33cae07bc7d39cdbe23b3123…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Math-App SMS Stealer (provisional) - an Android SMS/OTP stealer, signed with the public Android test/debug key (shared across many unrelated apps, so it is not an author fingerprint). Communicates with 1 operator endpoint. Android SMS stealer/banker (pkg com.dose.page) disguised as a math/equation-scanner app. C2 endpoints (math-themed API routes /derive/ /integrate/ /sin/ /simplify/ /log/) hardcoded in config class com.math.photo.scanner.equation.formula, host http://157.245.102.236:3000 (DigitalOcean). Requests READ/RECEIVE/SEND/WRITE_SMS, SYSTEM_ALERT_WINDOW, REQUEST_INSTALL_PACKAGES, CALL_PHONE; carries crypto-wallet/blockchain strings. Not Dendroid/EventBot. Label provisional. Indicators: http://157.245.102.236:3000/derive/.

Recovered configuration

c2_ip
157.245.102.236:3000
package
com.dose.page

Identification

SHA-256
33cae07bc7d39cdbe23b3123c6de42697c0d67798795fd5e665245c9c9fb1bdd
MD5
efeabacf216c4a5b79ebe5d8bdffc523

Observed

Families
Math-App SMS Stealer (provisional)
First seen
2022-12-23

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
157.245.102.236/derive/ ip 3000 http Math-App SMS Stealer (provisional) 2022-12-23

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.