d6aeeba8aa65674aa4138bfa…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Store Lure Dropper (provisional) — an Android dropper that installs a second-stage payload, distributed as dev.quantumorbit.a.a8o51, signed with the public Android test/debug key (shared across many unrelated apps, so it is not an author fingerprint). It installs further packages. Communicates with 1 operator endpoint. Android dropper impersonating the Russian Megamarket retail app (app label “Мегамаркет”, package dev.quantumorbit.a.a8o51). On launch it requests REQUEST_INSTALL_PACKAGES and fetches a second-stage APK from its distribution server at https://minipeka.info/down/ (observed 80174326-29f0-4897-bb67-bd6f021d0666), then prompts the victim to install it. The download host is the actionable indicator (recovered in plaintext). Family label provisional; Russian-targeted. Indicators: https://minipeka.info/down/.

Recovered configuration

behaviour
side-load second-stage APK
lure
Megamarket (Russian retail app)
package
dev.quantumorbit.a.a8o51
payload_host
https://minipeka.info/down/<uuid>

Identification

SHA-256
d6aeeba8aa65674aa4138bfaa60c23159d91eaf530e11c897f3b58912f9f2465
MD5
e8ee00b2a9b4132315b6bb74105e3cd2

Observed

Families
Store Lure Dropper (provisional)
First seen
2026-08-26

APK metadata

Summary

Type
Android · APK
Package
dev.quantumorbit.a.a8o51
Main activity
com.nexus.portal.FrameActivity
Internal version
1
Displayed version
1337.0-2026_08_26_13-44-32
Min SDK
26
Target SDK
34

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject email
android@android.com
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com

Permissions (13)

android.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_SPECIAL_USEandroid.permission.INTERNETandroid.permission.POST_NOTIFICATIONSandroid.permission.READ_EXTERNAL_STORAGEandroid.permission.READ_MEDIA_IMAGESandroid.permission.READ_MEDIA_VIDEOandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.REQUEST_DELETE_PACKAGESandroid.permission.REQUEST_INSTALL_PACKAGESandroid.permission.WRITE_EXTERNAL_STORAGEandroid.permission.WRITE_SYNC_SETTINGSdev.quantumorbit.a.a8o51.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (1)

  • com.nexus.portal.FrameActivity

Services (1)

  • com.nexus.portal.BlockerVpnService

Receivers (1)

  • com.nexus.portal.InstallResultReceiver

Providers (2)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider

Intent filters — actions

android.net.VpnServicedev.quantumorbit.a.a8o51.action.JOB_CLRdev.quantumorbit.a.a8o51.action.JOB_OK

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
minipeka.info/down/ domain — https Store Lure Dropper (provisional) 2026-08-26

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.