b7c7704d7cfb0a10db9a4c69…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Proxy Relay Botnet (provisional) - an Android malware family, self-signed as “Android”. Communicates with 1 operator endpoint. Android proxy-relay botnet (package com.app.mz.bmwn, app label BmwApplication). Turns the device into a proxy node: the DataReporter class opens a socket to a remote “prxserver” and relays traffic (strings ConnectedToProxserver, ConnectionWithHost, ‘prxServer finish connection error’). Proxy/C2 server song.bestipip.com:16000. Requests REQUEST_INSTALL_PACKAGES. C2 per threat research. Family label provisional. Indicators: song.bestipip.com:16000.

Recovered configuration

package
com.app.mz.bmwn
reference
amtracker

Identification

SHA-256
b7c7704d7cfb0a10db9a4c6900e8adacc4ee69c2ed9857675f2810f8271c7bf9
MD5
0c54d3c88f4c4f5be55e042cb3c3664d

Observed

Families
Proxy Relay Botnet (provisional)
First seen
2024-04-03

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
song.bestipip.com domain 16000 - Proxy Relay Botnet (provisional) 2024-04-03

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Fingerprint
dec8cc20520eceff734db2156a530448230a0471e59bb9b16e1894147af73160

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.