4c41274f3927577cff271de5…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- 4c41274f3927577cff271de57b3de3a464c11add7245d272877bc676a369dd3b
- MD5
- abf97951187ea6bd4fb8c72ccd0e8acc
Observed
- Families
- FakeSpy
- First seen
- 2018-11-19
APK metadata
Summary
- Type
- Android · APK
- Package
- com.example.dew18.myapplication
- Main activity
- com.example.dew18.myapplication.MainActivity
- Internal version
- 1
- Displayed version
- 1.0
- Min SDK
- 19
- Target SDK
- 22
Signing certificate
- Valid from
- 2018-11-18 16:12:15
- Valid to
- 2043-11-12 16:12:15
- Serial
- 201e1594
- Thumbprint
- 68434ea0127d974f0df513c6891b2c060e99bcb5
- Subject
- C:86, CN:oeofjkdk, L:dofjasdlkv, O:oefjnkflablqofjaksdf, ST:fkdjb, OU:oejfckbl
- Issuer
- C:86, CN:oeofjkdk, L:dofjasdlkv, O:oefjnkflablqofjaksdf, ST:fkdjb, OU:oejfckbl
Permissions (18)
Intent filters — actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 211.169.248.242/ | ip | — | http | FakeSpy | 2018-11-19 |
Signing certificate
- Subject CN
- oeofjkdk
- Issuer CN
- oeofjkdk
- Fingerprint
- 1429bb5704ae437a33f7f591f9cd05d761db3e103617a097e3a5128b52a88d36
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About FakeSpy
Android spyware posing as legitimate postal/ delivery-service apps, exfiltrating SMS and contact data to a PHP panel. The panel base URL is an http:// const-string in the MyService$ReThread (or MeService$ReThread) run() loop; some builds instead carry CONFIG_URL / IP_ADDRESS / LOGS_URL as static field values of Lorg/red/cute/common/Constant;.