8eb2f04065333e308689e509…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
MobileFoneX Spyware (provisional) - Android spyware, self-signed as “VC”. Communicates with 1 operator endpoint. Commercial Android monitoring/spyware ‘MobileFoneX MobileBackup’ (package com.mobilefonex.mobilebackup; one of the earliest Android spyware, first seen 2010-01). Harvests SMS (receivers.SMSIn), call/phone state (PhoneState, PROCESS_OUTGOING_CALLS, CALL_PHONE), contacts and fine/coarse location and uploads to the operator service at mobilefonex.mobi (lefonex.mobi), using tinyurl api-create to shorten exfil/location links. androguard cannot parse this old-format APK, so it is hash-attributed. Family label provisional. Indicators:
mobilefonex.mobi.Recovered configuration
package
com.mobilefonex.mobilebackup
Identification
- SHA-256
- 8eb2f04065333e308689e509bc333557e217d6b6bc3def791421853e06cc90bf
- MD5
- 8514c499f825ca5682a548081c2e6c61
Observed
- Families
- MobileFoneX Spyware (provisional)
- First seen
- 2010-01-13
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| mobilefonex.mobi | domain | - | - | MobileFoneX Spyware (provisional) | 2010-01-13 |
Signing certificate
- Subject CN
- -
- Issuer CN
- -
- Fingerprint
- daa8233e236c2d9b2694fefece58e06a96c02ff3c28303164f5afd41bf422dbc
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.