6d7cc07bae72aeeb4a6a7e28…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
6d7cc07bae72aeeb4a6a7e284e36dd3c832919f0de04524719ef549822dd49e1
MD5
00314e01f12e65f355b004b9ffb6c2db

Observed

Families
SK TelecomFraud
First seen
2015-05-05

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
115.23.172.67/sms_admin/ ip — http SK TelecomFraud 2015-05-05

Signing certificate

Subject CN
Android Debug
Issuer CN
Android Debug
Fingerprint
854ffef7227746ad8bef73810950962db7a0ab90806aaf17715028691ae37962

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About SK TelecomFraud

SMS-intercepting spyware used by telecom-fraud rings against South Korean victims, distributed disguised as insurance or government apps (observed package com.android.csi, "China Social Insurance"). Intercepts and forwards incoming SMS - the enabler for voice-phishing and number-porting fraud - and even runs an embedded FTP server on the device. Its C2 URL is Base64-encoded five times.