c6ad7e66f7fb0018ea5627b0…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Metasploit. Android payloads generated by Metasploit / msfvenom (meterpreter and command stages), running under the package com.metasploit.stage. The payload dials back to LHOST:LPORT, which is the C2. Two config formats appear in the wild. In the older/plain format the transport URL (tcp://, ssl:// or https://LHOST:LPORT) is a const-string in the DEX. In the newer format the stage carries a protobuf TransportConfig in the static byte array Payload.a, parsed by an embedded protobuf-lite runtime (com.metasploit.a); that array is XOR-masked with a per-build 4-byte key, and because the buffer is zero-padded the leading bytes leak the key, so XORing the array by key[i mod 4] recovers the protobuf and its transport URL. Many samples are red-team or test builds pointing at LAN, loopback or 0.0.0.0 addresses (recorded verbatim); live ones use public IPs or tunnel fronts such as *.lhr.life (localhost.run) and *.loca.lt (localtunnel). Indicators: tcp://10.0.2.15:4444.

Recovered configuration

package
com.metasploit.stage
payload
android/meterpreter (msfvenom)
test_lhost
10.0.2.15:4444

Identification

SHA-256
c6ad7e66f7fb0018ea5627b0dc5f77fc44a8ff7846a0784d9ca8664d9d21f9a5
MD5
ea2369a3d1b692159a070b5c66278109

Observed

Families
Metasploit
First seen
2026-10-08

APK metadata

Summary

Type
Android · APK
Package
com.metasploit.stage
Main activity
com.metasploit.stage.MainActivity
Internal version
1
Displayed version
1.0
Min SDK
10
Target SDK
17

Signing certificate

Valid from
2025-05-21 13:08:55
Valid to
2035-05-24 21:51:34
Serial
1
Thumbprint
9b80dbb7306b974aba61bcef4b98d673310e756b
Subject
C:US/O=Android/CN=Android Debug
Issuer
C:US/O=Android/CN=Android Debug

Permissions (23)

android.permission.ACCESS_COARSE_LOCATIONandroid.permission.ACCESS_FINE_LOCATIONandroid.permission.ACCESS_NETWORK_STATEandroid.permission.ACCESS_WIFI_STATEandroid.permission.CALL_PHONEandroid.permission.CAMERAandroid.permission.CHANGE_WIFI_STATEandroid.permission.INTERNETandroid.permission.READ_CALL_LOGandroid.permission.READ_CONTACTSandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.RECORD_AUDIOandroid.permission.REQUEST_IGNORE_BATTERY_OPTIMIZATIONSandroid.permission.SEND_SMSandroid.permission.SET_WALLPAPERandroid.permission.WAKE_LOCKandroid.permission.WRITE_CALL_LOGandroid.permission.WRITE_CONTACTSandroid.permission.WRITE_EXTERNAL_STORAGEandroid.permission.WRITE_SETTINGS

Activities (1)

  • com.metasploit.stage.MainActivity

Services (1)

  • com.metasploit.stage.MainService

Receivers (1)

  • com.metasploit.stage.MainBroadcastReceiver

Intent filters - actions

android.intent.action.BOOT_COMPLETED

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
10.0.2.15 ip 4444 tcp Metasploit 2026-10-08

Signing certificate

Subject CN
-
Issuer CN
-
Fingerprint
c1a0b39a22875d8c956349043e8f420214ea81f20edef8639fd44e558717761e

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Metasploit

Android payloads generated by Metasploit / msfvenom (meterpreter and command stages), running under the package com.metasploit.stage. The payload dials back to LHOST:LPORT, which is the C2. Two config formats appear in the wild. In the older/plain format the transport URL (tcp://, ssl:// or https://LHOST:LPORT) is a const-string in the DEX. In the newer format the stage carries a protobuf TransportConfig in the static byte array Payload.a, parsed by an embedded protobuf-lite runtime (com.metasploit.a); that array is XOR-masked with a per-build 4-byte key, and because the buffer is zero-padded the leading bytes leak the key, so XORing the array by key[i mod 4] recovers the protobuf and its transport URL. Many samples are red-team or test builds pointing at LAN, loopback or 0.0.0.0 addresses (recorded verbatim); live ones use public IPs or tunnel fronts such as *.lhr.life (localhost.run) and *.loca.lt (localtunnel).