Metasploit

Malware family · 31 sample(s) · 31 indicator record(s) · 29 signing certificate(s) · Active 2026-09-20 → 2026-10-11 (experimental)

About Metasploit

Android payloads generated by Metasploit / msfvenom (meterpreter and command stages), running under the package com.metasploit.stage. The payload dials back to LHOST:LPORT, which is the C2. Two config formats appear in the wild. In the older/plain format the transport URL (tcp://, ssl:// or https://LHOST:LPORT) is a const-string in the DEX. In the newer format the stage carries a protobuf TransportConfig in the static byte array Payload.a, parsed by an embedded protobuf-lite runtime (com.metasploit.a); that array is XOR-masked with a per-build 4-byte key, and because the buffer is zero-padded the leading bytes leak the key, so XORing the array by key[i mod 4] recovers the protobuf and its transport URL. Many samples are red-team or test builds pointing at LAN, loopback or 0.0.0.0 addresses (recorded verbatim); live ones use public IPs or tunnel fronts such as *.lhr.life (localhost.run) and *.loca.lt (localtunnel).

Indicators

IndicatorTypeSampleFirst seen
198093e2a63c17.lhr.life:443 domain 8d5d57a9b9dd… 2026-10-08
a01fb7af0461b1.lhr.life:443 domain 0e374119192a… 2026-10-08
a01fb7af0461b1.lhr.life:443 domain a32c17e333f9… 2026-10-08
a01fb7af0461b1.lhr.life:443 domain a7f01fc26000… 2026-10-08
a01fb7af0461b1.lhr.life:443 domain ba9df4f77503… 2026-10-08
orange-times-join.loca.lt:4444 domain e7ccdd997a28… 2026-10-10
0.0.0.0:4444 ip 03a1fe04ec36… 2026-10-09
10.0.2.15:4444 ip c6ad7e66f7fb… 2026-10-08
127.0.0.1:4444 ip b559b3d4fbf7… 2026-10-06
154.244.104.146:4444 ip d68b43f37b04… 2026-10-09
172.24.135.166:4444 ip 583c04d8726d… 2026-10-10
172.24.135.166:4444 ip 60fc70f8ab38… 2026-10-10
172.24.135.166:4444 ip 94aa198303b7… 2026-10-10
172.24.135.166:4444 ip deb7baae8601… 2026-10-10
172.25.152.84:4005 ip 95a6edd99c75… 2026-10-11
190.168.98.92:10086 ip e5260b85c316… 2026-09-25
192.168.0.110:8888 ip a88e4c6a9b49… 2026-10-03
192.168.1.10:4444 ip 58031d0230b1… 2026-10-06
192.168.1.110:4444 ip 63b6b4da5596… 2026-10-02
192.168.1.110:4444 ip d07f9331d777… 2026-10-02
192.168.1.3:22001 ip 17c0fd040f0d… 2026-09-20
192.168.10.8:4444 ip b1fdf25d6819… 2026-10-05
192.168.108.128:4444 ip f97a29dc26a0… 2026-09-29
192.168.123.151:10086 ip 930bc90c9b6c… 2026-09-25
192.168.18.110:4444 ip 0c258c2e7243… 2026-10-10
192.168.20.11:4444 ip e1d70d108255… 2026-10-04
192.168.27.128:4444 ip b6dc251ea9ce… 2026-10-08
192.168.43.146:4444 ip cb1227a95046… 2026-10-08
192.168.43.192:443 ip 7304a8996358… 2026-10-04
192.168.44.3:4444 ip 8d6a924c31a1… 2026-10-03
192.168.8.243:4444 ip 0106e49ef1ac… 2026-10-09

Detected samples without extractable endpoint (1)

Family matched by code marker or hash attribution, but no C2 is statically extractable - the endpoint arrives at runtime.

SHA-256PackageNoteFirst seen
ec4c271f1d042084ed9569fcab893ca13c3b438bf958abb68ee3a7dddb077d9f com.metasploit.stage Metasploit Android meterpreter stage (com.metasploit.stage). No embedded LHOST recovered in plaintext (staged payload fetches its handler at runtime); recorded as a family detection with no actionable C2. 2026-10-08