fb66986e1104d1c47ee7be04…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Malaysian FPX Bank Phish (provisional). Malaysia-targeted banking-scam cluster (NetbyteSec, 2022) built on a SoloDroid eCommerce app template and distributed through fake lure apps — Maid4u, KleanHouz, MyPetronas, cleaning-service and island-travel apps (packages com.app.homecleaning, com.app.islandtravel, …). The APK loads a fake FPX bank-selection page (assets/FPX.html, or assets/bank.html with per-bank asset folders in sibling builds that target AU/US banks) in a WebView; entered online-banking credentials are POSTed by assets/post.js to an attacker PHP endpoint (/post.php), card data by a ccsend script, and order / victim info to the SoloDroid backend (//api/api.php). A static SMS receiver (MyReciever) forwards incoming SMS to a separate C2 host as GET query parameters. Observed C2 roles: credential exfil (e.g. e12345.online, gpost996.online /post.php), order API (lapks.online) and SMS exfil (sgbx.online); hosts rotate across builds and are recovered from those sinks. Provisional bucket pending formal attribution. Indicators: e12345.online, lapks.online, sgbx.online.

Recovered configuration

kit
SoloDroid eCommerce + fake FPX WebView
package
com.app.homecleaning

Identification

SHA-256
fb66986e1104d1c47ee7be04567e8eec0c19042e3d06941429b5e20bcab00733
MD5
b32fc1337dd914cedbb17e52e0d1cca2

Observed

Families
Malaysian FPX Bank Phish (provisional)
First seen
2022-09-06

C2 configuration (3)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
e12345.online domain - - Malaysian FPX Bank Phish (provisional) 2022-09-06
lapks.online domain - - Malaysian FPX Bank Phish (provisional) 2022-09-06
sgbx.online domain - - Malaysian FPX Bank Phish (provisional) 2022-09-06

Signing certificate

Subject CN
-
Issuer CN
-
Fingerprint
022a1ed9feb0e6c9826df99c58350b7789a71ad51f142f40449f91d58c0278c1

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Malaysian FPX Bank Phish (provisional)

Malaysia-targeted banking-scam cluster (NetbyteSec, 2022) built on a SoloDroid eCommerce app template and distributed through fake lure apps — Maid4u, KleanHouz, MyPetronas, cleaning-service and island-travel apps (packages com.app.homecleaning, com.app.islandtravel, …). The APK loads a fake FPX bank-selection page (assets/FPX.html, or assets/bank.html with per-bank asset folders in sibling builds that target AU/US banks) in a WebView; entered online-banking credentials are POSTed by assets/post.js to an attacker PHP endpoint (/post.php), card data by a ccsend script, and order / victim info to the SoloDroid backend (/<agent>/api/api.php). A static SMS receiver (MyReciever) forwards incoming SMS to a separate C2 host as GET query parameters. Observed C2 roles: credential exfil (e.g. e12345.online, gpost996.online /post.php), order API (lapks.online) and SMS exfil (sgbx.online); hosts rotate across builds and are recovered from those sinks. Provisional bucket pending formal attribution.