e3832322e716af75d3de3b1b…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

GosuVPN Dropper (provisional). GosuVPN Dropper (provisional) is an Android install-time dropper (package com.sbyvt.qodevfkr; REQUEST_INSTALL_PACKAGES, QUERY_ALL_PACKAGES, RECEIVE_BOOT_COMPLETED) hidden behind a “gosuvpn” VPN lure. The real child payload ships as an encrypted ~4.4 MB asset (assets/jcvwjmntop.bin, marker .__wombat_payload__.) and is installed as genome.apk/g.apk; the install UI is assets/bloom.html with a {{BLOOM_DOWNLOADS}} template and decoy store links. Dropper strings are obfuscated with StringFog (com.github.megatronking.stringfog.xor, repeating-key XOR); decoding the StringFog byte-array pairs recovers the distribution/C2 host https://gosuvpnweb.top. The sample also embeds a spoofed OnePlus 8 Pro build fingerprint and many decoy padding assets. C2 recovered statically via source-to-sink StringFog decode; family label provisional. Indicators: https://gosuvpnweb.top.

Recovered configuration

child_apk
genome.apk
distribution_host
gosuvpnweb.top
package
com.sbyvt.qodevfkr
packer
StringFog XOR string obfuscation + encrypted asset payload

Identification

SHA-256
e3832322e716af75d3de3b1b1da2b8e85c0364dad6022afe1f2730d5868baac5
MD5
485afcb2868e4f09fd2cdeb7c8bd140d

Observed

Families
GosuVPN Dropper (provisional)
First seen
2026-10-08

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
gosuvpnweb.top domain - https GosuVPN Dropper (provisional) 2026-10-08

Signing certificate

Subject CN
com_android_nfc
Issuer CN
com_android_nfc
Fingerprint
fae9122a8721d6e2a196d2224dffcf773c9127e2bb956cbddb40b009192ffdfd

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About GosuVPN Dropper (provisional)

**GosuVPN Dropper (provisional)** is an Android install-time dropper (package `com.sbyvt.qodevfkr`; REQUEST_INSTALL_PACKAGES, QUERY_ALL_PACKAGES, RECEIVE_BOOT_COMPLETED) hidden behind a "gosuvpn" VPN lure. The real child payload ships as an encrypted ~4.4 MB asset (`assets/jcvwjmntop.bin`, marker `.__wombat_payload__.`) and is installed as `genome.apk`/`g.apk`; the install UI is `assets/bloom.html` with a {{BLOOM_DOWNLOADS}} template and decoy store links. Dropper strings are obfuscated with StringFog (`com.github.megatronking.stringfog.xor`, repeating-key XOR); decoding the StringFog byte-array pairs recovers the distribution/C2 host `https://gosuvpnweb.top`. The sample also embeds a spoofed OnePlus 8 Pro build fingerprint and many decoy padding assets. C2 recovered statically via source-to-sink StringFog decode; family label provisional.