Analysis

  • max time kernel
    36s
  • max time network
    388s
  • platform
    android_x64
  • resource
    android-x64-arm64-20240624-en
  • resource tags

    androidarch:armarch:arm64arch:x64arch:x86image:android-x64-arm64-20240624-enlocale:en-usos:android-11-x64system
  • submitted
    30-06-2024 22:49

General

  • Target

    LP_Downloader.apk

  • Size

    2.9MB

  • MD5

    0ffdbcf4b4315a0447f84cdd84ce78ce

  • SHA1

    4630f604cdca8fe9a4d9ed34b4f648dbe3350395

  • SHA256

    f4775b98b2eb3a2d4c8e8680bb902829d74626774594eb91474e9f948cf49636

  • SHA512

    ce82a8eb7b1233d4e2af170198a70ddcc8ee2921542cfacdefeaf828470da2ef00ec4dfca3e3b4119d57714f201a15922f98704050f6169a47ee9e23683299e7

  • SSDEEP

    49152:dLwSegL19xZF5NucFE0DR7qQyb+EmKoaGAGiwJMbphZffrlqi:dLP193XNuKlqQtEm1aGdigiffrlV

Malware Config

Signatures

  • Loads dropped Dex/Jar 1 TTPs 2 IoCs

    Runs executable file dropped to the device during analysis.

  • Acquires the wake lock 1 IoCs
  • Launchs application installer. 1 TTPs 1 IoCs
  • Queries information about active data network 1 TTPs 1 IoCs
  • Schedules tasks to execute at a specified time 1 TTPs 1 IoCs

    Application may abuse the framework's APIs to perform task scheduling for initial or recurring execution of malicious code.

  • Checks CPU information 2 TTPs 1 IoCs

Processes

  • com.luckypatchers.installer
    1⤵
    • Loads dropped Dex/Jar
    • Acquires the wake lock
    • Launchs application installer.
    • Queries information about active data network
    • Schedules tasks to execute at a specified time
    • Checks CPU information
    PID:4450

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • /data/user/0/com.luckypatchers.installer/cache/volley/-1959685321231207228
    Filesize

    916B

    MD5

    215a21de4ac3882752f862c597d2f89e

    SHA1

    74d2aed2211ff5d869e576d74575d6b9bcd33518

    SHA256

    d0c2f4019c67396ef1fe9410b2bc11b9a611e7566d281963c096eae7fd9b0303

    SHA512

    71ba304a1273de5bea9389ef538baed4da022bfbe956c5d890b1001dc459e8fa1ee09106e576edbec5fcb16bb68ae7735a9fab082361df8d00a5750c00563a0e

  • /data/user/0/com.luckypatchers.installer/cache/volley/-1959685321231207228
    Filesize

    916B

    MD5

    bb66f475106705685a5b89d1f5d098a9

    SHA1

    fc7de9930c3f7258eac19473e4b22e0f81a9e87b

    SHA256

    07c22501a2a2a30bf69944f6711f511098e74c49c23d62f208e7d53ef0a7f578

    SHA512

    eba943db3fcc319ef9f1eaf837052638980936007f7806e5ba963cd5b89a6e4e0f9bd516b03b632b644acf451f1264829d97e7136f4c7a0ba17b6c95e7c77546

  • /data/user/0/com.luckypatchers.installer/cache/volley/-2046855874506811318
    Filesize

    925B

    MD5

    0fbcf504cb106c4a5c578394fd16264a

    SHA1

    5c4d16e0eba5a8387435ddbdd90eea6ed7dc2e9d

    SHA256

    7a8d6df2aaf0f4bdba28178593d8c8576d904f783f7981c28f601d80e2049dab

    SHA512

    3a986a2d03db05bc31fffe2a391020f70692a4fcd89d7f32c94fcbb36703d53bc6d0762931a006db027e393c58ebb7cc5649ad6c6b83f09ea5bbb33c468bc8c5

  • /data/user/0/com.luckypatchers.installer/cache/volley/-789261001-1034700308
    Filesize

