e296be45721e501c83e7df36…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
https://api.telegram.org, https://t.me/MRBijiOntaMars69.Recovered configuration
Source: statically unpacked 4-stage native dropper -> Telegram bot payload
Identification
- SHA-256
- e296be45721e501c83e7df3626d43a0309449090725f4b6cf3b8f01aaf387140
- MD5
- 5c8d5480109014ca4a261e6af1fa020a
Observed
- Families
- Telegram Dropper (provisional)
- First seen
- –
APK metadata
Summary
- Type
- Android · APK
- Package
- com.secure.android.provider.jamym51
- Main activity
- etadl.flswv.adefgj.Ubrojjy72zjq26w
- Internal version
- 369
- Displayed version
- 2.4.79
- Min SDK
- 24
- Target SDK
- 37
Signing certificate
- Valid from
- 2023-03-07 10:06:56
- Valid to
- 2050-07-23 10:06:56
- Serial
- 354afd4b
- Thumbprint
- 4b29afc23e39fd541aaaf2fd16b0c90c9d9ea0bb
- Subject
- C:US, CN:QA Team, L:Palo Alto, O:Mattermost Inc., ST:California, OU:qa
- Issuer
- C:US, CN:QA Team, L:Palo Alto, O:Mattermost Inc., ST:California, OU:qa
Permissions (605)
Activities (2)
- etadl.flswv.adefgj.Ubrojjy72zjq26w
- etadl.flswv.adefgj.ui.W4k2bqqvxu07hf
Services (1)
- etadl.flswv.adefgj.vpn.Hi9f4kxq036liln
Receivers (3)
- androidx.profileinstaller.ProfileInstallReceiver
- etadl.flswv.adefgj.installer.Fcy273xtal7
- etadl.flswv.adefgj.installer.W188j8bvtcgd
Providers (2)
- androidx.core.content.FileProvider
- androidx.startup.InitializationProvider
Intent filters - actions
C2 configuration (2)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| api.telegram.org | domain | - | https | Telegram Dropper (provisional) | 2026-10-05 |
| t.me/MRBijiOntaMars69 | domain | - | https | Telegram Dropper (provisional) | – |
Signing certificate
- Subject CN
- QA Team
- Issuer CN
- QA Team
- Fingerprint
- 1431eedaa27b30fd846283f083e52a5fa40c0261e1a039a337a37174d699e750
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Telegram Dropper (provisional)
Android banking-malware dropper that leans on commodity cloud services for delivery and control. It pulls second-stage configuration/payloads and exfiltrates data through the Telegram Bot API (api.telegram.org) and t.me channels, with Firebase (Realtime Database / Storage) and DuckDNS hosts (e.g. binarypanel.duckdns.org) used as fallback C2/staging. Family label provisional.