Analysis

  • max time kernel
    27s
  • max time network
    154s
  • platform
    android_x64
  • resource
    android-x64-20240624-en
  • resource tags

    androidarch:x64arch:x86image:android-x64-20240624-enlocale:en-usos:android-10-x64system
  • submitted
    29-06-2024 22:04

General

  • Target

    42adf8fe74b58c00734f5ce898f5f8aa7d58820dd3441cb03f364dba6b6c4c5d.apk

  • Size

    4.4MB

  • MD5

    206bc09f2c57403ca22371b5b718ac51

  • SHA1

    6e686d9d13bbeb20ef41d407dc2a7fe7b0b55d8a

  • SHA256

    42adf8fe74b58c00734f5ce898f5f8aa7d58820dd3441cb03f364dba6b6c4c5d

  • SHA512

    5e5b99cee5e387e3bf774c2bad0d6878e7cf1cde0cb3ae2e52133c8ec506e3d6504ec8773de88ac311d65b9dc38c6bb801de79af7064c3c5e34ea9f056a7eaa5

  • SSDEEP

    98304:56aZcz5w89vUOlvBZjypRFOy9E6tSqILjey90ylshHuEzlAwRvZ3h:gaZq5n1UA21ErjeByquwr

Malware Config

Signatures

  • Obtains sensitive information copied to the device clipboard 2 TTPs 1 IoCs

    Application may abuse the framework's APIs to obtain sensitive information copied to the device clipboard.

  • Queries the phone number (MSISDN for GSM devices) 1 TTPs
  • Queries the mobile country code (MCC) 1 TTPs 1 IoCs
  • Registers a broadcast receiver at runtime (usually for listening for system events) 1 TTPs 1 IoCs
  • Checks CPU information 2 TTPs 1 IoCs
  • Checks memory information 2 TTPs 1 IoCs

Processes

  • apnapuram.pk.sbisms2new
    1⤵
    • Obtains sensitive information copied to the device clipboard
    • Queries the mobile country code (MCC)
    • Registers a broadcast receiver at runtime (usually for listening for system events)
    • Checks CPU information
    • Checks memory information
    PID:5056

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • /data/data/apnapuram.pk.sbisms2new/files/profileInstalled
    Filesize

    24B

    MD5

    4bba1b87b59acd47d20bc6e0f26ee0fb

    SHA1

    bff9577ce45627f02623342273126b965a079dc3

    SHA256

    c3221132acc9dd60127598cdb94e43356ded0ac9a408ff2a74813b336a1328a0

    SHA512

    c8546d1d9cdaa25a187c628644c336fe27c7bc82bcabbf0a724b2ec0da76b1b8065a2d3255646c38859eceb86716a9376657a8744d5671ca38944a65c89b1f6e

  • /data/data/apnapuram.pk.sbisms2new/files/profileinstaller_profileWrittenFor_lastUpdateTime.dat
    Filesize

    8B

    MD5

    92f3ab2905ec8412d5480f87b0917df1

    SHA1

    7ec6a32847c76270e7d7298a5171488f5d606f83

    SHA256

    ba9f71f91b343c64db09ce981856ef19ab0f00ae4a4b110ab182d25d742325ba

    SHA512

    2a383069fa1860601cd1fae87dfebee563f261d8d910b8daabf96a2b19fad81f1cdb1743b3b08dc7718708119575774114b0136e2046d4dbc1beab9ce5267ec9

  • /data/misc/profiles/cur/0/apnapuram.pk.sbisms2new/primary.prof
    Filesize

    1KB

    MD5

    da689221fddba7c36fe1def4f0293a8c

    SHA1

    e8c744e7f8a81f6e203c114b90b0fbbeab6ff643

    SHA256

    933bcfadf94f75cbeb04e20e58e2816fce06b81423b303dc8050cc0d9041992e

    SHA512

    b172cf1a783c3be91489c1227acf467de5b6a74c3044991d31e5adc4975aff51bbb0998b137d46fd22e3eabf0b4e556d2c6c72547e67a73e2f9c18e2bddafc9f