    606B

    MD5

    309474fe73b6efd3da10a224b453d631

    SHA1

    4eb1d82d4cce6139ee35ace34dc880bcbb8bf7f9

    SHA256

    625834dde6a3a38568be16a6c0e816293f91b45c6b6ff995b3e5a37af67565d6

    SHA512

    923336c108df9be9e3e2e8b769cbd7a609a205c0ea121bb17a3b13e0cbfd2128ce88d6b34011cbf2d03c4f78ba7f641b67345d6432a54dbcd0d8313aace19ba7

  • /data/user/0/com.luckypatchers.installer/cache/volley/1728755663-1568795026
    Filesize

    745B

    MD5

    e4511c2bae139b4937f53776574e62ea

    SHA1

    9a6bfbaf2d304c9c295ad040398fea6af84a481c

    SHA256

    912ea8db598fe28c132bdb56f37226e7a538c6512ef5a3502e2039efb4f588b9

    SHA512

    5db40aa0dabdd7d5a8af9e495ab9a0ce84d71ee90fdfa508d3d65387e9a84e6980b8f2539133340ce5a68c97b4937c859832c75a379aee43aec4382c7b25584b

  • /data/user/0/com.luckypatchers.installer/cache/volley/2071512381-2122914367
    Filesize

    2KB

    MD5

    0148eabe9544690f4296e83795427c58

    SHA1

    4cf994e492a47f84fcbb67435121bb199aed5ec7

    SHA256

    f5159bc9875d365e944ae7e8fa0d1a871c78a493d77e32acb78324df02452a98

    SHA512

    611074fc94f2be9d7dea2eb640d5f4fc67958963c76c09bcd8599c01d910c841b7dcbaa1d3c2f388873b5396720a00e2b130e1a982965e33c48e223616fc7f99

  • /data/user/0/com.luckypatchers.installer/cache/volley/2071512381-2122914367
    Filesize

    2KB

    MD5

    70efc6511112b437560c7da911fc8848

    SHA1

    ff6b652fdeb9788e499311597ae135a3dbc0bbb3

    SHA256

    472374739a0b15cf353c75b7c28cb6627d1893b07b64794d8c94af279d3be905

    SHA512

    c8ad4096aff11e68941496b80be46fd236c13d706fdef02afde85930c7adeb78847db4ea32ba9ec87a37d999a2418e711e479b176fc07e62722aa45398b7809a

  • /data/user/0/com.luckypatchers.installer/databases/com.google.android.datatransport.events
    Filesize

    56KB

    MD5

    fce592157d1e203f49848402ab23e144

    SHA1

    7ef1bea623ca4b7bf51a0099b9926ce91d3e92d7

    SHA256

    9cdcf69b3b94b268e84c6bd84b513a4dde4c2ba78001ff1ff9f3b7ad2843239b

    SHA512

    bec369d3ba55b0325225f768107569c753bad052518678e2cadbad853850fe6376c7fb6d5221f084704f01c477c939b905aa0faaf8b28dda3fc13f6bcaa234ee

  • /data/user/0/com.luckypatchers.installer/databases/com.google.android.datatransport.events-journal
    Filesize

    8KB

    MD5

    a2830004006c8bdf987cb7e21c5f306a

    SHA1

    aa6ffa05e8cc5eb1520adb1cc5392ee3091d1fa1

    SHA256

    46f08abacd5742af3ceccbf738c78c38a8456332ac9d2d83fe6b7c27de10ef00

    SHA512

    e6a65ef14b6263ef916d71063c67b5a60b7b523dc5706178d58b8de93500747ae9c19941c3cae0748148dcdff3ee62026a05566c657f4ba39a08fcf81d5f5a6b

  • /data/user/0/com.luckypatchers.installer/databases/com.google.android.datatransport.events-journal
    Filesize

