266b1c7134dae3c5f1b499c8…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Modobom WAP Fraud (provisional). Android WAP/toll-billing fraud tied to the Modobom ad-fraud operator. The app hides behind a game lure, requests SEND_SMS and CALL_PHONE, and pulls a silent premium-subscription config from an operator control backend (an auto_wap instruction feed on modobomco.com) that drives victims into paid WAP subscriptions. Landing pages are served from a rotating set of operator domains. Control/C2 hosts recovered as plaintext URLs in the dex; game-promo and app-store links used only as lures are not treated as indicators. Also covers the “Ender Inspector” variant (com.mi1hgr85yq.j5z43) whose Modobom SDK pulls tasking from apitoken.phoemobi.com and lperc.modobomco.com (shared infra across the cluster). Family label provisional. Indicators: http://apitoken.phoemobi.com/fuvi_4541341.php, http://lperc.modobomco.com/.

Recovered configuration

ad_network
Modobom (modobomco.com / modobomz.com / phoemobi.com)
app_label
Ender Inspector
package
com.mi1hgr85yq.j5z43

Identification

SHA-256
266b1c7134dae3c5f1b499c8b704a1c048cfcae4c10d99aa6660b3bb4a3b043e
MD5
b390cd68917eb59d495569dea941ef8a

Observed

Families
Modobom WAP Fraud (provisional)
First seen
2026-10-10

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
apitoken.phoemobi.com/fuvi_4541341.php domain - http Modobom WAP Fraud (provisional) 2026-10-10
lperc.modobomco.com/ domain - http Modobom WAP Fraud (provisional) 2026-10-10

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Modobom WAP Fraud (provisional)

Android WAP/toll-billing fraud tied to the Modobom ad-fraud operator. The app hides behind a game lure, requests SEND_SMS and CALL_PHONE, and pulls a silent premium-subscription config from an operator control backend (an auto_wap instruction feed on modobomco.com) that drives victims into paid WAP subscriptions. Landing pages are served from a rotating set of operator domains. Control/C2 hosts recovered as plaintext URLs in the dex; game-promo and app-store links used only as lures are not treated as indicators. Also covers the "Ender Inspector" variant (`com.mi1hgr85yq.j5z43`) whose Modobom SDK pulls tasking from `apitoken.phoemobi.com` and `lperc.modobomco.com` (shared infra across the cluster). Family label provisional.