c6ad7e66f7fb0018ea5627b0…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
tcp://10.0.2.15:4444.Recovered configuration
Identification
- SHA-256
- c6ad7e66f7fb0018ea5627b0dc5f77fc44a8ff7846a0784d9ca8664d9d21f9a5
- MD5
- ea2369a3d1b692159a070b5c66278109
Observed
- Families
- Metasploit
- First seen
- 2026-10-08
APK metadata
Summary
- Type
- Android · APK
- Package
- com.metasploit.stage
- Main activity
- com.metasploit.stage.MainActivity
- Internal version
- 1
- Displayed version
- 1.0
- Min SDK
- 10
- Target SDK
- 17
Signing certificate
- Valid from
- 2025-05-21 13:08:55
- Valid to
- 2035-05-24 21:51:34
- Serial
- 1
- Thumbprint
- 9b80dbb7306b974aba61bcef4b98d673310e756b
- Subject
- C:US/O=Android/CN=Android Debug
- Issuer
- C:US/O=Android/CN=Android Debug
Permissions (23)
Intent filters — actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 10.0.2.15 | ip | 4444 | tcp | Metasploit | 2026-10-08 |
Signing certificate
- Subject CN
- —
- Issuer CN
- —
- Fingerprint
- c1a0b39a22875d8c956349043e8f420214ea81f20edef8639fd44e558717761e
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Metasploit
Android payloads generated by the Metasploit Framework's msfvenom (package com.metasploit.stage, the stock android/meterpreter stager). A small bootstrap APK pulls the meterpreter stage from a handler (LHOST:LPORT, default port 4444) and grants a remote operator full device control - SMS, contacts, call logs, camera, microphone and file access. Metasploit is a legitimate penetration-testing framework, so samples range from red-team/training builds (non-routable test LHOSTs such as 10.0.2.15 or 192.168.x, recorded here as placeholders) to real intrusions; the family tag marks the tool, and each sample's handler address is the indicator when it is a routable one.