4b1cd7a6718e39d3ac72a698…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
http://23.238.171.77/sms.Recovered configuration
Identification
- SHA-256
- 4b1cd7a6718e39d3ac72a698533e201523fac524630aa0b90f2b33f3134cee1a
- MD5
- f0b4324d966bbf2c0beeacde02350caa
Observed
- Families
- Korean Smishing SMS Stealer (provisional)
- First seen
- 2019-01-08
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 23.238.171.77/sms | ip | - | http | Korean Smishing SMS Stealer (provisional) | 2019-01-08 |
Signing certificate
- Subject CN
- Luka
- Issuer CN
- Luka
- Fingerprint
- c719ce2fe5228d71539f43042a8dffb178bca9332e4a92f37bd462b38cf85de8
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Korean Smishing SMS Stealer (provisional)
**Korean Smishing SMS Stealer (provisional)** is a Korean SMS-stealing/smishing Android RAT disguised as a mobile wedding invitation lure (package com.android.systemsetting). It intercepts and exfiltrates SMS and MMS and device data, registers a DeviceAdmin receiver, and can place calls and install or delete packages, using SMS/MMS receivers and background services to drive collection. Stolen data is posted to an http /sms endpoint (observed C2 23.238.171.77). Family label provisional.