Analysis

  • max time kernel
    22s
  • max time network
    136s
  • platform
    android_x86
  • resource
    android-x86-arm-20240624-en
  • resource tags

    androidarch:armarch:x86image:android-x86-arm-20240624-enlocale:en-usos:android-9-x86system
  • submitted
    29-06-2024 22:04

General

  • Target

    9ef13ddb46c9621254411583577f5485caa87ede2395617a7d70693393715bca.apk

  • Size

    4.6MB

  • MD5

    0b2bce2dc07e12a6408390691fd4fff4

  • SHA1

    5efb02d6cd61f41e2a18f6e74461c01e365656ab

  • SHA256

    9ef13ddb46c9621254411583577f5485caa87ede2395617a7d70693393715bca

  • SHA512

    8e1c1823b6951f5ca616b23a91e5c6131628b3517b0415c67dc9d5817b139f5d64618c7ea8541ebd6f6a93541edc06bd536ff62cc529880ab7149b0f3561e583

  • SSDEEP

    98304:8jl13OfSeFCWcPX2bN7moWWgKhLho9f83WPoKfnADKN4H4UPbn:6ldeFCzPm57LWuSfaWAmKj

Malware Config

Signatures

  • Queries the mobile country code (MCC) 1 TTPs 1 IoCs
  • Registers a broadcast receiver at runtime (usually for listening for system events) 1 TTPs 1 IoCs
  • Checks CPU information 2 TTPs 1 IoCs
  • Checks memory information 2 TTPs 1 IoCs

Processes

  • com.google.massagg
    1⤵
    • Queries the mobile country code (MCC)
    • Registers a broadcast receiver at runtime (usually for listening for system events)
    • Checks CPU information
    • Checks memory information
    PID:4256

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • /data/data/com.google.massagg/logs/20240629222544038.log
    Filesize

    33KB

    MD5

    7c3f5d25bef96053837e1da61d766881

    SHA1

    9c018b764f76eb79c150a303a3ba1f1382891718

    SHA256

    1a3afd6d96c2c444c05665121c71391af6c09fbddb58d22ce717704834e36f56

    SHA512

    c0ac124d8e8e94ca74c6c5242ad231c84fd360b680676e2d6dcb7f7245731dd985fc86ef7beff3abdb8db9e28d382320e1a3d377d05184dd4da2dd94dd87e944

  • /data/data/com.google.massagg/logs/20240629222544060.log
    Filesize

    20KB

    MD5

    8efe7e154e9af575f7a62c03aca64507

    SHA1

    a8eb13a6cac6a5a87c8ffcc57c33242b12f4a3e1

    SHA256

    234119de2acbdc9e8041ce489656f83475cad8d5fe4c8316b87e83a1939aebb7

    SHA512

    8f33478f1e5f2c62d8a970500d706f53732fcb7b119f7c9011eecce26bb3d1cfa99b3a956db82a9138eba2b4aba4c2535308e26f2b1ecc75ea311987c6189225

  • /data/data/com.google.massagg/no_backup/androidx.work.workdb
    Filesize

    4KB

    MD5

    f2b4b0190b9f384ca885f0c8c9b14700

    SHA1

    934ff2646757b5b6e7f20f6a0aa76c7f995d9361

    SHA256

    0a8ffb6b327963558716e87db8946016d143e39f895fa1b43e95ba7032ce2514

    SHA512

    ec12685fc0d60526eed4d38820aad95611f3e93ae372be5a57142d8e8a1ba17e6e5dfe381a4e1365dddc0b363c9c40daaffdc1245bd515fddac69bf1abacd7f1

  • /data/data/com.google.massagg/no_backup/androidx.work.workdb-journal
    Filesize

    512B

    MD5

    8dc4c1e1d4fd9ad3f88a40f906f60640

    SHA1

    f9ab344e51a171e7e1aab0fae392d8898c82295b

    SHA256

    ee6334b3b12a2615cc8aa158e1235e9185226dc170b48a48a862430919aa33e4

    SHA512

    32124529be3f7e01b2bc17bd3d3183aad180c62d846894f1f6f58336786f256de7e7ebbdfde198f77e25bcda86309327ccf0bc87f1930b01eb601d9de37c0cb1

  • /data/data/com.google.massagg/no_backup/androidx.work.workdb-shm
    Filesize

    32KB

    MD5

    bb7df04e1b0a2570657527a7e108ae23

    SHA1

    5188431849b4613152fd7bdba6a3ff0a4fd6424b

    SHA256

    c35020473aed1b4642cd726cad727b63fff2824ad68cedd7ffb73c7cbd890479

    SHA512

    768007e06b0cd9e62d50f458b9435c6dda0a6d272f0b15550f97c478394b743331c3a9c9236e09ab5b9cb3b423b2320a5d66eb3c7068db9ea37891ca40e47012

  • /data/data/com.google.massagg/no_backup/androidx.work.workdb-wal
    Filesize

    16KB

    MD5

    15bc895a8fb987bfff1185627fbf4bc8

    SHA1

    6dd01323ad3b6b8f0267a3e7d77ae20aeffd5de8

    SHA256

    b39e8f25fbe13acb047d861e4e43091f821b86f9b21a30b1445d2aa801cc7bc2

    SHA512

    eae61311d9ddff0892f5aab0ec8eab137586d6c4551f60c2a8dce4da65bd447b71241f7e75e4691f9dc484a6f84417fc81ec6b544373c44fdb278c0d5da9a6c6

  • /data/data/com.google.massagg/no_backup/androidx.work.workdb-wal
    Filesize

    108KB

    MD5

    c30ffc6123d752857955d282e85129ff

    SHA1

    a9f86cbd47c21a43cfba536d0cf7d9a25752ec50

    SHA256

    86ed7162505d1ab2301f83eb7edb9ed74c056b1fb1798681d05b941200e9d9a7

    SHA512

    4639dfe8d94e0c6761da90291d5d746e8b30a01a412d1f4cd495492a41eb40da7def82fa65dba3f8940436e9e8d6e596fa8ce39640fe99907aa1e676a407c49b