b7c7704d7cfb0a10db9a4c69…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
Proxy Relay Botnet (provisional) - an Android malware family, self-signed as “Android”. Communicates with 1 operator endpoint. Android proxy-relay botnet (package com.app.mz.bmwn, app label BmwApplication). Turns the device into a proxy node: the DataReporter class opens a socket to a remote “prxserver” and relays traffic (strings ConnectedToProxserver, ConnectionWithHost, ‘prxServer finish connection error’). Proxy/C2 server song.bestipip.com:16000. Requests REQUEST_INSTALL_PACKAGES. C2 per threat research. Family label provisional. Indicators:
song.bestipip.com:16000.Recovered configuration
package
com.app.mz.bmwn
reference
amtracker
Identification
- SHA-256
- b7c7704d7cfb0a10db9a4c6900e8adacc4ee69c2ed9857675f2810f8271c7bf9
- MD5
- 0c54d3c88f4c4f5be55e042cb3c3664d
Observed
- Families
- Proxy Relay Botnet (provisional)
- First seen
- 2024-04-03
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| song.bestipip.com | domain | 16000 | - | Proxy Relay Botnet (provisional) | 2024-04-03 |
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Fingerprint
- dec8cc20520eceff734db2156a530448230a0471e59bb9b16e1894147af73160
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.