apitoken.modobomco.com

domain C2 not resolving

Tracked by C2 Tracker · Whois queried never

Registration

Registrar
-
Registered
-
Expires
-

DNS

Resolves to
-
Nameservers
-
Status
-

Observed in malware

FamilySample SHA-256RoleFirst seen
Modobom WAP Fraud (provisional) f63166f41ac9… C2 2026-10-07

About Modobom WAP Fraud (provisional)

Android WAP/toll-billing fraud tied to the Modobom ad-fraud operator. The app hides behind a game lure, requests SEND_SMS and CALL_PHONE, and pulls a silent premium-subscription config from an operator control backend (an auto_wap instruction feed on modobomco.com) that drives victims into paid WAP subscriptions. Landing pages are served from a rotating set of operator domains. Control/C2 hosts recovered as plaintext URLs in the dex; game-promo and app-store links used only as lures are not treated as indicators. Family label provisional.

Signing certificate

Subject CN
Android
Issuer CN
Android
Valid
2008-02-29 → 2035-07-17
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.