e1d2ad8dfaa518c2e9f7fdad…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
Magic Dropper (builder / dropper-as-a-service output). This is a generated installer stub, not a bespoke family: a “Magic”-branded DaaS builder wraps an operator-chosen payload and ships a plaintext assets/magic_build_overlay.json naming where the real APK lives and which paid build it is. The stub’s only job is to download and install that payload.
Overlay recovered from this sample:
- Payload-delivery endpoint (C2):
https://polisasas.com/down/50165d38-0589-44d7-ae8d-bfbbfd98bdde– the per-build URL the stub fetches the real APK from. - Dropped package:
com.silverapps.garden0x0x0x0x(the payload it sideloads). - DaaS tenant / build identity:
teamId=4555347,workerId=dd3c89a790d74701,buildSecureId=0e38f6dc856dcab38345586b120b5bd93a1fd25982ae110aff7038702ba23d84,buildApiKey=4f586270e8edfbc6f73308694ad66c365db8f6419e206999. Defender pivots: block/report the exactpolisasas.com/down/<uuid>URL and the host as the payload source; the real malware is whatever that URL serves (sideloaded ascom.silverapps.garden0x0x0x0x). TheteamId/buildSecureIdtie this stub to one DaaS tenant, so other stubs carrying the sameteamIdare the same operator/build batch. Payload may also ship bundled-encrypted asassets/pad.bin. Recovery is binary-only from the overlay JSON; family label provisional.
Identification
- SHA-256
- e1d2ad8dfaa518c2e9f7fdad891b1ee9eb1a361a673de74e3d73263bbb9cfc26
- MD5
- 4d95645ad4ed08152f5a6f4157b572f3
Observed
- Families
- Magic Dropper (provisional)
- First seen
- 2026-10-03
APK metadata
Summary
- Type
- Android · APK
- Package
- dev.fusionharbor.bridgealphax
- Main activity
- io.wave.device.ShellHostActivity
- Internal version
- 1
- Displayed version
- 1337.0-2026_10_03_08-48-17
- Min SDK
- 26
- Target SDK
- 35
Signing certificate
- Valid from
- 2008-02-29 01:33:46
- Valid to
- 2035-07-17 01:33:46
- Serial
- 936eacbe07f201df
- Thumbprint
- 61ed377e85d386a8dfee6b864bd85b0bfaa5af81
- Subject
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
- Subject email
- android@android.com
- Issuer
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Permissions (10)
Intent filters — actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| polisasas.com/down/50165d38-0589-44d7-ae8d-bfbbfd98bdde | domain | — | https | Magic Dropper (provisional) | 2026-10-03 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.