f01d9a2d49f49d28aaf222d7…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
Premium SMS Trojan (provisional) - an Android SMS/OTP stealer, signed with the public Android test/debug key (shared across many unrelated apps, so it is not an author fingerprint). Communicates with 4 operator endpoints. Early (2010) Chinese premium-SMS / fee-fraud and adware trojan (package com.hotel, SMS engine under com.mms.bg with SmsReceiver/PrivilegedSmsReceiver/AutoSMSRecevier and SEND_SMS/RECEIVE_SMS/BROADCAST_SMS). Silently sends and intercepts premium SMS and pulls content/billing config over HTTP. Statically recovered cleartext endpoints: 211.136.165.53 (/adapted/choose.jsp, /wl/rmw1s/pp66.jsp), union.zhuna.cn/api/utf-8/, www.youlubg.com:81/Coop/request3.php and xuesenlin.w44.mc-test.com. (mmsc.monternet.com, mapabc.com and 10.0.0.172 are legitimate China Mobile MMS/WAP infrastructure, excluded.) androguard cannot parse this old-format APK, so it is hash-attributed. Family label provisional. Indicators:
http://211.136.165.53/wl/rmw1s/pp66.jsp, http://union.zhuna.cn/api/utf-8/, http://www.youlubg.com:81/Coop/request3.php, http://xuesenlin.w44.mc-test.com/.Recovered configuration
package
com.hotel
Identification
- SHA-256
- f01d9a2d49f49d28aaf222d7c5ba855648f46768a403808e652ee1d856c46076
- MD5
- 92a35477e104ab13dc3e6da4155a09e2
Observed
- Families
- Premium SMS Trojan (provisional)
- First seen
- 2010-07-31
C2 configuration (4)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| union.zhuna.cn/api/utf-8/ | domain | - | http | Premium SMS Trojan (provisional) | 2010-07-31 |
| www.youlubg.com/Coop/request3.php | domain | 81 | http | Premium SMS Trojan (provisional) | 2010-07-31 |
| xuesenlin.w44.mc-test.com/ | domain | - | http | Premium SMS Trojan (provisional) | 2010-07-31 |
| 211.136.165.53/wl/rmw1s/pp66.jsp | ip | - | http | Premium SMS Trojan (provisional) | 2010-07-31 |
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.