8eb2f04065333e308689e509…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

MobileFoneX Spyware (provisional) - Android spyware, self-signed as “VC”. Communicates with 1 operator endpoint. Commercial Android monitoring/spyware ‘MobileFoneX MobileBackup’ (package com.mobilefonex.mobilebackup; one of the earliest Android spyware, first seen 2010-01). Harvests SMS (receivers.SMSIn), call/phone state (PhoneState, PROCESS_OUTGOING_CALLS, CALL_PHONE), contacts and fine/coarse location and uploads to the operator service at mobilefonex.mobi (lefonex.mobi), using tinyurl api-create to shorten exfil/location links. androguard cannot parse this old-format APK, so it is hash-attributed. Family label provisional. Indicators: mobilefonex.mobi.

Recovered configuration

package
com.mobilefonex.mobilebackup

Identification

SHA-256
8eb2f04065333e308689e509bc333557e217d6b6bc3def791421853e06cc90bf
MD5
8514c499f825ca5682a548081c2e6c61

Observed

Families
MobileFoneX Spyware (provisional)
First seen
2010-01-13

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
mobilefonex.mobi domain - - MobileFoneX Spyware (provisional) 2010-01-13

Signing certificate

Subject CN
-
Issuer CN
-
Fingerprint
daa8233e236c2d9b2694fefece58e06a96c02ff3c28303164f5afd41bf422dbc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.