e3832322e716af75d3de3b1b…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
com.sbyvt.qodevfkr; REQUEST_INSTALL_PACKAGES, QUERY_ALL_PACKAGES, RECEIVE_BOOT_COMPLETED) hidden behind a “gosuvpn” VPN lure. The real child payload ships as an encrypted ~4.4 MB asset (assets/jcvwjmntop.bin, marker .__wombat_payload__.) and is installed as genome.apk/g.apk; the install UI is assets/bloom.html with a {{BLOOM_DOWNLOADS}} template and decoy store links. Dropper strings are obfuscated with StringFog (com.github.megatronking.stringfog.xor, repeating-key XOR); decoding the StringFog byte-array pairs recovers the distribution/C2 host https://gosuvpnweb.top. The sample also embeds a spoofed OnePlus 8 Pro build fingerprint and many decoy padding assets. C2 recovered statically via source-to-sink StringFog decode; family label provisional. Indicators: https://gosuvpnweb.top.Recovered configuration
Identification
- SHA-256
- e3832322e716af75d3de3b1b1da2b8e85c0364dad6022afe1f2730d5868baac5
- MD5
- 485afcb2868e4f09fd2cdeb7c8bd140d
Observed
- Families
- GosuVPN Dropper (provisional)
- First seen
- 2026-10-08
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| gosuvpnweb.top | domain | - | https | GosuVPN Dropper (provisional) | 2026-10-08 |
Signing certificate
- Subject CN
- com_android_nfc
- Issuer CN
- com_android_nfc
- Fingerprint
- fae9122a8721d6e2a196d2224dffcf773c9127e2bb956cbddb40b009192ffdfd
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About GosuVPN Dropper (provisional)
**GosuVPN Dropper (provisional)** is an Android install-time dropper (package `com.sbyvt.qodevfkr`; REQUEST_INSTALL_PACKAGES, QUERY_ALL_PACKAGES, RECEIVE_BOOT_COMPLETED) hidden behind a "gosuvpn" VPN lure. The real child payload ships as an encrypted ~4.4 MB asset (`assets/jcvwjmntop.bin`, marker `.__wombat_payload__.`) and is installed as `genome.apk`/`g.apk`; the install UI is `assets/bloom.html` with a {{BLOOM_DOWNLOADS}} template and decoy store links. Dropper strings are obfuscated with StringFog (`com.github.megatronking.stringfog.xor`, repeating-key XOR); decoding the StringFog byte-array pairs recovers the distribution/C2 host `https://gosuvpnweb.top`. The sample also embeds a spoofed OnePlus 8 Pro build fingerprint and many decoy padding assets. C2 recovered statically via source-to-sink StringFog decode; family label provisional.