General

  • Target

    e6c0ef7ef87316d2c02b1a41fcc307b6bbbb2c3c60b2d8b99b4dbe213326403e.bin

  • Size

    4.3MB

  • MD5

    780f3edda0e071dee63f15abf5f3efe0

  • SHA1

    6f629dfbfd68da33574c8a3061c80524dea5aebd

  • SHA256

    e6c0ef7ef87316d2c02b1a41fcc307b6bbbb2c3c60b2d8b99b4dbe213326403e

  • SHA512

    d29494e07f5bd74c64b7d04da160b77061fc1896329db9d41a3d9213924faa4b7fce4c15babde64506a34c32c4ca9d81c1ae436fc2df31d9ad22e81ad1794272

  • SSDEEP

    98304:Ta5ycL4AoFzwVNg4RLWtMnVyD7vbneGp4ihH1w3UItfK0BDgFal:+5zJ+8VNPLtnQnvbeGp/hVwkItCEl

Score
10/10

Malware Config

Signatures

  • Ermac family
  • Ermac2 payload 1 IoCs
  • Declares broadcast receivers with permission to handle system events 1 IoCs
  • Declares services with permission to bind to the system 2 IoCs
  • Requests dangerous framework permissions 3 IoCs

Files

  • e6c0ef7ef87316d2c02b1a41fcc307b6bbbb2c3c60b2d8b99b4dbe213326403e.bin
    .apk android

    com.appd.instll.load

    com.appd.instll.splash


  • childapp.apk
    .apk android

    com.JiDpzrKa.WmqvXSVh

    com.JiDpzrKa.WmqvXSVh.lnbsFoqc


Android Permissions

e6c0ef7ef87316d2c02b1a41fcc307b6bbbb2c3c60b2d8b99b4dbe213326403e.bin

Permissions

android.permission.READ_EXTERNAL_STORAGE

android.permission.WRITE_EXTERNAL_STORAGE

android.permission.REQUEST_INSTALL_PACKAGES

android.permission.REQUEST_DELETE_PACKAGES