000a067df9235aea987cd1e6…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
Russian Premium SMS Trojan (provisional) - an Android SMS/OTP stealer, self-signed as “Reti”. Communicates with 1 operator endpoint. Russian premium-SMS fraud trojan (RuFraud/FakeInst-style; package com.depositmobi, SEND_SMS only). A fake ‘download agreement’ UI in Russian (res/raw/countries.cfg, keyed by MCC) tricks the user while the app sends premium SMS. Config res/raw/sms.cfg pins the distribution/C2 server http://android-my.ru/engine/download.php?id=2598, the lure app com.hippoapp.alarmlocation_1, and the premium billing string 1162+62688+d+a (premium short number 62688). androguard parses this one, but recorded via hash attribution with the statically-read config. Family label provisional. Indicators:
http://android-my.ru/engine/download.php.Recovered configuration
fake_app
com.hippoapp.alarmlocation_1
package
com.depositmobi
premium_number
62688
sms_config
1162+62688+d+a
Identification
- SHA-256
- 000a067df9235aea987cd1e6b7768bcc1053e640b267c5b1f0deefc18be5dbe1
- MD5
- ac926221a2c45f4b3f8721400341ceb0
Observed
- Families
- Russian Premium SMS Trojan (provisional)
- First seen
- 2011-11-14
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| android-my.ru/engine/download.php | domain | - | http | Russian Premium SMS Trojan (provisional) | 2011-11-14 |
Signing certificate
- Subject CN
- Code Coder
- Issuer CN
- Code Coder
- Fingerprint
- 6c51d90fcaded4681fb96892222cfeec28eb30ed3edcd9e410c6dc2340666e70
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.