001ba8384c75f9f27e1a8316…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Korean Spyware (provisional) - Android spyware, self-signed as “ouah08”. Communicates with 2 operator endpoints. Korean Android surveillance spyware (package com.ouah08.ouah_08_17_n, 2014). Harvests GPS/assisted-GPS location, SMS (SEND_SMS), call/phone state (CALL_PHONE, READ_PHONE_STATE) and accounts (GET_ACCOUNTS) and reports to the operator over HTTP. Statically recovered cleartext C2 endpoints: cocoam.co.kr (/api/, /mobile/) and testcocoa.com (/api/, /mobile/). Family label provisional. Indicators: http://cocoam.co.kr/api/, http://testcocoa.com/api/.

Recovered configuration

package
com.ouah08.ouah_08_17_n

Identification

SHA-256
001ba8384c75f9f27e1a831621f61a0e84492958d4c1ce885feab812ab824bbb
MD5
42dcd600444dda18185b86e66544afe8

Observed

Families
Korean Spyware (provisional)
First seen
2014-06-12

C2 configuration (2)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
cocoam.co.kr/api/ domain - http Korean Spyware (provisional) 2014-06-12
testcocoa.com/api/ domain - http Korean Spyware (provisional) 2014-06-12

Signing certificate

Subject CN
-
Issuer CN
-
Fingerprint
419332188121a5d656e7639d8a01b47f7a1343178d86894729265515d5b466f4

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.