e1d2ad8dfaa518c2e9f7fdad…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Magic Dropper (builder / dropper-as-a-service output). This is a generated installer stub, not a bespoke family: a “Magic”-branded DaaS builder wraps an operator-chosen payload and ships a plaintext assets/magic_build_overlay.json naming where the real APK lives and which paid build it is. The stub’s only job is to download and install that payload. Overlay recovered from this sample:

  • Payload-delivery endpoint (C2): https://polisasas.com/down/50165d38-0589-44d7-ae8d-bfbbfd98bdde – the per-build URL the stub fetches the real APK from.
  • Dropped package: com.silverapps.garden0x0x0x0x (the payload it sideloads).
  • DaaS tenant / build identity: teamId=4555347, workerId=dd3c89a790d74701, buildSecureId=0e38f6dc856dcab38345586b120b5bd93a1fd25982ae110aff7038702ba23d84, buildApiKey=4f586270e8edfbc6f73308694ad66c365db8f6419e206999. Defender pivots: block/report the exact polisasas.com/down/<uuid> URL and the host as the payload source; the real malware is whatever that URL serves (sideloaded as com.silverapps.garden0x0x0x0x). The teamId/buildSecureId tie this stub to one DaaS tenant, so other stubs carrying the same teamId are the same operator/build batch. Payload may also ship bundled-encrypted as assets/pad.bin. Recovery is binary-only from the overlay JSON; family label provisional.

Identification

SHA-256
e1d2ad8dfaa518c2e9f7fdad891b1ee9eb1a361a673de74e3d73263bbb9cfc26
MD5
4d95645ad4ed08152f5a6f4157b572f3

Observed

Families
Magic Dropper (provisional)
First seen
2026-10-03

APK metadata

Summary

Type
Android · APK
Package
dev.fusionharbor.bridgealphax
Main activity
io.wave.device.ShellHostActivity
Internal version
1
Displayed version
1337.0-2026_10_03_08-48-17
Min SDK
26
Target SDK
35

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject email
android@android.com
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com

Permissions (10)

android.permission.FOREGROUND_SERVICEandroid.permission.FOREGROUND_SERVICE_SPECIAL_USEandroid.permission.INTERNETandroid.permission.POST_NOTIFICATIONSandroid.permission.READ_EXTERNAL_STORAGEandroid.permission.READ_MEDIA_IMAGESandroid.permission.READ_MEDIA_VIDEOandroid.permission.REQUEST_INSTALL_PACKAGESandroid.permission.WRITE_EXTERNAL_STORAGEdev.fusionharbor.bridgealphax.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (1)

  • io.wave.device.ShellHostActivity

Services (1)

  • io.wave.device.BlockerVpnService

Receivers (2)

  • androidx.profileinstaller.ProfileInstallReceiver
  • io.wave.device.JobOutcomeReceiver

Providers (2)

  • androidx.core.content.FileProvider
  • androidx.startup.InitializationProvider

Intent filters — actions

android.net.VpnServiceandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEdev.fusionharbor.bridgealphax.action.JOB_CLRdev.fusionharbor.bridgealphax.action.JOB_OK

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
polisasas.com/down/50165d38-0589-44d7-ae8d-bfbbfd98bdde domain — https Magic Dropper (provisional) 2026-10-03

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.