000a067df9235aea987cd1e6…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Russian Premium SMS Trojan (provisional) - an Android SMS/OTP stealer, self-signed as “Reti”. Communicates with 1 operator endpoint. Russian premium-SMS fraud trojan (RuFraud/FakeInst-style; package com.depositmobi, SEND_SMS only). A fake ‘download agreement’ UI in Russian (res/raw/countries.cfg, keyed by MCC) tricks the user while the app sends premium SMS. Config res/raw/sms.cfg pins the distribution/C2 server http://android-my.ru/engine/download.php?id=2598, the lure app com.hippoapp.alarmlocation_1, and the premium billing string 1162+62688+d+a (premium short number 62688). androguard parses this one, but recorded via hash attribution with the statically-read config. Family label provisional. Indicators: http://android-my.ru/engine/download.php.

Recovered configuration

fake_app
com.hippoapp.alarmlocation_1
package
com.depositmobi
premium_number
62688
sms_config
1162+62688+d+a

Identification

SHA-256
000a067df9235aea987cd1e6b7768bcc1053e640b267c5b1f0deefc18be5dbe1
MD5
ac926221a2c45f4b3f8721400341ceb0

Observed

Families
Russian Premium SMS Trojan (provisional)
First seen
2011-11-14

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
android-my.ru/engine/download.php domain - http Russian Premium SMS Trojan (provisional) 2011-11-14

Signing certificate

Subject CN
Code Coder
Issuer CN
Code Coder
Fingerprint
6c51d90fcaded4681fb96892222cfeec28eb30ed3edcd9e410c6dc2340666e70

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.