798d24d677103dc303540c71…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Malaysian FPX Bank Phish (provisional). Malaysia-targeted banking-scam cluster (NetbyteSec, 2022) built on a SoloDroid eCommerce app template and distributed through fake lure apps — Maid4u, KleanHouz, MyPetronas, cleaning-service and island-travel apps (packages com.app.homecleaning, com.app.islandtravel, …). The APK loads a fake FPX bank-selection page (assets/FPX.html, or assets/bank.html with per-bank asset folders in sibling builds that target AU/US banks) in a WebView; entered online-banking credentials are POSTed by assets/post.js to an attacker PHP endpoint (/post.php), card data by a ccsend script, and order / victim info to the SoloDroid backend (//api/api.php). A static SMS receiver (MyReciever) forwards incoming SMS to a separate C2 host as GET query parameters. Observed C2 roles: credential exfil (e.g. e12345.online, gpost996.online /post.php), order API (lapks.online) and SMS exfil (sgbx.online); hosts rotate across builds and are recovered from those sinks. Provisional bucket pending formal attribution. Indicators: e12345.online, gpost996.online, lapks.online, sgbx.online.

Recovered configuration

kit
SoloDroid eCommerce + fake FPX WebView
package
com.app.homecleaning

Identification

SHA-256
798d24d677103dc303540c71b87f6a993e3006202cbdba0636acf90ffdd15b93
MD5
5baf24067fe0b752ebd78c9a38344488

Observed

Families
Malaysian FPX Bank Phish (provisional)
First seen
2022-09-11

C2 configuration (4)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
e12345.online domain - - Malaysian FPX Bank Phish (provisional) 2022-09-11
gpost996.online domain - - Malaysian FPX Bank Phish (provisional) 2022-09-11
lapks.online domain - - Malaysian FPX Bank Phish (provisional) 2022-09-11
sgbx.online domain - - Malaysian FPX Bank Phish (provisional) 2022-09-11

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Fingerprint
b11e2d296bd2de2dea90d1e1ac99a32b721713a717d1409cfd5c7f3dc04ab0ea

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Malaysian FPX Bank Phish (provisional)

Malaysia-targeted banking-scam cluster (NetbyteSec, 2022) built on a SoloDroid eCommerce app template and distributed through fake lure apps — Maid4u, KleanHouz, MyPetronas, cleaning-service and island-travel apps (packages com.app.homecleaning, com.app.islandtravel, …). The APK loads a fake FPX bank-selection page (assets/FPX.html, or assets/bank.html with per-bank asset folders in sibling builds that target AU/US banks) in a WebView; entered online-banking credentials are POSTed by assets/post.js to an attacker PHP endpoint (/post.php), card data by a ccsend script, and order / victim info to the SoloDroid backend (/<agent>/api/api.php). A static SMS receiver (MyReciever) forwards incoming SMS to a separate C2 host as GET query parameters. Observed C2 roles: credential exfil (e.g. e12345.online, gpost996.online /post.php), order API (lapks.online) and SMS exfil (sgbx.online); hosts rotate across builds and are recovered from those sinks. Provisional bucket pending formal attribution.