6574568551:aafexxr1s497ipononinff0pteqgyqeulby@6070996097
domain C2Tracked by C2 Tracker · Whois queried never
Registration
- Registrar
- -
- Registered
- -
- Expires
- -
DNS
- Resolves to
- -
- Nameservers
- -
- Status
- -
Observed in malware
| Family | Sample SHA-256 | Role | First seen |
|---|---|---|---|
| Kahwin SMS Stealer (provisional) | 22b710341e53… | C2 | 2023-08-11 |
About Kahwin SMS Stealer (provisional)
Wedding-invitation SMS stealer targeting Malaysia (NetbyteSec, June 2023). Distributed over WhatsApp as a fake digital wedding invite ("Kad Digital Kahwin.apk", "Jemputan-Majlis-Perkahwinan.apk"; app label "Kad Kahwin Digital" / "Undangan Pernikahan"), often throwaway packages such as com.example.myapplication or com.google.*. A ReceiveSMS handler intercepts incoming SMS and forwards the sender, body and device info to a hardcoded Telegram bot via api.telegram.org; a WebView shows a real wedding-invite page (e.g. ejemputan.com, our-wedding.link) as cover. The actionable IOC is the Telegram bot token (recorded as token@chat_id), recovered from the api.telegram.org sink. The invite labels use Indonesian phrasing ("Undangan Pernikahan"); that is lure localization and not by itself an attribution of the operator. Distinct from the generic commodity SMS-forwarder bucket by the consistent wedding-invitation lure. Provisional bucket pending attribution.
Signing certificate
- Subject CN
- Android
- Issuer CN
- Android
- Valid
- 2008-02-29 → 2035-07-17
- Fingerprint
- a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Other samples signed with this certificate? That's a lead worth checking - but not proof of a shared operator, since signing keys (and the Android debug certificate in particular) are widely reused. See the certificate page for every sample signed with it.