158.247.219.34/sms/sms_ingest.php
ip C2Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:26
Network
- Network
- CONSTANT-AP
- CIDR
- 158.247.192.0/18
- Country
- JP
Contact
- Handle
- 158.247.192.0 - 158.247.255.255
- Abuse
- [email protected], [email protected]
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| SMS Forwarder (provisional) | b920ac40a219… | C2 | 2026-09-27 |
About SMS Forwarder (provisional)
A broad class of simple **Android OTP/SMS stealers** (packages like `com.example.smsforwarder`) that register a `RECEIVE_SMS` receiver and exfiltrate every incoming message - one-time passwords above all - to the operator. Two exfil channels are seen in the wild and both are recovered binary-only: - **Telegram bot** - the message is sent through the Telegram Bot API; the bot token(s) (`<id>:<authstring>`) and target `chat_id` are hardcoded, so `api.telegram.org` is the C2 and the **bot token is the actionable IOC** (report the bot, block the channel). A single build often carries more than one bot token (primary + fallback). - **HTTP drop** - the message is POSTed to a hardcoded endpoint, typically a bare IP with an `/sms` / `ingest` PHP handler. Family label is provisional - these are commodity builders, not a single actor.
Signing certificate
- Subject CN
- SMS Forward Local
- Issuer CN
- SMS Forward Local
- Valid
- 2026-07-29 → 2053-12-14
- Fingerprint
- f193ce635f06f485a84f5980252639879e87d761dfb95ce0289620972c224fb0
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.