58.64.187.126:8087/sms_admin/
ipTracked by C2 Tracker · Whois queried 2026-10-04T14:35:07
Network
- Network
- NWTiDC-HK
- CIDR
- 58.64.187.0/24
- Country
- HK
Contact
- Handle
- 58.64.187.0 - 58.64.187.255
- Abuse
- [email protected], [email protected]
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| SK TelecomFraud | 29f84d309560… | 2016-01-03 |
About SK TelecomFraud
SMS-intercepting spyware used by telecom-fraud rings against South Korean victims, distributed disguised as insurance or government apps (observed package com.android.csi, "China Social Insurance"). Intercepts and forwards incoming SMS - the enabler for voice-phishing and number-porting fraud - and even runs an embedded FTP server on the device. Its C2 URL is Base64-encoded five times.
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Valid
- 2014-10-14 → 2044-10-06
- Fingerprint
- 5471db1ca710f51f9ad359e987b4c4ec27cf7dc8bd0bdf478c6e38e1525dd952
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.