivity that drives a phishing WebView against an operator panel (/api/phish/start, /api/phish/verify, /api/phish/2fa) to steal Telegram logins and 2FA codes. All strings are repeating-XOR obfuscated. Family label provisional; C2 indicators are binary-verified by a full static unpack. Indicators: ws://64.188.62.110:9800.

Recovered configuration

package
com.streamline.core

Identification

SHA-256
6c9c5f1e08fd793c477e0c1b68c85f77e95c7bf344d7b3763114c8d678fc40df
MD5
17757ecb759e28d91cb26f095e4e928e

Observed

Families
Telegram Phish Proxy (provisional)
First seen
2026-10-06

APK metadata

Summary

Type
Android · APK
Package
com.streamline.core
Main activity
com.template.shellapp.MainActivity
Internal version
1
Displayed version
1.0
Min SDK
16
Target SDK
29

Signing certificate

Valid from
2008-04-15 22:40:50
Valid to
2035-09-01 22:40:50
Serial
b3998086d056cffa
Thumbprint
27196e386b875e76adf700e7ea84e4c6eee33dfa
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject email
android@android.com
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com

Permissions (14)

android.permission.ACCESS_NETWORK_STATEandroid.permission.ACCESS_WIFI_STATEandroid.permission.CHANGE_WIFI_STATEandroid.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_SPECIAL_USEandroid.permission.INTERNETandroid.permission.KILL_BACKGROUND_PROCESSESandroid.permission.POST_NOTIFICATIONSandroid.permission.QUERY_ALL_PACKAGESandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.REQUEST_INSTALL_PACKAGESandroid.permission.VIBRATEandroid.permission.WAKE_LOCKcom.streamline.core.permission.MF_9LUXN04Z874FL04T48BKVIEN

Activities (88)

  • com.template.shellapp.AboutActivity
  • com.template.shellapp.MainActivity
  • com.template.shellapp.SettingsActivity
  • x.bba4l.rjn3.emo
  • x.c1ixi.dtn.vbj
  • x.e9rjn.it3.jnu
  • x.evt
  • x.gqbz.tirk.x16
  • x.hr0xp
  • x.ihjd
  • x.in4xf.uoy9.is
  • x.iwos.vjk0.dnw
  • x.jzda
  • x.lhxy
  • x.llt
  • x.mf.AS7pOIkKdqcG2aD
  • x.mf.AkRUQ1Qzk3
  • x.mf.C2kp96Cgf4Ylkf
  • x.mf.DIo2yxrvzjy
  • x.mf.DaXz28rP12dL
  • x.mf.DeevTlagie6mlpz
  • x.mf.DvRgcSEqB7Qs
  • x.mf.E8P24vfqtl
  • x.mf.EB36lOylCag3CU
  • x.mf.ER0BBRpy6N
  • x.mf.FdJlvXko7c9x
  • x.mf.Ffiz93jCtj2
  • x.mf.FjS2wweUrJ7
  • x.mf.Fl6bMx35VyG21FN6
  • x.mf.FrGWFJLeaGGISO
  • x.mf.GAU6ZrDhdYh2i
  • x.mf.GJSTwhDhA0b
  • x.mf.GKxlEAzoDKo2vTP
  • x.mf.GRUarfK46BkbioA
  • x.mf.HPQq1I7owi
  • x.mf.HWCwEpTnYqTYR
  • x.mf.HazNe1y64M1TNJ
  • x.mf.HqUDilDvo9TJk
  • x.mf.JBm9HyX9NnRy
  • x.mf.JVyMXSsGWBCUR
  • x.mf.K4ozoBlmLroT
  • x.mf.KA1PTJj9Tr6RZ
  • x.mf.KMeoYzxLRP3VJ
  • x.mf.KYqj0V5P4UJeQ
  • x.mf.KiMD1Xk5Xez
  • x.mf.KnR8z2fIeWF
  • x.mf.LgHNZ6GBrP1
  • x.mf.MvjuJjzsHbaStIZk
  • x.mf.NTXv9qFZs6qmrC9f
  • x.mf.NokwBMaroYeoQ
  • x.mf.OZ3pX5xZTm4b6g
  • x.mf.OasuFtAffoEF98h
  • x.mf.PBOmRrWtlJZ
  • x.mf.Q0zDs0WjrAP
  • x.mf.Q4d91ZJzUMkyU
  • x.mf.QFdalFj4SpM
  • x.mf.QLYEDuoBbf
  • x.mf.Qamm4eCX8q
  • x.mf.QbGcCE5rUw
  • x.mf.RAtk6AfplS3le9j9
  • x.mf.RKOXxd5E6wIis
  • x.mf.RhMBspjr2es2
  • x.mf.RmXFJAqBAqRS
  • x.mf.S7T4NGJjutUo
  • x.mf.SjpE7sqCIZZBU
  • x.mf.SwHFsWJJYu
  • x.mf.UNLlt6zJjwhfv8s8
  • x.mf.UPTHTfvhFpE
  • x.mf.UWXPK54zlQnP
  • x.mf.UuM454GlFEoN2J
  • x.mf.VkTqEmkxKYI
  • x.mf.WBo6x2z39nBdXLNO
  • x.mf.WOYABnSObf
  • x.mf.WXhe6udTabvV
  • x.mf.Wetnuu6dmY5NA
  • x.mf.WrWsZ0T9ih
  • x.mf.WtnAQ19kkKM7Upb
  • x.mf.Yz95xj0LVB64
  • x.mf.ZC5gpGaLhoI0PSF
  • x.mf.ZalNahJrPp2
  • x.myr24.wbt.ww4
  • x.teuy.ggc93.vy2
  • x.u2m.yvrn.k5
  • x.uepm7.qebl.inq
  • x.vzspm.uwdsm.ub
  • x.wl5xi.jiwsp.g9
  • x.y1d.aoo.xzj
  • x.ywife.uq34.iph

