b6dc251ea9ce86cb3aaf06a4…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Metasploit. Android payloads generated by the Metasploit Framework’s msfvenom (package com.metasploit.stage, the stock android/meterpreter stager). A small bootstrap APK pulls the meterpreter stage from a handler (LHOST:LPORT, default port 4444) and grants a remote operator full device control - SMS, contacts, call logs, camera, microphone and file access. Metasploit is a legitimate penetration-testing framework, so samples range from red-team/training builds (non-routable test LHOSTs such as 10.0.2.15 or 192.168.x, recorded here as placeholders) to real intrusions; the family tag marks the tool, and each sample’s handler address is the indicator when it is a routable one. Indicators: tcp://192.168.27.128:4444.

Recovered configuration

package
com.metasploit.stage
payload
android/meterpreter (msfvenom)
test_lhost
192.168.27.128:4444

Identification

SHA-256
b6dc251ea9ce86cb3aaf06a4eb284aac48d0a319c166a31a727f99f9e85671cb
MD5
6d4c03d72f82cb2110bd9d2488fa359b

Observed

Families
Metasploit
First seen
2026-10-08

APK metadata

Summary

Type
Android · APK
Package
com.metasploit.stage
Main activity
com.metasploit.stage.MainActivity
Internal version
1
Displayed version
1.0
Min SDK
10
Target SDK
17

Signing certificate

Valid from
2025-12-22 13:11:42
Valid to
2037-02-08 23:49:49
Serial
1
Thumbprint
fd7cd7f665c14b3d93228f37c9f74fee1eaff005
Subject
C:US/O=Android/CN=Android Debug
Issuer
C:US/O=Android/CN=Android Debug

Permissions (23)

android.permission.ACCESS_COARSE_LOCATIONandroid.permission.ACCESS_FINE_LOCATIONandroid.permission.ACCESS_NETWORK_STATEandroid.permission.ACCESS_WIFI_STATEandroid.permission.CALL_PHONEandroid.permission.CAMERAandroid.permission.CHANGE_WIFI_STATEandroid.permission.INTERNETandroid.permission.READ_CALL_LOGandroid.permission.READ_CONTACTSandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.RECORD_AUDIOandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SEND_SMSandroid.permission.SET_WALLPAPERandroid.permission.WAKE_LOCKandroid.permission.WRITE_CALL_LOGandroid.permission.WRITE_CONTACTSandroid.permission.WRITE_EXTERNAL_STORAGEandroid.permission.WRITE_SETTINGS

Activities (1)

  • com.metasploit.stage.MainActivity

Services (1)

  • com.metasploit.stage.MainService

Receivers (1)

  • com.metasploit.stage.MainBroadcastReceiver

Intent filters — actions

android.intent.action.BOOT_COMPLETED

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
192.168.27.128 ip 4444 tcp Metasploit 2026-10-08

Signing certificate

Subject CN
—
Issuer CN
—
Fingerprint
8ad283e0a06c7c218615b80ee2f7125635b0580ecebe8fe893479fcbfa06b1c2

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Metasploit

Android payloads generated by the Metasploit Framework's msfvenom (package com.metasploit.stage, the stock android/meterpreter stager). A small bootstrap APK pulls the meterpreter stage from a handler (LHOST:LPORT, default port 4444) and grants a remote operator full device control - SMS, contacts, call logs, camera, microphone and file access. Metasploit is a legitimate penetration-testing framework, so samples range from red-team/training builds (non-routable test LHOSTs such as 10.0.2.15 or 192.168.x, recorded here as placeholders) to real intrusions; the family tag marks the tool, and each sample's handler address is the indicator when it is a routable one.