29f84d309560240341443336…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
29f84d30956024034144333644d7a2023004af7e6f5acea3f21b03cf52ff0745
MD5
f507efa84ac63a356491455681a74272

Observed

Families
SK TelecomFraud
First seen
2016-01-03

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
58.64.187.126/sms_admin/ ip 8087 http SK TelecomFraud 2016-01-03

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Fingerprint
5471db1ca710f51f9ad359e987b4c4ec27cf7dc8bd0bdf478c6e38e1525dd952

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About SK TelecomFraud

SMS-intercepting spyware used by telecom-fraud rings against South Korean victims, distributed disguised as insurance or government apps (observed package com.android.csi, "China Social Insurance"). Intercepts and forwards incoming SMS - the enabler for voice-phishing and number-porting fraud - and even runs an embedded FTP server on the device. Its C2 URL is Base64-encoded five times.