158.247.219.34/sms/sms_ingest.php

ip C2 not resolving

Tracked by C2 Tracker · Updated as of 2026-10-11 · Whois queried 2026-10-07T08:18:26

Network

Network
CONSTANT-AP
CIDR
158.247.192.0/18
Country
JP

Contact

Handle
158.247.192.0 - 158.247.255.255
Abuse
[email protected], [email protected]

Observed in malware

FamilySample SHA-256RoleFirst seen
SMS Forwarder (provisional) b920ac40a219… C2 2026-09-27

About SMS Forwarder (provisional)

A broad class of simple **Android OTP/SMS stealers** (packages like `com.example.smsforwarder`) that register a `RECEIVE_SMS` receiver and exfiltrate every incoming message - one-time passwords above all - to the operator. Two exfil channels are seen in the wild and both are recovered binary-only: - **Telegram bot** - the message is sent through the Telegram Bot API; the bot token(s) (`<id>:<authstring>`) and target `chat_id` are hardcoded, so `api.telegram.org` is the C2 and the **bot token is the actionable IOC** (report the bot, block the channel). A single build often carries more than one bot token (primary + fallback). - **HTTP drop** - the message is POSTed to a hardcoded endpoint, typically a bare IP with an `/sms` / `ingest` PHP handler. Family label is provisional - these are commodity builders, not a single actor.

Signing certificate

Subject CN
SMS Forward Local
Issuer CN
SMS Forward Local
Valid
2026-07-29 → 2053-12-14
Fingerprint
f193ce635f06f485a84f5980252639879e87d761dfb95ce0289620972c224fb0

Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.