f63166f41ac9919a463d3dac…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Modobom WAP Fraud (provisional). Android WAP/toll-billing fraud tied to the Modobom ad-fraud operator. The app hides behind a game lure, requests SEND_SMS and CALL_PHONE, and pulls a silent premium-subscription config from an operator control backend (an auto_wap instruction feed on modobomco.com) that drives victims into paid WAP subscriptions. Landing pages are served from a rotating set of operator domains. Control/C2 hosts recovered as plaintext URLs in the dex; game-promo and app-store links used only as lures are not treated as indicators. Also covers the “Ender Inspector” variant (com.mi1hgr85yq.j5z43) whose Modobom SDK pulls tasking from apitoken.phoemobi.com and lperc.modobomco.com (shared infra across the cluster). Family label provisional. Indicators: http://apitoken.modobomco.com, http://onesignal5.modobomco.com, http://lperc.modobomco.com, http://lpbigfun.thacyber.com, https://lpflavornest.mdb.guru, http://wap.lpalice2appsmart.com, http://sunny-mobi.com.

Recovered configuration

behavior
silent WAP premium subscription via SEND_SMS/CALL_PHONE
control
onesignal5.modobomco.com/ais/auto_wap_first_json.html
operator
Modobom
package
com.livelqe983.livelop011

Identification

SHA-256
f63166f41ac9919a463d3daca3e298c73ea1956423f3253e77785f40f7e61e51
MD5
9f083a7f870ec8ae8a2c73dcf1e3169b

Observed

Families
Modobom WAP Fraud (provisional)
First seen
2026-10-07

APK metadata

Summary

Type
Android · APK
Package
com.livelqe983.livelop011
Main activity
com.livelqe983.livelop011.MainActivity
Internal version
38
Displayed version
101.100.38
Min SDK
24
Target SDK
36

Signing certificate

Valid from
2008-02-29 01:33:46
Valid to
2035-07-17 01:33:46
Serial
936eacbe07f201df
Thumbprint
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
Subject
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]
Subject email
[email protected]
Issuer
C:US, CN:Android, L:Mountain View, O:Android, ST:California, OU:Android, email:[email protected]

Permissions (8)

android.permission.ACCESS_NETWORK_STATEandroid.permission.CALL_PHONEandroid.permission.FOREGROUND_SERVICEandroid.permission.INTERNETandroid.permission.RECEIVE_BOOT_COMPLETEDandroid.permission.SEND_SMSandroid.permission.WAKE_LOCKcom.livelqe983.livelop011.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Activities (2)

  • com.google.android.gms.common.api.GoogleApiActivity
  • com.livelqe983.livelop011.MainActivity

Services (3)

  • androidx.room.MultiInstanceInvalidationService
  • androidx.work.impl.background.systemjob.SystemJobService
  • androidx.work.impl.foreground.SystemForegroundService

Receivers (4)

  • androidx.profileinstaller.ProfileInstallReceiver
  • androidx.work.impl.background.systemalarm.RescheduleReceiver
  • androidx.work.impl.diagnostics.DiagnosticsReceiver
  • androidx.work.impl.utils.ForceStopRunnable$BroadcastReceiver

Providers (1)

  • androidx.startup.InitializationProvider

Intent filters - actions

android.intent.action.BOOT_COMPLETEDandroidx.profileinstaller.action.BENCHMARK_OPERATIONandroidx.profileinstaller.action.INSTALL_PROFILEandroidx.profileinstaller.action.SAVE_PROFILEandroidx.profileinstaller.action.SKIP_FILEandroidx.work.diagnostics.REQUEST_DIAGNOSTICS

C2 configuration (7)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

Signing certificate

Subject CN
Android
Issuer CN
Android
Fingerprint
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About Modobom WAP Fraud (provisional)

Android WAP/toll-billing fraud tied to the Modobom ad-fraud operator. The app hides behind a game lure, requests SEND_SMS and CALL_PHONE, and pulls a silent premium-subscription config from an operator control backend (an auto_wap instruction feed on modobomco.com) that drives victims into paid WAP subscriptions. Landing pages are served from a rotating set of operator domains. Control/C2 hosts recovered as plaintext URLs in the dex; game-promo and app-store links used only as lures are not treated as indicators. Also covers the "Ender Inspector" variant (`com.mi1hgr85yq.j5z43`) whose Modobom SDK pulls tasking from `apitoken.phoemobi.com` and `lperc.modobomco.com` (shared infra across the cluster). Family label provisional.