    512B

    MD5

    8861cd29630488508ffa7cc4371d3edb

    SHA1

    cfffbd12ad6c49e14a96057f9155a271a4c51e7b

    SHA256

    4929491defafed387293a84e1a88eb18e34db2efd08192a30eb081eca68f03bf

    SHA512

    3b6a46535db74ae12c08bed048582510ebc6c855ec1032b88bdf33296064a53c15449708c4af22cc14ba3035252573a2d74931a74f54421f32130e3560d15dc3

  • /data/user/0/com.luckypatchers.installer/databases/com.google.android.datatransport.events-journal
    Filesize

    8KB

    MD5

    948a6b12b7c246ad3303c908d53209dd

    SHA1

    f72f2c5abbec0398a5cf2c7f8c3fa030fad03fbe

    SHA256

    9193b7a3e5e5a737251c7f696ec4804b76d55e193f6e16bc8bcd2e80611ac189

    SHA512

    0eb72185997be5b88881360ef52dce5597ac8bfcfb95a91943ed7582f61ac3db73f9997b8db4eb59d10bbd7221d1cbd04297ec98d54a22152817200cd4202f52

  • /data/user/0/com.luckypatchers.installer/databases/google_app_measurement_local.db
    Filesize

    16KB

    MD5

    d9cf75fdd1c2292d986f6c3d5d60f2c8

    SHA1

    07ecb1d3a26d952ae5fecf54f36699ab498510b1

    SHA256

    2d227e9b7a044c8e10294f6a831fb92d81ea9582381796d87f35bd268e37538a

    SHA512

    442c96e4b4c79b8d1c64dd3a6d6088ae1dace441e78d830dfb3190ee1c0fafebc606fb432071b4a1ad1a4ba9b68c7877b0bce520ccc88708feaf82bbc474e0cb

  • /data/user/0/com.luckypatchers.installer/databases/google_app_measurement_local.db
    Filesize

    16KB

    MD5

    785bccd4222d353bac3e1e0b87284959

    SHA1

    41b2d1d6afdadb603795ed6217ee66ea37409aca

    SHA256

    d96745e653325f2cb8a040bae4b042bfbe4901028120b40d0b27e6edae7ae69e

    SHA512

    709bb98eefca0ea731c19a0a159b998f028b0726f26cb98db9a67bf6b557dcc78013ecc11ee562f9b10672ca40ae0f6129dd71e979d8c15f5b699ab707b76bd3

  • /data/user/0/com.luckypatchers.installer/databases/google_app_measurement_local.db
    Filesize

    16KB

    MD5

    dfc084e72c38a9e1045578f43b9ccf43

    SHA1

    8afbc361bd15902f35cae0ed3eba3fb196714afd

    SHA256

    caea7011aca60ca51b0a5e97600d13e3fe23314ba730e7548f3592670bd404bc

    SHA512

    81fdf075295e2d47aad754691d51762fea08f0382d1a320cd05943ab3d7a7f333f10b5821efdebc4e123c0e123833ecf5031988ce919b459feb81a2919e553ee

  • /data/user/0/com.luckypatchers.installer/databases/google_app_measurement_local.db
    Filesize

    16KB

    MD5

    6490367510e4838510d0699ea9fda335

    SHA1

    9db5fcf65816442a8430729e7e7ad2901c750cd4

    SHA256

    59bf65558e68ae5cc77c4a231dd471c0ef3caa5196d856b4e576c46387bcf8ec

    SHA512

    acacbc37d570ddd10394d97cabf87381bfb0c3aba4d6949ccbbb469bbca328395c3ed15f85b9e6dd476c2c90d5daf1fa4603e2ca2b94783f759d23e7e202a2f8

  • /data/user/0/com.luckypatchers.installer/databases/google_app_measurement_local.db
    Filesize

    16KB

    MD5

    eeb3e229e70ad7b859a0a6206df741e2

    SHA1

    e099d23140424273f96138d7a60d96439e55e942

    SHA256

    f548b55ebec8c40686f620b0acd50aa00c86b3061f93d63d473201873f8306fe

    SHA512

    c1049336898cc6df8388f7338ddfab2f126cd13856d414957995ca1e45bc093d00c80f5b5033443c4a252390b551cfab3b6bf59d528ea5a4204c7af3b10b2ee6

