9354d54a1c6be37793148fb9…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

SMS Forwarder (provisional). A broad class of simple Android OTP/SMS stealers (packages like com.example.smsforwarder) that register a RECEIVE_SMS receiver and exfiltrate every incoming message - one-time passwords above all - to the operator. Two exfil channels are seen in the wild and both are recovered binary-only:

  • Telegram bot - the message is sent through the Telegram Bot API; the bot token(s) (<id>:<authstring>) and target chat_id are hardcoded, so api.telegram.org is the C2 and the bot token is the actionable IOC (report the bot, block the channel). A single build often carries more than one bot token (primary + fallback).

  • HTTP drop - the message is POSTed to a hardcoded endpoint, typically a bare IP with an /sms / ingest PHP handler.

Family label is provisional - these are commodity builders, not a single actor. Indicators: https://api.telegram.org, https://vip-panel-krish-developer.42web.io/.

Recovered configuration

exfil_channel
telegram-bot
operator_panel
https://vip-panel-krish-developer.42web.io/
telegram_bot_id
8691487788
telegram_bot_token
8691487788:AAHi1uxqFehipD7riUlFOdymQQC_Vsiylyk

Identification

SHA-256
9354d54a1c6be37793148fb9cd6df8626ccf0d8ae4301e27d4436b75950b8336
MD5
e2996885b7dbfb11fa1f2fb07756bdcd

Observed

Families
SMS Forwarder (provisional)
First seen
2026-08-17

APK metadata

Summary

Type
Android · APK
Package
com.example.smsforwarder
Main activity
-
Internal version
1
Displayed version
1.0
Min SDK
19
Target SDK
26

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
Subject email
[email protected]
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]

Permissions (9)

android.permission.FOREGROUND_SERVICEandroid.permission.INTERNETandroid.permission.POST_NOTIFICATIONSandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.RECEIVE_SMSandroid.permission.SEND_SMSandroid.permission.WAKE_LOCK

Activities (1)

  • com.example.smsforwarder.MainActivity

Services (1)

  • com.example.smsforwarder.ForegroundService

Receivers (4)

  • com.example.smsforwarder.AutoRestartReceiver
  • com.example.smsforwarder.BootReceiver
  • com.example.smsforwarder.KeepAliveReceiver
  • com.example.smsforwarder.SMSReceiver

Intent filters - actions

android.intent.action.BOOT_COMPLETEDandroid.intent.action.MY_PACKAGE_REPLACEDandroid.provider.Telephony.SMS_RECEIVED

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
api.telegram.org domain - https SMS Forwarder (provisional) 2026-08-17
vip-panel-krish-developer.42web.io/ domain - https SMS Forwarder (provisional) 2026-08-17

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About SMS Forwarder (provisional)

A broad class of simple **Android OTP/SMS stealers** (packages like `com.example.smsforwarder`) that register a `RECEIVE_SMS` receiver and exfiltrate every incoming message - one-time passwords above all - to the operator. Two exfil channels are seen in the wild and both are recovered binary-only: - **Telegram bot** - the message is sent through the Telegram Bot API; the bot token(s) (`<id>:<authstring>`) and target `chat_id` are hardcoded, so `api.telegram.org` is the C2 and the **bot token is the actionable IOC** (report the bot, block the channel). A single build often carries more than one bot token (primary + fallback). - **HTTP drop** - the message is POSTed to a hardcoded endpoint, typically a bare IP with an `/sms` / `ingest` PHP handler. Family label is provisional - these are commodity builders, not a single actor.