32dc8100654e262ace5a6e2f…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
http://23.238.171.77/sms.Recovered configuration
Identification
- SHA-256
- 32dc8100654e262ace5a6e2fe5f716855d745827893e2060a48b4ec1b49a4547
- MD5
- 701f49d3bc1ef2f84ede1565d55b8488
Observed
- Families
- Korean Smishing SMS Stealer (provisional)
- First seen
- 2018-12-07
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 23.238.171.77/sms | ip | - | http | Korean Smishing SMS Stealer (provisional) | 2018-12-07 |
Signing certificate
- Subject CN
- Luka
- Issuer CN
- Luka
- Fingerprint
- c719ce2fe5228d71539f43042a8dffb178bca9332e4a92f37bd462b38cf85de8
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Korean Smishing SMS Stealer (provisional)
**Korean Smishing SMS Stealer (provisional)** is a Korean SMS-stealing/smishing Android RAT disguised as a mobile wedding invitation lure (package com.android.systemsetting). It intercepts and exfiltrates SMS and MMS and device data, registers a DeviceAdmin receiver, and can place calls and install or delete packages, using SMS/MMS receivers and background services to drive collection. Stolen data is posted to an http /sms endpoint (observed C2 23.238.171.77). Family label provisional.