General

  • Target

    c0b49d35aba26433370836dacc9d3007.bin

  • Size

    2.6MB

  • MD5

    68391fe42d6f4f61202f40ff7324b57d

  • SHA1

    1dee13f166a3fa951a5fcc7ecca7e6dc15b55fe7

  • SHA256

    c370c5b65b7cb690a4318c1ed7dca724281d482486b7f6f797c77ee3e27dba1d

  • SHA512

    8963d65b7f3586594585965cc5775109fe57e5e265c9e7c38ac13609d28df2980027f166e45da3cf777f84a0a0efbc236376e7657478d7de0cc622ad03fa5d72

  • SSDEEP

    49152:VTkRiCPHpTZ16cMalDIUyxFLyQ1eHRbbsAIBps+YcyXFB+tTb6LgbSfjy6ve:VT1+tmhADUaQ1Q59IL89yN9Ofjle

Score
10/10

Malware Config

Signatures

  • Ermac family
  • Ermac2 payload 1 IoCs
  • Declares broadcast receivers with permission to handle system events 1 IoCs
  • Declares services with permission to bind to the system 2 IoCs
  • Requests dangerous framework permissions 15 IoCs

Files

  • c0b49d35aba26433370836dacc9d3007.bin
    .zip

    Password: infected

  • ef9c1ee9c06e8f6f92e9388e445d268072a321a4bf77704054dfdfbc68bd8830.apk
    .apk android

    Password: infected

    com.gohaxacupumasa.kipo

    com.gohaxacupumasa.kipo.saxixi