  • /data/user/0/com.luckypatchers.installer/databases/google_app_measurement_local.db
    Filesize

    16KB

    MD5

    b85b26a1f9e93a36ef887a984de929f8

    SHA1

    a6c088cf6dc68da12358e7686bb97ee7660b69b0

    SHA256

    c3b4040d10fc60fe1d90fff3e65f5258aac089dc12d0578ec43f89e2d1d207b4

    SHA512

    2acf546c45a11f2d0b3edb020e66c9de4bd104e8cc3c0a624125926589fbbea0412ce66fe6f582da8ecae726dbafa647b72383818508e2c57d6da46cd4698e4b

  • /data/user/0/com.luckypatchers.installer/databases/google_app_measurement_local.db-journal
    Filesize

    512B

    MD5

    10bd80d461c37349bdac1facd0445763

    SHA1

    1bc1ee0c281f046b3ee8e9f7dbf8cc488f7db43b

    SHA256

    5802d5520613344d2b49c7b1886014e7974d1e72d1e37391501874a109d7d9ce

    SHA512

    0aff36eb559efeeccb3c532c3f329f2af15fd2dc76416751900b874f56718c5a2e97c354d2af955c573f9849715dd679be567db099067de654c9ef8e3c606fe2

  • /data/user/0/com.luckypatchers.installer/databases/google_app_measurement_local.db-journal
    Filesize

    8KB

    MD5

    3a5a3c9a27284df77da1504228f04a62

    SHA1

    7882387cc124ccfa0b570b510c8753cd8a87cce1

    SHA256

    0e7b5d20e11302f2e5026e0bab9421880b63ea924818ae84010208782ae8514f

    SHA512

    95a590ecd4fb21594f7bff08850a136c4d5a9df95e51740d181253a1b27a168f5e1cd77b25a0ef2a9fd80090441fd65dda6d16acb2474762fc30979cc1e61279

  • /data/user/0/com.luckypatchers.installer/databases/google_app_measurement_local.db-journal
    Filesize

    4KB

    MD5

    6b3ebe57640e4175ad9a5a6215b5f920

    SHA1

    a4544bec150d3ac09bc5297c0004591b2a637efa

    SHA256

    3c89adda302c1601f9b2b6d289926708bc938141331e21751dbb02fe1ab80530

    SHA512

    696a2ef41bdfb3ba52ae014a7af766b92820f8407b5277ae35633d65f42dd308a4d28d0f38b1843621d68adb58e52c6aeb18ec55647f34e7bd1f059869b01a6b

  • /data/user/0/com.luckypatchers.installer/databases/google_app_measurement_local.db-journal
    Filesize

    8KB

    MD5

    fb2dfaab9c12b9f34e2c1eac804ba737

    SHA1

    76c0124694bcd1aaa429fa8027252a5c0a4541fe

    SHA256

    36970f9543c1168dba82fc35ddeae2b0e141574febe0f356cf57f057ff920a40

    SHA512

    8a7e73d4e5485102f7eadeada0cfe9576cb3488f353e18998881bdc6f0ddca75e2164d7b14f50e1118ca8e0c72f95fc008f71ce90d458744b60374785c453b35

  • /data/user/0/com.luckypatchers.installer/databases/google_app_measurement_local.db-journal
    Filesize

    8KB

    MD5

    30dcb2e3f2865edeb2db7d641c964579

    SHA1

    e218cc6e1d8fa04cd72b674a46204e9676a9e272

    SHA256

    d7d7449bbd9d96681a39eb0bf60a163ca72a79a53a96a469c7a1b921ffc23dc9

    SHA512

    9cb42664c2783d17a4b87b1ab38f2303afc50715d999d80f6f6640b9313de4791c65a0d55bc0dc2a15eb110e94ada8838688e2a32976a909756a0c756ba46094

  • /data/user/0/com.luckypatchers.installer/databases/google_app_measurement_local.db-journal
    Filesize

