115.23.172.67/sms_admin/
ipTracked by C2 Tracker · Whois queried 2026-10-04T14:35:07
Network
- Network
- KORNET-KR
- CIDR
- 115.16.0.0/13
- Country
- KR
Contact
- Handle
- 115.16.0.0 - 115.23.255.255
- Abuse
- [email protected], [email protected]
Observed in malware
| Family | Sample SHA-256 | First seen |
|---|---|---|
| SK TelecomFraud | 6d7cc07bae72… | 2015-05-05 |
| SK TelecomFraud | 0eef59d4a6e6… | 2015-10-28 |
| SK TelecomFraud | 20c159ee7b90… | 2015-12-21 |
About SK TelecomFraud
SMS-intercepting spyware used by telecom-fraud rings against South Korean victims, distributed disguised as insurance or government apps (observed package com.android.csi, "China Social Insurance"). Intercepts and forwards incoming SMS - the enabler for voice-phishing and number-porting fraud - and even runs an embedded FTP server on the device. Its C2 URL is Base64-encoded five times.
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Valid
- 2014-10-15 → 2044-10-07
- Fingerprint
- 854ffef7227746ad8bef73810950962db7a0ab90806aaf17715028691ae37962
Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.