23.238.171.77/sms
ip C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-10T07:44:41
Network
- Network
- AMAZO-4
- CIDR
- 23.238.128.0/17
- Country
- US
Contact
- Handle
- NET-23-238-128-0-1
- Abuse
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Korean Smishing SMS Stealer (provisional) | 32dc8100654e… | C2 | 2018-12-07 |
| Korean Smishing SMS Stealer (provisional) | 4b1cd7a6718e… | C2 | 2019-01-08 |
About Korean Smishing SMS Stealer (provisional)
**Korean Smishing SMS Stealer (provisional)** is a Korean SMS-stealing/smishing Android RAT disguised as a mobile wedding invitation lure (package com.android.systemsetting). It intercepts and exfiltrates SMS and MMS and device data, registers a DeviceAdmin receiver, and can place calls and install or delete packages, using SMS/MMS receivers and background services to drive collection. Stolen data is posted to an http /sms endpoint (observed C2 23.238.171.77). Family label provisional.
Signing certificate
- Subject CN
- Luka
- Issuer CN
- Luka
- Valid
- 2017-12-16 → 2042-12-10
- Fingerprint
- c719ce2fe5228d71539f43042a8dffb178bca9332e4a92f37bd462b38cf85de8
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.