32dc8100654e262ace5a6e2f…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Korean Smishing SMS Stealer (provisional) - an Android SMS/OTP stealer, self-signed as “Luka”. Communicates with 1 operator endpoint. Korean SMS-stealing/smishing RAT disguised as a 모바일청첩장 (mobile wedding invitation) lure (package com.android.systemsetting, app label 모바일청첩장), same family as 4b1cd7a6. SMS/MMS interception, DeviceAdmin, call and package install/delete capabilities; background services HallelujahServ, PruServ, AuloriaServ, CosmoServ. Stolen data posted to the /sms endpoint. C2 http://23.238.171.77/sms per threat research. Family label provisional. Indicators: http://23.238.171.77/sms.

Recovered configuration

package
com.android.systemsetting
reference
amtracker

Identification

SHA-256
32dc8100654e262ace5a6e2fe5f716855d745827893e2060a48b4ec1b49a4547
MD5
701f49d3bc1ef2f84ede1565d55b8488

Observed

Families
Korean Smishing SMS Stealer (provisional)
First seen
2018-12-07

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
23.238.171.77/sms ip - http Korean Smishing SMS Stealer (provisional) 2018-12-07

Signing certificate

Subject CN
Luka
Issuer CN
Luka
Fingerprint
c719ce2fe5228d71539f43042a8dffb178bca9332e4a92f37bd462b38cf85de8

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.