Analysis
-
max time kernel
178s -
max time network
130s -
platform
android_x64 -
resource
android-x64-arm64-20240624-en -
resource tags
androidarch:armarch:arm64arch:x64arch:x86image:android-x64-arm64-20240624-enlocale:en-usos:android-11-x64system -
submitted
30-06-2024 22:03
Static task
static1
Behavioral task
behavioral1
Sample
62edd681bc2ca0192ad1290ff14a65a507418df74e07ebcc2222432847b1ee24.apk
Resource
android-x86-arm-20240624-en
Behavioral task
behavioral2
Sample
62edd681bc2ca0192ad1290ff14a65a507418df74e07ebcc2222432847b1ee24.apk
Resource
android-x64-20240624-en
Behavioral task
behavioral3
Sample
62edd681bc2ca0192ad1290ff14a65a507418df74e07ebcc2222432847b1ee24.apk
Resource
android-x64-arm64-20240624-en
General
-
Target
62edd681bc2ca0192ad1290ff14a65a507418df74e07ebcc2222432847b1ee24.apk
-
Size
1.8MB
-
MD5
1c12d0bca98b75364a883aad0e537be2
-
SHA1
599d2ec3e9716e182e930c91d685c83ab911cfd5
-
SHA256
62edd681bc2ca0192ad1290ff14a65a507418df74e07ebcc2222432847b1ee24
-
SHA512
0685c3391e9dc7d503ce43fabbe4a9883a2416a62c35e8d38ddcd086078a62da2b05aba3009c23292831a89a4094daeb1fafe9297cddbfbef85f9be5044e04ce
-
SSDEEP
49152:UY1K80SgiuWt0QAUAyD5SRtIlzFvb0Auh:YZS3t0n94SMlzFIAk
Malware Config
Signatures
-
Makes use of the framework's Accessibility service 4 TTPs 2 IoCs
Retrieves information displayed on the phone screen using AccessibilityService.
Processes:
org.zzzz.aaadescription ioc process Framework service call android.accessibilityservice.IAccessibilityServiceConnection.findAccessibilityNodeInfoByAccessibilityId org.zzzz.aaa Framework service call android.accessibilityservice.IAccessibilityServiceConnection.findAccessibilityNodeInfosByText org.zzzz.aaa
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
/data/data/org.zzzz.aaa/files/profileinstaller_profileWrittenFor_lastUpdateTime.datFilesize
8B
MD51835b0a5959124304d92adeeb1d55e32
SHA19929de80a301031a1219e67d12eafd6517b8cea1
SHA256fe443973b192e26b14db5cede371308c3d12ed2fbc3971f0183187656a088325
SHA512888c218e8915f024de61c50cd2715cbc5c241a6270c63b410841c887602145e6ff5ee4a23f4fa9be11f4f3e76f5346af883d276cf84e2e2b11b0fe2fce5c031e
-
/data/misc/profiles/cur/0/org.zzzz.aaa/primary.profFilesize
1KB
MD5185e15460b52cadea98c630f25a806d5
SHA12425571ee6b4bc8935986dd144ff1ab93eaea513
SHA256c1880c0160d9d693ce0e561ffc732a839b68af08b7ae1ac07f9bce2be6c4c019
SHA51218ab22132d95c9f99c2071e9de6a17591270c5caf4e0b12415740b26c227f291ff0a440a3583b25272e87b1c21a9ed9e9fd90bb04db2515420562a525c5a9c05
-
/data/misc/profiles/cur/0/org.zzzz.aaa/primary.profFilesize
2KB
MD5d7da134de322b207f07f041bec300806
SHA10d9c3700752fe5afdbb0df4dddc2be90c54231fc
SHA2564a0d5c2fb0d2945dbdf624161ad4e1ebfb7a7674466936102471ca9d5505564b
SHA512b176ecc4825953f45130249f047f93ab4e38279d487b96d65598c2c94a5e234eb106e34358ebc313063ce151f694a9fc09bf22dc8c4b93ba67609154ffeafa29