4b1cd7a6718e39d3ac72a698…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Analyst notes

Korean Smishing SMS Stealer (provisional) - an Android SMS/OTP stealer, self-signed as “Luka”. Communicates with 1 operator endpoint. Korean SMS-stealing/smishing RAT disguised as a 모바일청첩장 (mobile wedding invitation) lure (package com.android.systemsetting, app label 모바일청첩장). Intercepts and exfiltrates SMS/MMS and device data, registers a DeviceAdmin receiver, and can place calls and install/delete packages. SMS/MMS receivers (SmsReceiver, MmsReceiver) and background services (CosmoServ, PruServ, AuloriaServ, HallelujahServ) drive collection; stolen data is posted to the /sms endpoint. C2 http://23.238.171.77/sms per threat research. Shares C2 with 32dc8100. Family label provisional. Indicators: http://23.238.171.77/sms.

Recovered configuration

package
com.android.systemsetting
reference
amtracker

Identification

SHA-256
4b1cd7a6718e39d3ac72a698533e201523fac524630aa0b90f2b33f3134cee1a
MD5
f0b4324d966bbf2c0beeacde02350caa

Observed

Families
Korean Smishing SMS Stealer (provisional)
First seen
2019-01-08

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
23.238.171.77/sms ip - http Korean Smishing SMS Stealer (provisional) 2019-01-08

Signing certificate

Subject CN
Luka
Issuer CN
Luka
Fingerprint
c719ce2fe5228d71539f43042a8dffb178bca9332e4a92f37bd462b38cf85de8

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.