75a7ccc2e9366e32aeeb3498…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
http://183.111.122.43:8080.Recovered configuration
Identification
- SHA-256
- 75a7ccc2e9366e32aeeb34981eea0c90f6b0c536bf484d02ac8d3c4acac77974
- MD5
- f7e61cd7e9ff3ab95a89afc304323a1d
Observed
- Families
- WhiteBroad
- First seen
- 2018-11-28
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 183.111.122.43 | ip | 8080 | http | WhiteBroad | 2018-11-28 |
Signing certificate
- Subject CN
- yescofield
- Issuer CN
- yescofield
- Fingerprint
- 806b6f8979e54c2eaa8bd1281b0c886814a187b681321e04dbda7f333cd3ca6b
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About WhiteBroad
Android spyware family spanning several build flavors: com.red.rainbow and cn.close.vcl.play (plus repacks caught by a four-part manifest fingerprint) carry the C2 as a CompileConfig static field or ApiManager getApi() const-string shaped http://host/v1/api/...; a common/Constant; class exposes the full endpoint set (IP_ADDRESS, CONFIG_URL, *_URL). The com.android.hellon flavor moves the C2 into the .rodata of bundled libhelper/libma?sker native libraries as plain http(s) .php URLs.