a7f01fc26000d9d0124e38c0…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Metasploit. Android payloads generated by Metasploit / msfvenom (meterpreter and command stages), running under the package com.metasploit.stage. The payload dials back to LHOST:LPORT, which is the C2. Two config formats appear in the wild. In the older/plain format the transport URL (tcp://, ssl:// or https://LHOST:LPORT) is a const-string in the DEX. In the newer format the stage carries a protobuf TransportConfig in the static byte array Payload.a, parsed by an embedded protobuf-lite runtime (com.metasploit.a); that array is XOR-masked with a per-build 4-byte key, and because the buffer is zero-padded the leading bytes leak the key, so XORing the array by key[i mod 4] recovers the protobuf and its transport URL. Many samples are red-team or test builds pointing at LAN, loopback or 0.0.0.0 addresses (recorded verbatim); live ones use public IPs or tunnel fronts such as *.lhr.life (localhost.run) and *.loca.lt (localtunnel). Indicators: https://a01fb7af0461b1.lhr.life:443.

Recovered configuration

cluster_note
Same localhost.run tunnel host (a01fb7af0461b1.lhr.life:443) reused across 4 distinct samples (0e374119, a32c17e3, a7f01fc2, ba9df4f7) -> same operator / reserved tunnel / one build run. Ephemeral rendezvous: value is clustering, not blocking; the apex lhr.life is shared SaaS and is never an indicator on its own.
indicator_note
Ephemeral reverse-tunnel rendezvous on shared SaaS (localhost.run/localtunnel); the full per-session hostname is the beacon target but rotates and the bare apex must never be blocked.
package
com.metasploit.stage

Identification

SHA-256
a7f01fc26000d9d0124e38c06a1e2fee3f8ca21b91ba3bf49abd40ede3b07143
MD5
1ead46fa5c6198c6f5d6d97bb01bfa6d

Observed

Families
Metasploit
First seen
2026-10-08

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
a01fb7af0461b1.lhr.life domain 443 https Metasploit 2026-10-08

Signing certificate

Subject CN
-
Issuer CN
-
Fingerprint
d3f825ec3103a4f9226adc4b00d22f9214e5cc3990ff8375376bdb15e9444734

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Metasploit

Android payloads generated by Metasploit / msfvenom (meterpreter and command stages), running under the package com.metasploit.stage. The payload dials back to LHOST:LPORT, which is the C2. Two config formats appear in the wild. In the older/plain format the transport URL (tcp://, ssl:// or https://LHOST:LPORT) is a const-string in the DEX. In the newer format the stage carries a protobuf TransportConfig in the static byte array Payload.a, parsed by an embedded protobuf-lite runtime (com.metasploit.a); that array is XOR-masked with a per-build 4-byte key, and because the buffer is zero-padded the leading bytes leak the key, so XORing the array by key[i mod 4] recovers the protobuf and its transport URL. Many samples are red-team or test builds pointing at LAN, loopback or 0.0.0.0 addresses (recorded verbatim); live ones use public IPs or tunnel fronts such as *.lhr.life (localhost.run) and *.loca.lt (localtunnel).