23.238.171.77/sms

ip C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-10T07:44:41

Network

Network
AMAZO-4
CIDR
23.238.128.0/17
Country
US

Contact

Handle
NET-23-238-128-0-1
Abuse
-

Observed in malware

FamilySample SHA-256RoleFirst seen
Korean Smishing SMS Stealer (provisional) 32dc8100654e… C2 2018-12-07
Korean Smishing SMS Stealer (provisional) 4b1cd7a6718e… C2 2019-01-08

About Korean Smishing SMS Stealer (provisional)

**Korean Smishing SMS Stealer (provisional)** is a Korean SMS-stealing/smishing Android RAT disguised as a mobile wedding invitation lure (package com.android.systemsetting). It intercepts and exfiltrates SMS and MMS and device data, registers a DeviceAdmin receiver, and can place calls and install or delete packages, using SMS/MMS receivers and background services to drive collection. Stolen data is posted to an http /sms endpoint (observed C2 23.238.171.77). Family label provisional.

Signing certificate

Subject CN
Luka
Issuer CN
Luka
Valid
2017-12-16 → 2042-12-10
Fingerprint
c719ce2fe5228d71539f43042a8dffb178bca9332e4a92f37bd462b38cf85de8

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.