Services (47)

  • com.template.shellapp.services.BlockVpnService
  • com.template.shellapp.services.SyncService
  • x.df7.lsgue.rmg
  • x.e3p8.j10e4.a8a
  • x.f0l.usl.i79
  • x.iym8i
  • x.jdc.o3xo.il0
  • x.k9lq
  • x.mee.ss7.p9
  • x.mf.AEZnokFQZEg8h1Mm
  • x.mf.AbvVo29uvqE
  • x.mf.Ap46hd4H5QrJHiq0
  • x.mf.BR6Y9U7oLEz
  • x.mf.CXR1BKYePBuff
  • x.mf.CaQqtyIwB4eeF
  • x.mf.D69VG56cDS
  • x.mf.DAZ6nBhtM5t
  • x.mf.EVJ7X42ohnlpvc
  • x.mf.FgMc5BTKolEX1W
  • x.mf.FlsmACGzXr7V
  • x.mf.GBM4dETzBU4ey
  • x.mf.GnJ0vMxK4zm60nYP
  • x.mf.H1Kb4MMfb6AX
  • x.mf.HDpEJbDqfEE37kVS
  • x.mf.ItydwKNDAJhfdm
  • x.mf.K2yFoMFHEhOr
  • x.mf.KpM5nimqLbaa
  • x.mf.LXb0X2uHBB0
  • x.mf.MnizjsjtYZVg4VGN
  • x.mf.MuHq4gUdEiqAYG
  • x.mf.OWGKyxmsJQUAV
  • x.mf.OWZwUHQFNhBgXBE
  • x.mf.OvYSoPBwbbsiZzIc
  • x.mf.SwxCfmlti6
  • x.mf.UFEa3BPfVK8p
  • x.mf.Uh4hJxdbSh9iR
  • x.mf.VNunojgIKi4
  • x.mf.W4naucLo4y5YDh
  • x.mf.X96Axf0b9F0k
  • x.mf.YUE4N0eKPKtX
  • x.mf.YgzmHEMphy
  • x.obo
  • x.p6mfk
  • x.p91e7
  • x.tfvn.t5n1.h2x
  • x.yfwe8.ho1u.ds
  • x.yzwql.whsa5.v5d

Receivers (32)

