c51ff0587c160d2009d4a333…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
Flutter SMS Stealer (provisional). A Flutter-built Android SMS/PII stealer of likely Chinese origin, distributed under social and adult-content app disguises. Flutter apps compile their real logic to a native Dart “snapshot” inside lib/<abi>/libapp.so rather than to ordinary Java/DEX, so both the behaviour and the C2 live in that .so file instead of in the usual Android code.
What it does
- Harvests SMS messages, contacts, call logs and location and exfiltrates them to the operator.
- Ships under the stable packages
com.dataapp.data_collectorandcom.jlsw.jmy, as well as randomly-named packages (e.g.com.ncwtaakvv.rzpyvfqstgw). - Some builds are additionally wrapped with the Jiagu commercial packer; the Flutter payload is identical once unpacked.
How the C2 is recovered (binary-only)
The command-and-control endpoint is a hardcoded bare-IP HTTP URL compiled directly into the Dart snapshot libapp.so, read out of that file’s string pool. The cluster rotates across a small set of hosting IPs (observed 156.254.21.112, 156.254.21.43, 172.252.173.36, 172.252.224.194, 172.252.224.195, 66.212.58.145). Family label provisional. Indicators: http://66.212.58.145.
Recovered configuration
Source: hardcoded bare-IP base URL compiled into Flutter libapp.so (Jiagu-packed Dalvik layer)
Identification
- SHA-256
- c51ff0587c160d2009d4a333744e458250fe486710202c8677967583b6baf832
- MD5
- b8e3840e07d18e10edd957d20f634805
Observed
- Families
- Flutter SMS Stealer (provisional)
- First seen
- 2026-10-01
APK metadata
Summary
- Type
- Android · APK
- Package
- com.dmygjlf.fcloxyqflu
- Main activity
- com.dmygjlf.fcloxyqflu.MainActivity
- Internal version
- 1
- Displayed version
- 1.0.0
- Min SDK
- 24
- Target SDK
- 33
Signing certificate
- Valid from
- 2026-09-30 11:33:37
- Valid to
- 2027-11-03 11:33:37
- Serial
- ceabddaf586611e3f7f229a9fa9902ee9665de7
- Thumbprint
- 4d240a89feedb583b39aee9dc3e0f610d36ac54e
- Subject
- C:BA, CN:EHZVNJ, L:T84X873S, O:Q44A5A6SN5, ST:DLW7LM9R, OU:LYMHHHB2, email:[email protected]
- Subject email
- [email protected]
- Issuer
- C:BA, CN:EHZVNJ, L:T84X873S, O:Q44A5A6SN5, ST:DLW7LM9R, OU:LYMHHHB2, email:[email protected]
Permissions (18)
Intent filters - actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 66.212.58.145 | ip | - | http | Flutter SMS Stealer (provisional) | 2026-10-01 |
Signing certificate
- Subject CN
- EHZVNJ
- Issuer CN
- EHZVNJ
- Fingerprint
- 15782565eb42c3b63427855561d9ba6287cc51e8f1f54f26c1b8609975bafebf
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Flutter SMS Stealer (provisional)
A **Flutter**-built Android SMS/PII stealer of likely Chinese origin, distributed under social and adult-content app disguises. Flutter apps compile their real logic to a native Dart "snapshot" inside `lib/<abi>/libapp.so` rather than to ordinary Java/DEX, so both the behaviour and the C2 live in that `.so` file instead of in the usual Android code. **What it does** - Harvests **SMS messages, contacts, call logs and location** and exfiltrates them to the operator. - Ships under the stable packages `com.dataapp.data_collector` and `com.jlsw.jmy`, as well as randomly-named packages (e.g. `com.ncwtaakvv.rzpyvfqstgw`). - Some builds are additionally wrapped with the **Jiagu** commercial packer; the Flutter payload is identical once unpacked. **How the C2 is recovered (binary-only)** The command-and-control endpoint is a hardcoded **bare-IP HTTP** URL compiled directly into the Dart snapshot `libapp.so`, read out of that file's string pool. The cluster rotates across a small set of hosting IPs (observed `156.254.21.112`, `156.254.21.43`, `172.252.173.36`, `172.252.224.194`, `172.252.224.195`, `66.212.58.145`). Family label provisional.