a8e7f53427fff29d46b43efe…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- a8e7f53427fff29d46b43efe508cd046537b09324b6b0574c3e15b863b4136a1
- MD5
- 7426af4623416e1be73576f9e2b17488
Observed
- Families
- FakeSpy
- First seen
- 2019-10-07
APK metadata
Summary
- Type
- Android · APK
- Package
- com.example.dew18.a
- Main activity
- com.example.dew18.a.MainActivity
- Internal version
- 1
- Displayed version
- 1.0
- Min SDK
- 19
- Target SDK
- 22
Permissions (18)
Intent filters — actions
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 182.162.104.202/ | ip | — | http | FakeSpy | 2019-10-07 |
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About FakeSpy
Android spyware posing as legitimate postal/ delivery-service apps, exfiltrating SMS and contact data to a PHP panel. The panel base URL is an http:// const-string in the MyService$ReThread (or MeService$ReThread) run() loop; some builds instead carry CONFIG_URL / IP_ADDRESS / LOGS_URL as static field values of Lorg/red/cute/common/Constant;.