WhiteBroad
Malware family · 15 sample(s) · 15 indicator record(s) · 3 signing certificate(s) · Active 2018-11-09 → 2019-03-08 (experimental)
About WhiteBroad
Android spyware family spanning several build flavors: com.red.rainbow and cn.close.vcl.play (plus repacks caught by a four-part manifest fingerprint) carry the C2 as a CompileConfig static field or ApiManager getApi() const-string shaped http://host/v1/api/…; a common/Constant; class exposes the full endpoint set (IP_ADDRESS, CONFIG_URL, *_URL). The com.android.hellon flavor moves the C2 into the .rodata of bundled libhelper/libma?sker native libraries as plain http(s) .php URLs.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 180.150.226.122:8080 | ip | 2fc1f2220375… | 2018-12-07 |
| 180.150.226.122:8080 | ip | 77efb6de7409… | 2018-12-13 |
| 180.150.227.8:8080 | ip | eb13781968e9… | 2018-12-18 |
| 180.70.134.76:8080 | ip | fbbe92080415… | 2019-03-08 |
| 183.111.122.156:8080 | ip | 4b67e5db3a3a… | 2018-12-05 |
| 183.111.122.185:8080 | ip | cbf5b3e62ac1… | 2018-12-29 |
| 183.111.122.43:8080 | ip | 75a7ccc2e936… | 2018-11-28 |
| 183.111.122.58:8080 | ip | 6fccc3d0ae9b… | 2018-12-29 |
| 183.111.122.63:8080 | ip | 1d1519d511a9… | 2018-12-19 |
| 183.111.122.63:8080 | ip | 8b3215611c7b… | 2018-12-21 |
| 183.111.122.63:8080 | ip | b9db15b41689… | 2018-12-29 |
| 27.255.64.3:8080 | ip | 18105bb5cc06… | 2018-12-01 |
| 27.255.72.30:8080 | ip | f81b0c01b007… | 2018-11-14 |
| 27.255.80.231:8080 | ip | 41db9722392f… | 2018-11-30 |
| 27.255.80.231:8080 | ip | 4e3847d6d85d… | 2018-11-09 |