b7c7704d7cfb0a10db9a4c69…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
song.bestipip.com:16000.Recovered configuration
Identification
- SHA-256
- b7c7704d7cfb0a10db9a4c6900e8adacc4ee69c2ed9857675f2810f8271c7bf9
- MD5
- 0c54d3c88f4c4f5be55e042cb3c3664d
Observed
- Families
- Proxy Relay Botnet (provisional)
- First seen
- 2024-04-03
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| song.bestipip.com | domain | 16000 | - | Proxy Relay Botnet (provisional) | 2024-04-03 |
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Fingerprint
- dec8cc20520eceff734db2156a530448230a0471e59bb9b16e1894147af73160
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Proxy Relay Botnet (provisional)
**Proxy Relay Botnet (provisional)** turns the infected Android device into a proxy relay node. The DataReporter component opens a socket to a remote prxserver and relays traffic (telltale strings ConnectedToProxserver, ConnectionWithHost, prxServer finish connection error). Observed proxy/C2 server song.bestipip.com:16000; the app (BmwApplication, package com.app.mz.bmwn) requests REQUEST_INSTALL_PACKAGES. Family label provisional.