610cc1ca02e343c745a768c6…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
https://mproxs.info.Identification
- SHA-256
- 610cc1ca02e343c745a768c6307a90575eefb9f53499c0e1e1a865338ddbeb79
- MD5
- 634a301aed633f85633262a5d0107a3d
Observed
- Families
- TaxiSpy RAT
- First seen
- 2026-02-23
APK metadata
Summary
- Type
- Android · APK
- Package
- ru.xt5irnt.fi34llgh
- Main activity
- -
- Internal version
- 302
- Displayed version
- 3.0.2
- Min SDK
- 24
- Target SDK
- 35
Signing certificate
- Valid from
- 2026-02-06 13:39:07
- Valid to
- 2053-06-24 13:39:07
- Serial
- 3d07bacdae9113bc
- Thumbprint
- 75e03bb34eb3be362eb62226519fe897dac18277
- Subject
- C:US, CN:Google Inc, L:Mountain View, O:Google Inc, ST:California, OU:Android
- Issuer
- C:US, CN:Google Inc, L:Mountain View, O:Google Inc, ST:California, OU:Android
Permissions (12)
Intent filters - actions
Intent filters - categories
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| mproxs.info | domain | - | https | TaxiSpy RAT | 2026-02-23 |
Signing certificate
- Subject CN
- Google Inc
- Issuer CN
- Google Inc
- Fingerprint
- e5e1a101b0d951d4114be8593fa42ff8d05eef1e2340c72914bd9ab67056ef57
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About TaxiSpy RAT
**TaxiSpy** is a Russian-nexus Android banking RAT that combines SMS theft, hidden VNC remote control and overlays to run on-device fraud. It intercepts and forwards incoming SMS (OTP and bank codes), gives the operator a live VNC view/control channel to drive the infected device directly, and beacons to its C2 at mproxs.info. Used against Russian-speaking targets.