115.23.172.67/sms_admin/

ip not resolving

Tracked by C2 Tracker · Whois queried 2026-10-04T14:35:07

Network

Network
KORNET-KR
CIDR
115.16.0.0/13
Country
KR

Contact

Handle
115.16.0.0 - 115.23.255.255
Abuse
[email protected], [email protected]

Observed in malware

FamilySample SHA-256First seen
SK TelecomFraud 6d7cc07bae72… 2015-05-05
SK TelecomFraud 0eef59d4a6e6… 2015-10-28
SK TelecomFraud 20c159ee7b90… 2015-12-21

About SK TelecomFraud

SMS-intercepting spyware used by telecom-fraud rings against South Korean victims, distributed disguised as insurance or government apps (observed package com.android.csi, "China Social Insurance"). Intercepts and forwards incoming SMS - the enabler for voice-phishing and number-porting fraud - and even runs an embedded FTP server on the device. Its C2 URL is Base64-encoded five times.

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Valid
2014-10-15 → 2044-10-07
Fingerprint
854ffef7227746ad8bef73810950962db7a0ab90806aaf17715028691ae37962

Other samples signed with this certificate? That's a lead worth checking — but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.