4b1cd7a6718e39d3ac72a698…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Analyst notes
Korean Smishing SMS Stealer (provisional) - an Android SMS/OTP stealer, self-signed as “Luka”. Communicates with 1 operator endpoint. Korean SMS-stealing/smishing RAT disguised as a 모바일청첩장 (mobile wedding invitation) lure (package com.android.systemsetting, app label 모바일청첩장). Intercepts and exfiltrates SMS/MMS and device data, registers a DeviceAdmin receiver, and can place calls and install/delete packages. SMS/MMS receivers (SmsReceiver, MmsReceiver) and background services (CosmoServ, PruServ, AuloriaServ, HallelujahServ) drive collection; stolen data is posted to the /sms endpoint. C2 http://23.238.171.77/sms per threat research. Shares C2 with 32dc8100. Family label provisional. Indicators:
http://23.238.171.77/sms.Recovered configuration
package
com.android.systemsetting
reference
amtracker
Identification
- SHA-256
- 4b1cd7a6718e39d3ac72a698533e201523fac524630aa0b90f2b33f3134cee1a
- MD5
- f0b4324d966bbf2c0beeacde02350caa
Observed
- Families
- Korean Smishing SMS Stealer (provisional)
- First seen
- 2019-01-08
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 - each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 23.238.171.77/sms | ip | - | http | Korean Smishing SMS Stealer (provisional) | 2019-01-08 |
Signing certificate
- Subject CN
- Luka
- Issuer CN
- Luka
- Fingerprint
- c719ce2fe5228d71539f43042a8dffb178bca9332e4a92f37bd462b38cf85de8
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.