Analysis

  • max time kernel
    26s
  • max time network
    132s
  • platform
    android_x64
  • resource
    android-x64-arm64-20240624-en
  • resource tags

    androidarch:armarch:arm64arch:x64arch:x86image:android-x64-arm64-20240624-enlocale:en-usos:android-11-x64system
  • submitted
    29-06-2024 22:04

General

  • Target

    5d2461d4aa977208da9aa2aca48646ad2586af07a1c718cbbe8ee026d013009e.apk

  • Size

    4.4MB

  • MD5

    27ab58d304e89bf784dcab85f59482ad

  • SHA1

    778ce244cd72b3388d0d240f921b40d885732b6d

  • SHA256

    5d2461d4aa977208da9aa2aca48646ad2586af07a1c718cbbe8ee026d013009e

  • SHA512

    5dcf4d9f973f22efd420629e1cda8f76b15aa732c0cf5b92a51ef10c5adaf46f1e2b414922133a54b077476866c18b6c46845aa07b3aa952bf2419d552efef60

  • SSDEEP

    98304:NLojuXUOlvBZjypRFOy9E6tSqILjey90ylshHuEzlAwRvZ3W:NbXUA21ErjeByquwM

Malware Config

Signatures

  • Obtains sensitive information copied to the device clipboard 2 TTPs 1 IoCs

    Application may abuse the framework's APIs to obtain sensitive information copied to the device clipboard.

  • Queries the phone number (MSISDN for GSM devices) 1 TTPs
  • Checks CPU information 2 TTPs 1 IoCs
  • Checks memory information 2 TTPs 1 IoCs

Processes

  • apnapuram.pk.sbisms2new
    1⤵
    • Obtains sensitive information copied to the device clipboard
    • Checks CPU information
    • Checks memory information
    PID:4467

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • /data/data/apnapuram.pk.sbisms2new/files/profileinstaller_profileWrittenFor_lastUpdateTime.dat
    Filesize

    8B

    MD5

    4437c28e90306cc0506548777a1ffcc7

    SHA1

    e531de671aa33e0b901a00cea2b3f572f13b6f81

    SHA256

    3dabb955688ed3f320f538fe141aa95a880a09a53c3a7f642d4af972659ea6df

    SHA512

    73b866958249784bb226cd110ac165fa29a45577facd06078fa76d505e22ec3c514484d6a505c21c680ae8b3502b7fe76dfa867bf45233f7226980ed422cee80

  • /data/misc/profiles/cur/0/apnapuram.pk.sbisms2new/primary.prof
    Filesize

    1KB

    MD5

    f96e9622d3d2df4be53fe52f1db85589

    SHA1

    986e220f53015c179e01bac1f821a0ee6ac3ca62

    SHA256

    96b182a06fb8db8537a25d904f85432e6d408a1359d16dc46d661e2d916632be

    SHA512

    65895b968b514ca5c7967f880c6bffb9ef72bbf3e485d3a71ecef8b7c649dd0083c0f7e738f472c439c856f528b0e5ab2a4ebc81eef5334baeb263bce348077a