  • com.template.shellapp.CB
  • com.template.shellapp.receivers.BootReceiver
  • x.ed7n2
  • x.fstf.zpj90.s4
  • x.iyrno.oa9l.im7
  • x.kg4.oge.zr
  • x.ln1
  • x.mf.BRTp8ou9RanzRdj
  • x.mf.DZ69Kel5OGQRck
  • x.mf.EaLPeXkXuWA
  • x.mf.GNaeXQkcIE6fbH
  • x.mf.Hj0W7B1ECf
  • x.mf.I4LOiWSocFQDI
  • x.mf.IXHZwqV7gh0EU
  • x.mf.IukyjYJSaEZMJl
  • x.mf.Jo8WJdFU9OhGGngx
  • x.mf.Kjz4bsezArhfPGr2
  • x.mf.MGiGdybOzemMVY1v
  • x.mf.McYf6mTTrAh0
  • x.mf.NI7XUj9ISF3EyQ
  • x.mf.NKsuBpNh97QfRRu
  • x.mf.UPpO9My3Kuf
  • x.mf.UlMBY0ofWCa
  • x.mf.VdV4aRSCetvh9
  • x.mf.XaRshaPlIqqp
  • x.mf.XeDipLIP5td
  • x.mf.YWGp6tVwidSAN9T
  • x.mf.YzxdroNJzBkgE2
  • x.uyxdu.ncb.nmo
  • x.wkuv
  • x.x8j.h59o.avt
  • x.xrm7o

Providers (20)

  • x.imrw.rf6.qg
  • x.mf.ASMZw3uMejPVqGq
  • x.mf.F0actkeThl
  • x.mf.FDE95u4yaFnO
  • x.mf.IaJGilGhX3EMnKHm
  • x.mf.Ju2BjlrJBW5Y7h
  • x.mf.KGCktrdUx1J6kI01
  • x.mf.KPZ8yrFceJ
  • x.mf.KgmixsHoAO
  • x.mf.LwYm3D31GdAEyj9
  • x.mf.MoEO8V3qLyvM
  • x.mf.OnhCuUsgjr1
  • x.mf.RQ2yjDnZtTFxZ
  • x.mf.SOXd7gtMYwfR3
  • x.mf.T8Vcaxsa4xd0
  • x.mf.ULTzI52Ppam
  • x.qcbk
  • x.qtv
  • x.rfot.h3d0.pae
  • x.uw0g.bzb.d5

Intent filters — actions

android.intent.action.BOOT_COMPLETEDandroid.intent.action.MY_PACKAGE_REPLACEDandroid.net.VpnServicecom.streamline.core.mf.receiver.action.ghwmx45hfppxdf8jyl0ncom.streamline.core.mf.receiver.action.np2dup8vg5soqbghlv0ncom.streamline.core.mf.service.action.2wzvnejl7m66vm3fqyj0com.streamline.core.mf.service.action.bmxwva7j2j7n1hp10qq2com.streamline.core.mf.service.action.jlibxfyp2glfpf9f89qvcom.streamline.core.mf.service.action.l11sguy6mhcccqg1x4wacom.streamline.core.mf.service.action.rrx09gb0gg00lgv0iz45

Intent filters — categories

android.intent.category.INFO

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
64.188.62.110 ip 9800 ws Telegram Phish Proxy (provisional) 2026-10-06

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
c8a2e9bccf597c2fb6dc66bee293fc13f2fc47ec77bc6b2b0d52c11f51192ab8

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Telegram Phish Proxy (provisional)

Final payload of a **4-stage "shellapp" native dropper** (outer package `com.coresoft.studio`, horoscope *"goroskopys"* lure; final payload `com.apexware.utils` / `com.base.template`). Each stage decrypts and `DexClassLoader`-loads the next, so the real code never appears in the installed APK's dex. The unpacking recovered statically: stage 1→2 uses a native `nativeCipher` = `payload[16:] XOR SHA256(key)` with a per-sample repeating-XOR-obfuscated key; stage 2 (a VPN "Telegram-bypass" internet blocker) carries a `PayloadInstaller` that AES-256-CBC-decrypts `assets/payload.db`; stage 3 decrypts a further asset to the stage-4 stealer. The stealer runs a `ProxyService` that opens a **WebSocket device-relay C2** and a `TelegramPhishActivity` that drives a phishing WebView against an operator panel (`/api/phish/start`, `/api/phish/verify`, `/api/phish/2fa`) to steal Telegram logins and 2FA codes. All strings are repeating-XOR obfuscated. Family label provisional; C2 indicators are binary-verified by a full static unpack.