b1d7c28025a430e048e728c0…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
Miyu Romance-Scam App (provisional) - an Android malware family, self-signed as “fe”. Communicates with 1 operator endpoint. Chinese romance-scam / dating app ‘蜜语’ (miyu, package uni.app.cqeo) built on the uni-app (DCloud) JS framework. Requests READ_SMS, CAMERA and REQUEST_INSTALL_PACKAGES. Its backend/C2 is http://api.miyu919.fit, recovered from the uni-app JS bundle (assets/apps/__UNI__F0B5F31/www). Family label provisional. Indicators:
http://api.miyu919.fit.Recovered configuration
app_label
蜜语
backend
http://api.miyu919.fit
framework
uni-app (DCloud)
package
uni.app.cqeo
Identification
- SHA-256
- b1d7c28025a430e048e728c086908b04ca22fbf73b4abf63f32711a0867061a6
- MD5
- 6fc3de9718127432899b5b5de8ae4b58
Observed
- Families
- Miyu Romance-Scam App (provisional)
- First seen
- 2026-10-10
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| api.miyu919.fit | domain | - | http | Miyu Romance-Scam App (provisional) | 2026-10-10 |
Signing certificate
- Subject CN
- fewr
- Issuer CN
- fewr
- Fingerprint
- be2e3db87bc047f9d9f018ddcc4e2be973e6565a2e7ed1be95b3496c528f3cb7
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.