f63166f41ac9919a463d3dac…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Modobom WAP Fraud (provisional). Android WAP/toll-billing fraud tied to the Modobom ad-fraud operator. The app hides behind a game lure, requests SEND_SMS and CALL_PHONE, and pulls a silent premium-subscription config from an operator control backend (an auto_wap instruction feed on modobomco.com) that drives victims into paid WAP subscriptions. Landing pages are served from a rotating set of operator domains. Control/C2 hosts recovered as plaintext URLs in the dex; game-promo and app-store links used only as lures are not treated as indicators. Family label provisional. Indicators: http://apitoken.modobomco.com, http://onesignal5.modobomco.com, http://lperc.modobomco.com, http://lpbigfun.thacyber.com, https://lpflavornest.mdb.guru, http://wap.lpalice2appsmart.com, http://sunny-mobi.com.

Recovered configuration

behavior
silent WAP premium subscription via SEND_SMS/CALL_PHONE
control
onesignal5.modobomco.com/ais/auto_wap_first_json.html
operator
Modobom
package
com.livelqe983.livelop011

Identification

SHA-256
f63166f41ac9919a463d3daca3e298c73ea1956423f3253e77785f40f7e61e51
MD5
9f083a7f870ec8ae8a2c73dcf1e3169b

Observed

Families
Modobom WAP Fraud (provisional)
First seen
2026-10-07

APK metadata

Summary

Type
Android · APK
Package
com.livelqe983.livelop011
Main activity
com.livelqe983.livelop011.MainActivity
Internal version
38
Displayed version
101.100.38
Min SDK
24
Target SDK
36

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com
Subject email
android@android.com
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:android@android.com

Permissions (8)

android.permission.ACCESS_NETWORK_STATEandroid.permission.CALL_PHONEandroid.permission.FOREGROUND_SERVICEandroid.permission.INTERNETandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.SEND_SMSandroid.permission.WAKE_LOCKcom.livelqe983.livelop011.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (2)

  • com.google.android.gms.common.api.GoogleApiActivity
  • com.livelqe983.livelop011.MainActivity

Services (3)

  • androidx.room.MultiInstanceInvalidationService
  • androidx.work.impl.background.systemjob.SystemJobService
  • androidx.work.impl.foreground.SystemForegroundService

Receivers (4)

  • androidx.profileinstaller.ProfileInstallReceiver
  • androidx.work.impl.background.systemalarm.RescheduleReceiver
  • androidx.work.impl.diagnostics.DiagnosticsReceiver
  • androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver

Providers (1)

  • androidx.startup.InitializationProvider

Intent filters - actions

android.intent.action.BOOT_COMPLETEDandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEandroidx.work.diagnostics.REQUEST_DIAGNOSTICS

C2 configuration (7)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
apitoken.modobomco.com domain - http Modobom WAP Fraud (provisional) 2026-10-07
lpbigfun.thacyber.com domain - http Modobom WAP Fraud (provisional) 2026-10-07
lperc.modobomco.com domain - http Modobom WAP Fraud (provisional) 2026-10-07
lpflavornest.mdb.guru domain - https Modobom WAP Fraud (provisional) 2026-10-07
onesignal5.modobomco.com domain - http Modobom WAP Fraud (provisional) 2026-10-07
sunny-mobi.com domain - http Modobom WAP Fraud (provisional) 2026-10-07
wap.lpalice2appsmart.com domain - http Modobom WAP Fraud (provisional) 2026-10-07

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Modobom WAP Fraud (provisional)

Android WAP/toll-billing fraud tied to the Modobom ad-fraud operator. The app hides behind a game lure, requests SEND_SMS and CALL_PHONE, and pulls a silent premium-subscription config from an operator control backend (an auto_wap instruction feed on modobomco.com) that drives victims into paid WAP subscriptions. Landing pages are served from a rotating set of operator domains. Control/C2 hosts recovered as plaintext URLs in the dex; game-promo and app-store links used only as lures are not treated as indicators. Family label provisional.