b1d7c28025a430e048e728c0…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Miyu Romance-Scam App (provisional) - an Android malware family, self-signed as “fe”. Communicates with 1 operator endpoint. Chinese romance-scam / dating app ‘蜜语’ (miyu, package uni.app.cqeo) built on the uni-app (DCloud) JS framework. Requests READ_SMS, CAMERA and REQUEST_INSTALL_PACKAGES. Its backend/C2 is http://api.miyu919.fit, recovered from the uni-app JS bundle (assets/apps/__UNI__F0B5F31/www). Family label provisional. Indicators: http://api.miyu919.fit.

Recovered configuration

app_label
蜜语
backend
http://api.miyu919.fit
framework
uni-app (DCloud)
package
uni.app.cqeo

Identification

SHA-256
b1d7c28025a430e048e728c086908b04ca22fbf73b4abf63f32711a0867061a6
MD5
6fc3de9718127432899b5b5de8ae4b58

Observed

Families
Miyu Romance-Scam App (provisional)
First seen
2026-10-10

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
api.miyu919.fit domain - http Miyu Romance-Scam App (provisional) 2026-10-10

Signing certificate

Subject CN
fewr
Issuer CN
fewr
Fingerprint
be2e3db87bc047f9d9f018ddcc4e2be973e6565a2e7ed1be95b3496c528f3cb7

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.