32dc8100654e262ace5a6e2f…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
Korean Smishing SMS Stealer (provisional) - an Android SMS/OTP stealer, self-signed as “Luka”. Communicates with 1 operator endpoint. Korean SMS-stealing/smishing RAT disguised as a 모바일청첩장 (mobile wedding invitation) lure (package com.android.systemsetting, app label 모바일청첩장), same family as 4b1cd7a6. SMS/MMS interception, DeviceAdmin, call and package install/delete capabilities; background services HallelujahServ, PruServ, AuloriaServ, CosmoServ. Stolen data posted to the /sms endpoint. C2 http://23.238.171.77/sms per threat research. Family label provisional. Indicators:
http://23.238.171.77/sms.Recovered configuration
package
com.android.systemsetting
reference
amtracker
Identification
- SHA-256
- 32dc8100654e262ace5a6e2fe5f716855d745827893e2060a48b4ec1b49a4547
- MD5
- 701f49d3bc1ef2f84ede1565d55b8488
Observed
- Families
- Korean Smishing SMS Stealer (provisional)
- First seen
- 2018-12-07
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 23.238.171.77/sms | ip | - | http | Korean Smishing SMS Stealer (provisional) | 2018-12-07 |
Signing certificate
- Subject CN
- Luka
- Issuer CN
- Luka
- Fingerprint
- c719ce2fe5228d71539f43042a8dffb178bca9332e4a92f37bd462b38cf85de8
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.