Dendroid

Malware family · 7 sample(s) · 8 indicator record(s) · 6 signing certificate(s) · Active 2019-07-16 → 2020-04-29 (experimental)

About Dendroid

One of the earliest commercial Android RATs, sold openly around 2014. Identified by the com.connect.MyService service; the config (panel URL, backup URL, password) lives base64-encoded as const-strings stored into the encodedURL / backupURL / encodedPassword fields of MyService..

Indicators

IndicatorTypeSampleFirst seen
glug.freecluster.eu domain 523d3305ac09… 2020-04-29
josequervo.net/master domain 092df2a10b3d… 2020-03-08
josequervo.net/master domain 72408d70ed81… 2020-03-08
kipk.cf/pu/ domain 712e04130c2f… 2019-09-27
pizzachip.com/rat domain 10f3ed976800… 2020-04-29
stephen.kl.com.ua/ domain 712e04130c2f… 2019-09-27
127.0.0.1 ip 909ac45cde3a… 2019-09-23
82.41.82.92 ip d569e0cb100b… 2020-04-20

Detected samples without extractable endpoint (2)

Family matched by code marker or hash attribution, but no C2 is statically extractable - the endpoint arrives at runtime.

SHA-256PackageNoteFirst seen
bfea0288a3c463f0f1646cf23eed920b49b90c5ff316d42715c8c7bf8ba1e2e5 com.adobe.flash13 2019-07-16
ca53cdcbc80e364fe4fc1ec3173aaf0a1e74ce79879c0e9a57d66bf1f6095f80 com.parental.control.v4 2019-08-03