Analysis

  • max time kernel
    144s
  • max time network
    150s
  • platform
    android_x64
  • resource
    android-x64-20231215-en
  • resource tags

    androidarch:x64arch:x86image:android-x64-20231215-enlocale:en-usos:android-10-x64system
  • submitted
    25-01-2024 09:52

General

  • Target

    7462d3be5f649b52794ca5a1f1d201f1.apk

  • Size

    4.7MB

  • MD5

    7462d3be5f649b52794ca5a1f1d201f1

  • SHA1

    2120f85722f2ad7ea1bec4d779ca738de28af9c6

  • SHA256

    8fff451a8088ec7b89800fc743d43034a6531304429309beb073f888813ee16f

  • SHA512

    77bdfdcd7db1617f94f1cfa041c895a19e1a4683b14252c2b4c22a60b87009a6aaf3c94e52f32f68d684c7b9608a4952418b14ce9b2b94db5a8e4d2e7e565f9e

  • SSDEEP

    98304:DPDrwLnOoQqcwP91K8CTn2cil3MhlkGKfSJsg5CDX3po4dN4feL8I:fr6OoQ7c91Fw6lcbhJh5enpo4dN4feF

Malware Config

Signatures

  • 888RAT

    888RAT is an Android remote administration tool.

  • Removes its main activity from the application launcher 1 IoCs
  • Acquires the wake lock 1 IoCs
  • Requests dangerous framework permissions 3 IoCs

Processes

  • com.example.dat.a8andoserverx
    1⤵
    • Removes its main activity from the application launcher
    • Acquires the wake lock
    PID:4956

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • /storage/emulated/0/.app.apk
    Filesize

    637KB

    MD5

    d78e82604487e2fb8e6961e090ffee91

    SHA1

    2d0228d16f8d5897a25bcd0c1ed33fb5a518e74f

    SHA256

    dbd578c476d71600c46ca20a5078b5f69b8f36f04e21fd07010a80d584159729

    SHA512

    5629de6da1b8f2490f7717965dfc78dd8f024025c0797d46726f767e257bf13161d36e85d01d30cdafc45c12c28afb44badb6a19bcccba508a16fd9ed07c9263