General

  • Target

    701d6fecbf2156261c4933536c46854c3a89bb73b849775a0da32234415429f0.bin

  • Size

    4.6MB

  • Sample

    240701-1ywrassejg

  • MD5

    4f82a9e8a0b87bdf2be5433abe45f501

  • SHA1

    cfc37a47f3040ab82322c3dc6fa43f908a1d819f

  • SHA256

    701d6fecbf2156261c4933536c46854c3a89bb73b849775a0da32234415429f0

  • SHA512

    43c2000d745a14a218dc9984b33dc19e58ab3eed5227c4e1a7e879cab5779b26fb879889244eaf163397bb232b76324d890c682eb10edfdc7aa7f7381cba218e

  • SSDEEP

    98304:JMykAKXWmz+VEHWrB0PJqEgGHXNRVGGkxIiTHW2rKzuGqm:JrUXWS2l0PJq09RVGG90HTuzuGqm

Malware Config

Targets

    • Target

      701d6fecbf2156261c4933536c46854c3a89bb73b849775a0da32234415429f0.bin

    • Size

      4.6MB

    • MD5

      4f82a9e8a0b87bdf2be5433abe45f501

    • SHA1

      cfc37a47f3040ab82322c3dc6fa43f908a1d819f

    • SHA256

      701d6fecbf2156261c4933536c46854c3a89bb73b849775a0da32234415429f0

    • SHA512

      43c2000d745a14a218dc9984b33dc19e58ab3eed5227c4e1a7e879cab5779b26fb879889244eaf163397bb232b76324d890c682eb10edfdc7aa7f7381cba218e

    • SSDEEP

      98304:JMykAKXWmz+VEHWrB0PJqEgGHXNRVGGkxIiTHW2rKzuGqm:JrUXWS2l0PJq09RVGG90HTuzuGqm

    Score
    4/10
    • Target

      app.apk

    • Size

      3.9MB

    • MD5

      54402c807a9061e2f19e2b425f11e8fe

    • SHA1

      cea77af489505085b7da9c2db7534f574198ffdb

    • SHA256

      a01595815441b88680a0b3cec4ee86f56897fe389151db98d73c09fddac03227

    • SHA512

      acd29e0e7bf414e474bec049728247d295967963593047476a6f5696b9fa23a755600ee529b8e0ee546a630cc5c736d66f492fc2f9453621068770d8bc4e4da0

    • SSDEEP

      98304:8Gi8dluhgr7btsZgIVxXBBuO6YBOsZhM3Hc6cEXLM:8GJsinbtsXXBBuO6rahMSEo

    • Makes use of the framework's Accessibility service

      Retrieves information displayed on the phone screen using AccessibilityService.

    • Acquires the wake lock

    • Makes use of the framework's foreground persistence service

      Application may abuse the framework's foreground service to continue running in the foreground.

    • Performs UI accessibility actions on behalf of the user

      Application may abuse the accessibility service to prevent their removal.

MITRE ATT&CK Matrix

Tasks