Analysis

  • max time kernel
    143s
  • max time network
    148s
  • platform
    android_x86
  • resource
    android-x86-arm-20231215-en
  • resource tags

    androidarch:armarch:x86image:android-x86-arm-20231215-enlocale:en-usos:android-9-x86system
  • submitted
    25-01-2024 09:52

General

  • Target

    7462d3be5f649b52794ca5a1f1d201f1.apk

  • Size

    4.7MB

  • MD5

    7462d3be5f649b52794ca5a1f1d201f1

  • SHA1

    2120f85722f2ad7ea1bec4d779ca738de28af9c6

  • SHA256

    8fff451a8088ec7b89800fc743d43034a6531304429309beb073f888813ee16f

  • SHA512

    77bdfdcd7db1617f94f1cfa041c895a19e1a4683b14252c2b4c22a60b87009a6aaf3c94e52f32f68d684c7b9608a4952418b14ce9b2b94db5a8e4d2e7e565f9e

  • SSDEEP

    98304:DPDrwLnOoQqcwP91K8CTn2cil3MhlkGKfSJsg5CDX3po4dN4feL8I:fr6OoQ7c91Fw6lcbhJh5enpo4dN4feF

Malware Config

Signatures

  • 888RAT

    888RAT is an Android remote administration tool.

  • Removes its main activity from the application launcher 1 IoCs
  • Acquires the wake lock 1 IoCs
  • Requests dangerous framework permissions 3 IoCs

Processes

  • com.example.dat.a8andoserverx
    1⤵
    • Removes its main activity from the application launcher
    • Acquires the wake lock
    PID:4190

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • /storage/emulated/0/.app.apk
    Filesize

    115KB

    MD5

    399f9fb73cd061dffe8af527323bd1bc

    SHA1

    7fe099679808fea3bc96dd262444a0d7fd19c810

    SHA256

    db40f841bd34d18308027779e0ec625a60fab71f81c87c3acb0b4e2aa084a0f8

    SHA512

    79cc6b6d26c4f071e233ca93651ea8f12e68702ad227923d5f791c94120f6f424a836921b36cfa983cd5362611087404490cee327e241816207719322ad1c80e