8bd23d6635f112da49ea041c…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
Script-Bot Dropper (provisional), package com.mmtjb3. A thin Android stub whose real
logic is delivered as a hot-updated Lua/script bundle, so almost nothing malicious lives in
the APK itself.
Command / update channel: the app polls http://maomaotoujioben.oss-cn-hangzhou.aliyuncs.com/mmtjb3/version.txt,
an Alibaba Cloud OSS bucket, which returns:
{"downloadUrl":"http://maomaotoujioben.oss-cn-hangzhou.aliyuncs.com/mmtjb3/update.hot","version":1791269153}
Payload: update.hot is a ZIP containing script.lc, script.prop, script.rtd,
script.uip, script.uis - the hot-loaded engine/UI scripts that actually drive the bot.
Defenders should block/monitor the .../mmtjb3/update.hot and version.txt paths on the OSS
bucket; the second host dwz.junwfk.com/1JcMi is a short-link used for distribution.
Recovered configuration
Identification
- SHA-256
- 8bd23d6635f112da49ea041c1af9c12d2f296b69fad86fe0bde74f95c903cde6
- MD5
- 18412f55381deaab7ea66d2747a0c0f4
Observed
- Families
- Script-Bot Dropper (provisional)
- First seen
- 2026-10-01
APK metadata
Summary
- Type
- Android · APK
- Package
- com.mmtjb3
- Main activity
- com.cyjh.elfin.activity.news.SplashActivity
- Internal version
- 2017011016
- Displayed version
- 5.6.0
- Min SDK
- 16
- Target SDK
- 26
Signing certificate
- Valid from
- 2008-02-29 01:33:46
- Valid to
- 2035-07-17 01:33:46
- Serial
- 936eacbe07f201df
- Thumbprint
- 61ed377e85d386a8dfee6b864bd85b0bfaa5af81
- Subject
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
- Subject email
- [email protected]
- Issuer
- C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
Permissions (46)
Intent filters - actions
Intent filters - categories
C2 configuration (2)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| dwz.junwfk.com/1JcMi | domain | - | - | Script-Bot Dropper (provisional) | 2026-10-01 |
| maomaotoujioben.oss-cn-hangzhou.aliyuncs.com/mmtjb3/version.txt | domain | - | http | Script-Bot Dropper (provisional) | 2026-10-01 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Script-Bot Dropper (provisional)
**Script-Bot Dropper** (provisional, package com.mmtjb3) is a thin Android stub whose real logic is delivered as a hot-updated Lua/script bundle, so almost nothing malicious ships inside the APK itself. It polls an Alibaba Cloud OSS bucket (maomaotoujioben.oss-cn-hangzhou.aliyuncs.com) and a short-link resolver (dwz.junwfk.com) for its script payload and commands. Behaviour is click-fraud / automation botting driven entirely by the remotely served scripts.