    8KB

    MD5

    da2dac7a566b217c7159c7c083acc48f

    SHA1

    051d9a288d58781199062b52842dc7de7c52b3e6

    SHA256

    e7ca765eb6dc482f9d8cf4f2cc9fc202fe16175c3e9917598c62be96352991d6

    SHA512

    e0b7827451cd9e68ea26692318be486e30338debd0f8a3962d0a965a8191d9fd1c4fb5acf91fb28f7328029f150d266c446b25bfe135de7c5cd384d43e4a69b7

  • /data/user/0/com.luckypatchers.installer/files/PersistedInstallation2719903832822788197tmp
    Filesize

    569B

    MD5

    323031756082f63e3037fb544c92682b

    SHA1

    933c7a24de06566f5ae4681e3ae92431b7b0215e

    SHA256

    f688a86bc1d693038979740fb332bb14a2a10a0f88c295418d68547d3e654082

    SHA512

    ffe192cc0159a3fb9d3ea9d489a1f6274913ae99942031ed32133834923e33751191061debee32ff5d0b8d2b8c09bab912bd751f1b4eef17c435d4aad22e3630

  • /data/user/0/com.luckypatchers.installer/files/PersistedInstallation2916507453396635300tmp
    Filesize

    90B

    MD5

    ca3fbae007002b1aff728e1301d94ba0

    SHA1

    93ac4db6d0c1a1ae25ecf6c9ab8d81829544cb4d

    SHA256

    51b6ea76d749ae625b318246c3e050d089f3e3be369b68754cfa5a054a4548ad

    SHA512

    8bcb8aef35234f925bbab99d0dc22211b1f880cea42e55ec097083ca631a6b222a00f2dfc85093d893ac09524cc6dfd486da6efcfc6a4263f8d0cf5fd71a3af0

  • /data/user/0/com.luckypatchers.installer/files/PersistedInstallation8189114545040409227tmp
    Filesize

    90B

    MD5

    56c2fa700f5c3c9ef78b339826c70d22

    SHA1

    4f578609aaf30da96018b5112420808cd83aaa62

    SHA256

    4d2d94f2c7ece96a67d5744b1b6c5a8dce1ecafd05bd62bfb68a105a497b233a

    SHA512

    3d4c16278866a12a613c52dfaff1d5135c9a1804f75422cef9809789f7c47b859e7f07e5e0d3e7c0fba7e7fef3ad48d00706a8732be1d521850a17c4f1097396

  • /data/user/0/com.luckypatchers.installer/files/PersistedInstallation978378901198478372tmp
    Filesize

    570B

    MD5

    c88041dfc4dda046cbf0b2be0ab1587a

    SHA1

    91eeec2694a161dca7da8cff90ccd9cd17b4c6c7

    SHA256

    c0493afbde4d6fd0431d114382a35b9f9387649000a09fee5f92b7b240628f75

    SHA512

    29bc36fbe103f472f0227341c0104d4f9f32b7ec6a21559a7f4041e81b0e4a55b94d50d094a62a0a7aac6ed704dc434164699353a03854e3745b601c130f8117

  • /data/user/0/com.luckypatchers.installer/no_backup/androidx.work.workdb
    Filesize

    4KB

    MD5

    7e858c4054eb00fcddc653a04e5cd1c6

    SHA1

    2e056bf31a8d78df136f02a62afeeca77f4faccf

    SHA256

    9010186c5c083155a45673017d1e31c2a178e63cc15a57bbffde4d1956a23dad

    SHA512

    d0c7a120940c8e637d5566ef179d01eff88a2c2650afda69ad2a46aad76533eaace192028bba3d60407b4e34a950e7560f95d9f9b8eebe361ef62897d88b30cb

  • /data/user/0/com.luckypatchers.installer/no_backup/androidx.work.workdb-journal
    Filesize

    512B

    MD5

    24a8aac737511d89bcb4faa7d9d23a7c

    SHA1

    40e0d22a3e885970826025db05b3441388a60fa1

    SHA256

    c011603b71123f545bad33f7aa3bb623336a5bb9ac160cee50894c2a0ff2948b

    SHA512

    fd72b07b012370cd120dfb80958601c5ac45e2fa209ea7f70e6d439c6f50cde648aeed0d3f99230b6bfe2608b8fd92cc1ab5030d67fc969dee95e7e22b3932a7

