General

  • Target

    d6bad24d0fb7e89ec5338bf8267338fd4dfdc1906b6081833bf11a7a167786d9.zip

  • Size

    1.1MB

  • Sample

    240519-ckry7ada6v

  • MD5

    5a1ab94461832306c209591bb3bae32a

  • SHA1

    8d5d298719ddd1d8267838215af1cc1320ff8c59

  • SHA256

    d6bad24d0fb7e89ec5338bf8267338fd4dfdc1906b6081833bf11a7a167786d9

  • SHA512

    b3bb210e1bcd6237fe233e3004c5d750b2b25f9f02d03807772c088adbd4b38ed0d85e2ef22b66a6136fbb6fd6ba80db8ccb899e72b561450add9feb68ed2e25

  • SSDEEP

    24576:sBRi+rjCGi7i9KfOizdgY+MO5hU5K4aH/DkXp/omyGng/WIMZr:sFrjCT+9yOizdsdsqH7k5/iGng/or

Malware Config

Extracted

Family

hook

AES_key

Targets

    • Target

      d6bad24d0fb7e89ec5338bf8267338fd4dfdc1906b6081833bf11a7a167786d9.zip

    • Size

      1.1MB

    • MD5

      5a1ab94461832306c209591bb3bae32a

    • SHA1

      8d5d298719ddd1d8267838215af1cc1320ff8c59

    • SHA256

      d6bad24d0fb7e89ec5338bf8267338fd4dfdc1906b6081833bf11a7a167786d9

    • SHA512

      b3bb210e1bcd6237fe233e3004c5d750b2b25f9f02d03807772c088adbd4b38ed0d85e2ef22b66a6136fbb6fd6ba80db8ccb899e72b561450add9feb68ed2e25

    • SSDEEP

      24576:sBRi+rjCGi7i9KfOizdgY+MO5hU5K4aH/DkXp/omyGng/WIMZr:sFrjCT+9yOizdsdsqH7k5/iGng/or

    • Hook

      Hook is an Android malware that is based on Ermac with RAT capabilities.

    • Makes use of the framework's Accessibility service

      Retrieves information displayed on the phone screen using AccessibilityService.

    • Prevents application removal

      Application may abuse the framework's APIs to prevent removal.

    • Makes use of the framework's foreground persistence service

      Application may abuse the framework's foreground service to continue running in the foreground.

    • Queries information about running processes on the device

      Application may abuse the framework's APIs to collect information about running processes on the device.

    • Queries information about the current Wi-Fi connection

      Application may abuse the framework's APIs to collect information about the current Wi-Fi connection.

    • Queries the mobile country code (MCC)

    • Queries the phone number (MSISDN for GSM devices)

    • Registers a broadcast receiver at runtime (usually for listening for system events)

    • Requests enabling of the accessibility settings.

    • Acquires the wake lock

    • Reads information about phone network operator.

    • Schedules tasks to execute at a specified time

      Application may abuse the framework's APIs to perform task scheduling for initial or recurring execution of malicious code.

MITRE ATT&CK Matrix

Tasks