0000065384a28b39fc95704e…

sample

Tracked by C2 Tracker Ā· indicators & metadata only, the APK itself is never published

Analyst notes

ChinaSMSStealer. SMS-intercepting stealer exfiltrating over email rather than a network C2: the SMTP account and password sit as const-strings in the i()/j() accessors of Lcom/phone/stop/db/a;. Detected by a four-part manifest fingerprint (INTERNET, activity.MainActivity, receiver.SMSReceiver, service.SecondService). Indicators: a15221319850@vip.163.com:qq168168.

Identification

SHA-256
0000065384a28b39fc95704e457125e1fb0dfb6e2df074ffe6abdd5c7bf4d082
MD5
4caf3754a67c5d30a5fa06bdbcf57dd4

Observed

Families
ChinaSMSStealer
First seen
2026-04-09

APK metadata

Summary

Type
Android Ā· APK
Package
com.ith5e.cn56y
Main activity
aa.bb.cc.dd.ClientActivity
Internal version
—
Displayed version
—
Min SDK
—
Target SDK
—

Signing certificate

Valid from
2015-04-23 06:21:20
Valid to
2115-03-30 06:21:20
Serial
7f153241
Thumbprint
cd9944a9b66dd95d102d6f6b6b57b7234aa80866
Subject
C:86, CN:y9uh, L:6ryfug, O:6tygu, ST:6tyug, OU:6yug
Issuer
C:86, CN:y9uh, L:6ryfug, O:6tygu, ST:6tyug, OU:6yug

Permissions (17)

android.permission.ACCESS_NETWORK_STATEandroid.permission.ACCESS_WIFI_STATEandroid.permission.CALL_PHONEandroid.permission.GET_TASKSandroid.permission.INTERNETandroid.permission.READ_CALL_LOGandroid.permission.READ_CONTACTSandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.SEND_SMSandroid.permission.VIBRATEandroid.permission.WRITE_CALL_LOGandroid.permission.WRITE_EXTERNAL_STORAGEandroid.permission.WRITE_SETTINGSandroid.permission.WRITE_SMS

Activities (8)

  • aa.bb.cc.dd.ClientActivity
  • aa.bb.cc.dd.FX
  • aa.bb.cc.dd.UninActivity
  • aa.bb.cc.dd.Uninstaller
  • aa.bb.cc.dd.WebInterfaceActivity
  • com.aa.bb.cc.dd.UninstallerActivity
  • com.ith5e.cn56y.MainActivity
  • com.shit.ComposeSmsActivity

Services (2)

  • com.ith5e.cn56y.HeadlessSmsSendService
  • com.ith5e.cn56y.MyService

Receivers (5)

  • aa.bb.cc.dd.BootReceiver
  • com.ith5e.cn56y.AlarmReceiver
  • com.ith5e.cn56y.Dx
  • com.ith5e.cn56y.MmsReceiver
  • com.ith5e.cn56y.XReceiver

Intent filters — actions

android.app.action.DEVICE_ADMIN_ENABLEDandroid.intent.action.BOOT_COMPLETEDandroid.intent.action.RESPOND_VIA_MESSAGEandroid.provider.Telephony.SMS_DELIVERandroid.provider.Telephony.SMS_RECEIVEDandroid.provider.Telephony.WAP_PUSH_DELIVER

Intent filters — categories

android.intent.category.DEFAULT

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
a15221319850@vip.163.com:qq168168 email — — ChinaSMSStealer 2026-04-09

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About ChinaSMSStealer

SMS-intercepting stealer exfiltrating over email rather than a network C2: the SMTP account and password sit as const-strings in the i()/j() accessors of Lcom/phone/stop/db/a;. Detected by a four-part manifest fingerprint (INTERNET, activity.MainActivity, receiver.SMSReceiver, service.SecondService).