Analysis

  • max time kernel
    126s
  • max time network
    132s
  • platform
    android_x64
  • resource
    android-x64-arm64-20240624-en
  • resource tags

    androidarch:armarch:arm64arch:x64arch:x86image:android-x64-arm64-20240624-enlocale:en-usos:android-11-x64system
  • submitted
    29-06-2024 22:04

General

  • Target

    42adf8fe74b58c00734f5ce898f5f8aa7d58820dd3441cb03f364dba6b6c4c5d.apk

  • Size

    4.4MB

  • MD5

    206bc09f2c57403ca22371b5b718ac51

  • SHA1

    6e686d9d13bbeb20ef41d407dc2a7fe7b0b55d8a

  • SHA256

    42adf8fe74b58c00734f5ce898f5f8aa7d58820dd3441cb03f364dba6b6c4c5d

  • SHA512

    5e5b99cee5e387e3bf774c2bad0d6878e7cf1cde0cb3ae2e52133c8ec506e3d6504ec8773de88ac311d65b9dc38c6bb801de79af7064c3c5e34ea9f056a7eaa5

  • SSDEEP

    98304:56aZcz5w89vUOlvBZjypRFOy9E6tSqILjey90ylshHuEzlAwRvZ3h:gaZq5n1UA21ErjeByquwr

Malware Config

Signatures

  • Obtains sensitive information copied to the device clipboard 2 TTPs 1 IoCs

    Application may abuse the framework's APIs to obtain sensitive information copied to the device clipboard.

  • Queries the phone number (MSISDN for GSM devices) 1 TTPs
  • Checks CPU information 2 TTPs 1 IoCs
  • Checks memory information 2 TTPs 1 IoCs

Processes

  • apnapuram.pk.sbisms2new
    1⤵
    • Obtains sensitive information copied to the device clipboard
    • Checks CPU information
    • Checks memory information
    PID:4626

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • /data/data/apnapuram.pk.sbisms2new/files/profileinstaller_profileWrittenFor_lastUpdateTime.dat
    Filesize

    8B

    MD5

    bcf4b19271481422b12d48ce39eed61a

    SHA1

    93dba5c3122f305c2d5bc365c9bcb3c6f0474eb6

    SHA256

    c97cebdadb0e6d24cbb6e02104d163f4d3f6214c6cb7be683a664216aa751af6

    SHA512

    d9acf6bf87da7461ca7ec5ea3e9247d2b3bbfc1c90159cac344d29d48e4b932a4b5e5c523942493aaeabca722aedc6dad6f88a280c27ffb7c647e7e42265754c

  • /data/misc/profiles/cur/0/apnapuram.pk.sbisms2new/primary.prof
    Filesize

    1KB

    MD5

    da689221fddba7c36fe1def4f0293a8c

    SHA1

    e8c744e7f8a81f6e203c114b90b0fbbeab6ff643

    SHA256

    933bcfadf94f75cbeb04e20e58e2816fce06b81423b303dc8050cc0d9041992e

    SHA512

    b172cf1a783c3be91489c1227acf467de5b6a74c3044991d31e5adc4975aff51bbb0998b137d46fd22e3eabf0b4e556d2c6c72547e67a73e2f9c18e2bddafc9f