e1d70d1082555fb298c3f512…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
tcp://192.168.20.11:4444.Recovered configuration
Identification
- SHA-256
- e1d70d1082555fb298c3f5120d775db6220979939d4853684f8a3ea4494a8d94
- MD5
- 2b98b0feaf0e68aeff777f78f598a91d
Observed
- Families
- Metasploit
- First seen
- 2026-10-04
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 192.168.20.11 | ip | 4444 | tcp | Metasploit | 2026-10-04 |
Signing certificate
- Subject CN
- kali kali
- Issuer CN
- kali kali
- Fingerprint
- b9fbd0e46952a63c3ba5dc6419ae7b6d1d9c857fa981dbc443909f331ec3f1b3
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Metasploit
Android payloads generated by Metasploit / msfvenom (meterpreter and command stages), running under the package com.metasploit.stage. The payload dials back to LHOST:LPORT, which is the C2. Two config formats appear in the wild. In the older/plain format the transport URL (tcp://, ssl:// or https://LHOST:LPORT) is a const-string in the DEX. In the newer format the stage carries a protobuf TransportConfig in the static byte array Payload.a, parsed by an embedded protobuf-lite runtime (com.metasploit.a); that array is XOR-masked with a per-build 4-byte key, and because the buffer is zero-padded the leading bytes leak the key, so XORing the array by key[i mod 4] recovers the protobuf and its transport URL. Many samples are red-team or test builds pointing at LAN, loopback or 0.0.0.0 addresses (recorded verbatim); live ones use public IPs or tunnel fronts such as *.lhr.life (localhost.run) and *.loca.lt (localtunnel).