Dendroid
Malware family · 7 sample(s) · 8 indicator record(s) · 6 signing certificate(s) · Active 2019-07-16 → 2020-04-29 (experimental)
About Dendroid
One of the earliest commercial Android RATs, sold openly around 2014. Identified by the com.connect.MyService service; the config (panel URL, backup URL, password) lives base64-encoded as const-strings stored into the encodedURL / backupURL / encodedPassword fields of MyService..
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| glug.freecluster.eu | domain | 523d3305ac09… | 2020-04-29 |
| josequervo.net/master | domain | 092df2a10b3d… | 2020-03-08 |
| josequervo.net/master | domain | 72408d70ed81… | 2020-03-08 |
| kipk.cf/pu/ | domain | 712e04130c2f… | 2019-09-27 |
| pizzachip.com/rat | domain | 10f3ed976800… | 2020-04-29 |
| stephen.kl.com.ua/ | domain | 712e04130c2f… | 2019-09-27 |
| 127.0.0.1 | ip | 909ac45cde3a… | 2019-09-23 |
| 82.41.82.92 | ip | d569e0cb100b… | 2020-04-20 |
Detected samples without extractable endpoint (2)
Family matched by code marker or hash attribution, but no C2 is statically extractable - the endpoint arrives at runtime.
| SHA-256 | Package | Note | First seen |
|---|---|---|---|
| bfea0288a3c463f0f1646cf23eed920b49b90c5ff316d42715c8c7bf8ba1e2e5 | com.adobe.flash13 | 2019-07-16 | |
| ca53cdcbc80e364fe4fc1ec3173aaf0a1e74ce79879c0e9a57d66bf1f6095f80 | com.parental.control.v4 | 2019-08-03 |