a70c310e5fd743b75e90976c…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Dual-RAT repackage — mapped to both SandroRat (DroidJack) and AhMyth. This APK (launcher package com.elijash.blog) bundles two complete RAT codebases: DroidJack/SandroRat (net.droidjack.server.*, incl. CamSnapDJ/VideoCapDJ activities) and AhMyth (ahmyth/mine/king/ahmyth/*, incl. IOSocket). Both configs resolve to the same C2, sudomorning-60041.portmap.io:60041 — recovered independently from the DroidJack config class <clinit> (host const-string + port const/16) and from AhMyth’s IOSocket.<init> Socket.IO URL. Because both families are genuinely present and wired to the same endpoint, the sample is attributed to both rather than to whichever decoder happened to match first. (The port reads as 60041, confirmed by the sudomorning-60041 portmap.io subdomain; a naive signed-16-bit parse yields −5495.)

Recovered configuration

package
com.elijash.blog

Identification

SHA-256
a70c310e5fd743b75e90976c33d0cc88cfac2e355df5bc41053377812610ca8c
MD5
2204084f3e1ef9e1c4e7c77fc3df5515

Observed

Families
AhMyth, SandroRat
First seen
2018-12-24

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
sudomorning-60041.portmap.io domain 60041 http AhMyth 2018-12-24

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About AhMyth

Open-source Android RAT whose builder lowered the bar for mobile surveillance; has repeatedly sneaked into the Google Play store disguised inside seemingly legitimate apps.

About SandroRat

Android remote-access trojan sold as "DroidJack", repackaged under many names over the years. Its config (host + port) hides in the static initializer of an obfuscated helper class referenced from MainActivity.onCreate via an sget-byte field read.