efa8679360e96bd659ecb6ea…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
com.ouah08.ouah_08_17[_n], main activity user_info) that harvests GPS/assisted-GPS location, SMS, call and phone state, and account data, uploading it via api.send_post (HttpURLConnection) to http://cocoam.co.kr/api/ and files via cm.HttpFileUpload to /mobile/, with commands delivered over Google Cloud Messaging. The live C2 is selected in cm.onCreate by comparing build resource 0x7f040000 (baked value real) against an obfuscated constant that also decodes to real, so the shipped build uses cocoam.co.kr; the testcocoa.com endpoint is a test fallback that is runtime-overridden and not reached. The name reflects infrastructure and apparent victim focus only - the live C2 is hosted on a South Korean .co.kr domain and the samples appear aimed at Korean users - and is NOT an attribution of authorship or origin; the operator is unknown. Samples observed 2014-2017. Distinct from the com.map.call SMS-interception family, which the tracker classifies separately as WhiteBroad. Indicators: http://cocoam.co.kr/api/.Recovered configuration
Identification
- SHA-256
- efa8679360e96bd659ecb6ea6d6b38e16dbc7073decf9228a7d6d28dfaf60094
- MD5
- c818b9470e3216c41a2f11573452ca26
Observed
- Families
- Korea-Hosted Spyware (provisional)
- First seen
- 2017-05-28
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| cocoam.co.kr/api/ | domain | - | http | Korea-Hosted Spyware (provisional) | 2017-05-28 |
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About Korea-Hosted Spyware (provisional)
**Korea-Hosted Spyware (provisional)** is an Android surveillance tool (package `com.ouah08.ouah_08_17[_n]`, main activity `user_info`) that harvests GPS/assisted-GPS location, SMS, call and phone state, and account data, uploading it via `api.send_post` (HttpURLConnection) to `http://cocoam.co.kr/api/` and files via `cm.HttpFileUpload` to `/mobile/`, with commands delivered over Google Cloud Messaging. The live C2 is selected in `cm.onCreate` by comparing build resource 0x7f040000 (baked value `real`) against an obfuscated constant that also decodes to `real`, so the shipped build uses cocoam.co.kr; the `testcocoa.com` endpoint is a test fallback that is runtime-overridden and not reached. The name reflects infrastructure and apparent victim focus only - the live C2 is hosted on a South Korean `.co.kr` domain and the samples appear aimed at Korean users - and is NOT an attribution of authorship or origin; the operator is unknown. Samples observed 2014-2017. Distinct from the com.map.call SMS-interception family, which the tracker classifies separately as WhiteBroad.