  • /data/user/0/com.luckypatchers.installer/no_backup/androidx.work.workdb-shm
    Filesize

    32KB

    MD5

    bb7df04e1b0a2570657527a7e108ae23

    SHA1

    5188431849b4613152fd7bdba6a3ff0a4fd6424b

    SHA256

    c35020473aed1b4642cd726cad727b63fff2824ad68cedd7ffb73c7cbd890479

    SHA512

    768007e06b0cd9e62d50f458b9435c6dda0a6d272f0b15550f97c478394b743331c3a9c9236e09ab5b9cb3b423b2320a5d66eb3c7068db9ea37891ca40e47012

  • /data/user/0/com.luckypatchers.installer/no_backup/androidx.work.workdb-wal
    Filesize

    108KB

    MD5

    4007d1fd10a7c7820d0389d916a94486

    SHA1

    fe30c2116a3b87f453029acbc5af27d042a5690b

    SHA256

    81bfb4f3e55548d5bff44c5acb6428588a2cf59576bbec03c0ca3cd9aec2defc

    SHA512

    c177930c61e2dba15de9ba00d21d228ff57551885d811d57a790d940871a0aeaf088bdcc325c2a5627a9c930f63457fa92efbfba9698bcfa8398586766c2b5ef

  • /data/user/0/com.luckypatchers.installer/no_backup/androidx.work.workdb-wal
    Filesize

    189KB

    MD5

    670c569351e44721afad644d386ea6ed

    SHA1

    c80fcd892f6bd27cedf1fbfe3772d133c058a536

    SHA256

    4c6fb46a750761928a9fa097975b2235d537a7f823b1d988300e71747ef1a07c

    SHA512

    0d616fae7625639f003fc7f71b96caac3f8334837f4fe142463db81020a61d24d4103fd05fbabc5ae0a5d3540e3c3f4d55c784b6a16c0ee1a208a128939a1836

  • /data/user/0/com.luckypatchers.installer/no_backup/androidx.work.workdb-wal
    Filesize

    16KB

    MD5

    e6a5c60caded28339826e8ff6640fa7c

    SHA1

    b1ab1214dc25317824f36f64dc86f350ffa3cfd3

    SHA256

    b254ad2e8b0161ffdd05abcaaa00ab28a0efa38f870dd8848c0ed46d028b895e

    SHA512

    298569a5ae46dfa25042cdd386327d36ba84561ae5cf59acedfc3e2304112f5f63c63264e282af62e50d65466c029fdf98cb2b743ba4eecb935f5b1e7a63a627

  • /storage/emulated/0/Download/luckypatcher.apk.temp
    Filesize

    10.4MB

    MD5

    4acc7696d99ea2693b3a490e0bf54a59

    SHA1

    c3ce8970dcc5f55ad64d53ecc603b58f7cd1d504

    SHA256

    d84ad92be6343805085a809140ae637456bd2dc3a8f3b648f58f33dcd2eceb63

    SHA512

    b1f55279a8bb67ec5f3f0bc2988ba22581efdb0e8a855b5c5cf0fcc156ae0a2d03700e1edb2cf6cee2d008b143edc8a026b295929c932160ea69a6d53d969c57

  • /system_ext/framework/androidx.window.sidecar.jar
    Filesize

    12KB

    MD5

    bdf3529e80318eb14e53a5bf3720c10d

    SHA1

    25c9ace4b1af6e80ebb2572345972c56505969ba

    SHA256

    bbc8300dd1e9cd08de8f66560c1ac2c928615b72b51cef9649f88974f586d64b

    SHA512

    48b9c2d01171bb651b9b54826baa51f4add48431a3efd8ceb5f7cc3bcd6f8f37edf47fabb24349dd15b3a02329cd450f90a8d164bf4f8dfae554bf3b35a8a55b