Resubmissions

03-03-2024 12:23

240303-pktt1aad8w 10

General

  • Target

    Best Executor(not estrogen).apk

  • Size

    135.4MB

  • Sample

    240303-pktt1aad8w

  • MD5

    edc9e62bbf7348b491a5746417f83b18

  • SHA1

    83057fe09cba453fbe17eeb7185998899877d7d5

  • SHA256

    94fc77b396e172a24e60086f11cbe3a595ef89afe1315116b4e49de56aa7241d

  • SHA512

    3bcb0f1d86fccaadbb76abc0f481ea29c56fa8153133199dbc79b280c29617e1e939e461da2bc3c64b968d9807a91afcb3afa63997a2c47b326999f890a459c4

  • SSDEEP

    3145728:5r2Grhmyx/vyyCd9MH6SA1iFtrnd2lSD2clL070oaMUr:xmI/nCdCDAAFtrnd0SD1lLBM+

Malware Config

Targets

    • Target

      Best Executor(not estrogen).apk

    • Size

      135.4MB

    • MD5

      edc9e62bbf7348b491a5746417f83b18

    • SHA1

      83057fe09cba453fbe17eeb7185998899877d7d5

    • SHA256

      94fc77b396e172a24e60086f11cbe3a595ef89afe1315116b4e49de56aa7241d

    • SHA512

      3bcb0f1d86fccaadbb76abc0f481ea29c56fa8153133199dbc79b280c29617e1e939e461da2bc3c64b968d9807a91afcb3afa63997a2c47b326999f890a459c4

    • SSDEEP

      3145728:5r2Grhmyx/vyyCd9MH6SA1iFtrnd2lSD2clL070oaMUr:xmI/nCdCDAAFtrnd0SD1lLBM+

    • 888RAT

      888RAT is an Android remote administration tool.

    • Removes its main activity from the application launcher

    • Requests enabling of the accessibility settings.

    • Tries to add a device administrator.

    • Acquires the wake lock

    • Requests disabling of battery optimizations (often used to enable hiding in the background).

MITRE ATT&CK Matrix

Tasks