Analysis

  • max time kernel
    26s
  • max time network
    131s
  • platform
    android_x64
  • resource
    android-x64-arm64-20240624-en
  • resource tags

    androidarch:armarch:arm64arch:x64arch:x86image:android-x64-arm64-20240624-enlocale:en-usos:android-11-x64system
  • submitted
    01-07-2024 22:00

General

  • Target

    a1233cdb6a0e6a6296c50e0eff23668b9258a315eabfffbe655ab7e5fb915528.apk

  • Size

    1.8MB

  • MD5

    f46ca721230ac3f1d41829435b3a7d71

  • SHA1

    1a7ebdcca76ed15c704b31844f8077c2887747a0

  • SHA256

    a1233cdb6a0e6a6296c50e0eff23668b9258a315eabfffbe655ab7e5fb915528

  • SHA512

    8f6da29ce6d14743618393e0760b7b7e979dbda1f36a09442bb9008d38a6582c7a7c890ddfa7ca7dd0b395f0e248e966e6a4ba4c686a05e15e75040892c86a30

  • SSDEEP

    49152:jv880rdjLbAf6cZk59QOthbnH16oWgSHNb:z4rdkfRkJwoaNb

Malware Config

Signatures

  • Obtains sensitive information copied to the device clipboard 2 TTPs 1 IoCs

    Application may abuse the framework's APIs to obtain sensitive information copied to the device clipboard.

  • Checks the presence of a debugger
  • Checks CPU information 2 TTPs 1 IoCs
  • Checks memory information 2 TTPs 1 IoCs

Processes

  • pkmast.pk.yonosbipannel_new
    1⤵
    • Obtains sensitive information copied to the device clipboard
    • Checks CPU information
    • Checks memory information
    PID:4453

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • /data/data/pkmast.pk.yonosbipannel_new/files/profileinstaller_profileWrittenFor_lastUpdateTime.dat
    Filesize

    8B

    MD5

    32f7597430a27e0822a5f9fce5968c02

    SHA1

    04182edee3638775ba3dbece2efb261c2214d10d

    SHA256

    4a190d4a2a4ef68354b2ac7716a9a911ccdfff52c29dea69f9b63a4f6d5135ee

    SHA512

    05e7325210415853e14d43fed4106db4d46a9a62d764349a6d8069e13ae05ce7b139d9ba4dc5c4480e5ff6956bb22787fccc6c9c45927a91e018aa4cf5129412

  • /data/misc/profiles/cur/0/pkmast.pk.yonosbipannel_new/primary.prof
    Filesize

    1KB

    MD5

    8fc50e2e9a8973a5472b571679193472

    SHA1

    5c41be786750f4dc09ba628412c5cf0181fe5daf

    SHA256

    91d99eae9c72a8fd611cf2c5397131f7b6f7d9ef970ea88627430f0328699c94

    SHA512

    62c0631e26ccbde92ece58143075bdfa99553204390fa8a0511a46557f1f2e74e82a354150057b6558cca629883ed5d94af706381054636b1a17a3f143e7d783