29f84d309560240341443336…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- 29f84d30956024034144333644d7a2023004af7e6f5acea3f21b03cf52ff0745
- MD5
- f507efa84ac63a356491455681a74272
Observed
- Families
- SK TelecomFraud
- First seen
- 2016-01-03
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 58.64.187.126/sms_admin/ | ip | 8087 | http | SK TelecomFraud | 2016-01-03 |
Signing certificate
- Subject CN
- Android Debug
- Issuer CN
- Android Debug
- Fingerprint
- 5471db1ca710f51f9ad359e987b4c4ec27cf7dc8bd0bdf478c6e38e1525dd952
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About SK TelecomFraud
SMS-intercepting spyware used by telecom-fraud rings against South Korean victims, distributed disguised as insurance or government apps (observed package com.android.csi, "China Social Insurance"). Intercepts and forwards incoming SMS - the enabler for voice-phishing and number-porting fraud - and even runs an embedded FTP server on the device. Its C2 URL is Base64-encoded five times.