General

  • Target

    1c93d2ad8fb673cc3a704333eae792b8_JaffaCakes118

  • Size

    23.7MB

  • Sample

    240701-1eznvavdrq

  • MD5

    1c93d2ad8fb673cc3a704333eae792b8

  • SHA1

    faa703047aa8fcf446f545c1d736b234b374faba

  • SHA256

    60d3ea4b78684c3b58b1a0d54ede42ca2204141e04e23ab5660a60044007af57

  • SHA512

    23e2a4db86b34ed24e112d3f1856724ba9a3ee49ecb9738999d4aa9e6c079820ec185fa1959cdaf2ac845c1cc26881bba1e77faeb0d5e40ca95b0fe495c8d080

  • SSDEEP

    393216:ORroi3/Qmfl8aIpsZH4uqj2OAj+EWJL79MG9kYERCYA+5wdwBE2E0iHBmsmH/8R:a74mflVXHcjpJGG9LElA+5owdikty

Malware Config

Targets

    • Target

      1c93d2ad8fb673cc3a704333eae792b8_JaffaCakes118

    • Size

      23.7MB

    • MD5

      1c93d2ad8fb673cc3a704333eae792b8

    • SHA1

      faa703047aa8fcf446f545c1d736b234b374faba

    • SHA256

      60d3ea4b78684c3b58b1a0d54ede42ca2204141e04e23ab5660a60044007af57

    • SHA512

      23e2a4db86b34ed24e112d3f1856724ba9a3ee49ecb9738999d4aa9e6c079820ec185fa1959cdaf2ac845c1cc26881bba1e77faeb0d5e40ca95b0fe495c8d080

    • SSDEEP

      393216:ORroi3/Qmfl8aIpsZH4uqj2OAj+EWJL79MG9kYERCYA+5wdwBE2E0iHBmsmH/8R:a74mflVXHcjpJGG9LElA+5owdikty

    • Checks if the Android device is rooted.

    • Checks Android system properties for emulator presence.

    • Obtains sensitive information copied to the device clipboard

      Application may abuse the framework's APIs to obtain sensitive information copied to the device clipboard.

    • Queries a list of all the installed applications on the device (Might be used in an attempt to overlay legitimate apps)

    • Queries account information for other applications stored on the device

      Application may abuse the framework's APIs to collect account information stored on the device.

    • Queries information about running processes on the device

      Application may abuse the framework's APIs to collect information about running processes on the device.

    • Queries information about active data network

    • Queries the mobile country code (MCC)

    • Reads information about phone network operator.

    • Checks the presence of a debugger

MITRE ATT&CK Matrix

Tasks