844b58576a5f7848e3349d74…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
assets/c2_config.json with a panel API URL and a vnc_server_url plus fallbacks, and an assets/mode.json marking device_type: rat. Distinct from the Telegram Phish Proxy payload (which uses a ws://<ip>:9800 device relay and a phishing WebView); here the operator drives a VNC session over wss://. C2 indicators are recovered by a full static unpack of the dropper. Family label provisional. Indicators: https://appmetric-cdn.buzz/vnc-ws, https://cloudmetric-api.top/vnc-ws, https://netpulseapichill.biz/vnc-ws, https://testdomain-lil.shop/vnc-ws.Recovered configuration
Identification
- SHA-256
- 844b58576a5f7848e3349d744bbcbac848f39ee2eb5bffd832c7720623603a9d
- MD5
- 2b37b58557159088f0b54667e3b46e7d
Observed
- Families
- Shellapp VNC RAT (provisional)
- First seen
- 2026-09-29
APK metadata
Summary
- Type
- Android · APK
- Package
- com.quickdev.bridge
- Main activity
- com.template.shellapp.MainActivity
- Internal version
- 1
- Displayed version
- 1.0
- Min SDK
- 26
- Target SDK
- 35
Signing certificate
- Valid from
- 2017-12-02 08:49:52
- Valid to
- 2042-11-26 08:49:52
- Serial
- 675b171b
- Thumbprint
- 0897ad328f32968a6bad07722de7ddf86e936dfb
- Subject
- C:86
- Issuer
- C:86
Permissions (17)
Intent filters - actions
Intent filters - categories
C2 configuration (4)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| appmetric-cdn.buzz/vnc-ws | domain | - | https | Shellapp VNC RAT (provisional) | 2026-09-29 |
| cloudmetric-api.top/vnc-ws | domain | - | https | Shellapp VNC RAT (provisional) | 2026-09-29 |
| netpulseapichill.biz/vnc-ws | domain | - | https | Shellapp VNC RAT (provisional) | 2026-09-29 |
| testdomain-lil.shop/vnc-ws | domain | - | https | Shellapp VNC RAT (provisional) | 2026-09-29 |
Signing certificate
- Subject CN
- -
- Issuer CN
- -
- Fingerprint
- eea324cf335f92ef4d5d9812f6104ca9972f1a60c985ed579d09b24d149b347c
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Shellapp VNC RAT (provisional)
VNC-over-WebSocket remote-access payload shipped behind the **"shellapp" native dropper** (same packer as Telegram Phish Proxy). The unpacked stealer carries a plaintext `assets/c2_config.json` with a panel API URL and a `vnc_server_url` plus fallbacks, and an `assets/mode.json` marking `device_type: rat`. Distinct from the Telegram Phish Proxy payload (which uses a `ws://<ip>:9800` device relay and a phishing WebView); here the operator drives a VNC session over `wss://`. C2 indicators are recovered by a full static unpack of the dropper. Family label provisional.