18f02dd87210fc75a7da90a7…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
18f02dd87210fc75a7da90a7637bb0920453aee59bbc4bfd820b6576c3fd9dbe
MD5
a4b68eb8b4ab1c21e52554cdc7770c99

Observed

Families
AndroRat
First seen
2019-10-08

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
hacker12345.ddns.net domain 100 — AndroRat 2019-10-08

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About AndroRat

One of the oldest open-source Android RATs (first released ~2012), still repackaged into fresh campaigns. Classic builds carry the my.app.client package; repackaged flavors ship under innocuous package names and app titles like "Google Service Framework".