6dd7c9573329ba8ae5389dd8…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
wss://144.31.167.91:8443/ws.Recovered configuration
Identification
- SHA-256
- 6dd7c9573329ba8ae5389dd89e569d41d28db9a50e8172ad2f087c72370ad83a
- MD5
- 5798712fd54329c4a9f085b9a1f98a7a
Observed
- Families
- WebSocket SMS Stealer (provisional)
- First seen
- 2026-10-11
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 144.31.167.91/ws | ip | 8443 | wss | WebSocket SMS Stealer (provisional) | 2026-10-11 |
Signing certificate
- Subject CN
- APK Signer
- Issuer CN
- APK Signer
- Fingerprint
- b6da01480eefd5fbf2cd3771b8d1021ec791304bdd6c4bf41d3faabad48ee5e1
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About WebSocket SMS Stealer (provisional)
Modern Kotlin Android stealer (observed 2026) that requests SMS, call and contacts permissions and talks to its C2 over a WebSocket using the OkHttp client. Endpoints seen in captured traffic include an HTTP registration call (/api/v1/register) and a WebSocket channel (/ws) on port 8443. The implant is heavily obfuscated: strings are encrypted and the C2 configuration is stored as a custom AES-GCM container in an encrypted asset (observed name assets/<rand>.cache), so the host is not present in the DEX in any plaintext, base64, hex or single-byte-XOR form and is only resolved at runtime. Provisional bucket pending attribution.