Analysis

  • max time kernel
    174s
  • max time network
    130s
  • platform
    android_x86
  • resource
    android-x86-arm-20240624-en
  • resource tags

    androidarch:armarch:x86image:android-x86-arm-20240624-enlocale:en-usos:android-9-x86system
  • submitted
    01-07-2024 02:19

General

  • Target

    c816d7513cb36becac080698ee3937bccfc5f8f3b2b0a436c8b46f7f0635197b.apk

  • Size

    3.7MB

  • MD5

    af60591348229c9ac3400cf47db0d146

  • SHA1

    8a0233bf2c6272b085daade9c6fa6f3a32708467

  • SHA256

    c816d7513cb36becac080698ee3937bccfc5f8f3b2b0a436c8b46f7f0635197b

  • SHA512

    4c9e01cc6568d7d31d8ca7c28d7d8e5726b649c1caf323175cb33a9e2e703ea166fd030a19e230df1b8a3e22db375c7c49fa40d6bd1c9f90168ecd8b23c18b03

  • SSDEEP

    98304:N9m7hsS4M8HR2/LXL+Jhwcxgv/q7xyvwNI8MG/koZOU1iEOVdJ5l7kfBNjF:O7iS4rHR2/LXyJhwrvKCiI8MGsoMy

Malware Config

Signatures

  • Checks if the Android device is rooted. 1 TTPs 1 IoCs
  • Queries information about active data network 1 TTPs 1 IoCs
  • Registers a broadcast receiver at runtime (usually for listening for system events) 1 TTPs 1 IoCs
  • Uses Crypto APIs (Might try to encrypt user data) 1 TTPs 1 IoCs

Processes

  • Aktualizacja.apps
    1⤵
    • Checks if the Android device is rooted.
    • Queries information about active data network
    • Registers a broadcast receiver at runtime (usually for listening for system events)
    • Uses Crypto APIs (Might try to encrypt user data)
    PID:4245

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • /data/data/Aktualizacja.apps/files/libaudio.so
    Filesize

    66B

    MD5

    1823c7963e5cd61c4571660a045baa05

    SHA1

    fdbb8d161e99a257cb11c758dfeddbf5aae1092b

    SHA256

    e24978236cfc611894c665b15108d177cec60d7de5c7149dc859550de705c36d

    SHA512

    222817bead9f4ca86ec517da570e734dbcb739850259046794567b3aef2cbb14e4b299ed2421f2f87a82d2e6b7ae633d5eb0ed1a934736111eb7ecb07810e31c

  • /data/data/Aktualizacja.apps/files/libaudio.so
    Filesize

    149B

    MD5

    62883166aca64b512990a27a1d88df42

    SHA1

    109aed6da330abb70fbd1a0a6cb879e06555035c

    SHA256

    5f26b4065e1afec38c3a141c4357f1d39e91b345e30861a55aa2003418a5d694

    SHA512

    3e8853e70eaeb27bb7f169ad1518874e3d801303f6dfec47bcf686a3a85d08458ea78da68191ee2e767c0b8a2347852728ee73054bb76585cc57d7f9cf79d436

  • /data/data/Aktualizacja.apps/files/libaudio.so
    Filesize

    76B

    MD5

    ea0c5aa8d05d9df043b280bbeecf476f

    SHA1

    4a1218cc47e68085fb773d3b36cebb3000e0d1a7

    SHA256

    fcb1cfd2f84d21946b0a81467310dfbbafe239b697589639b277f8d536db487e

    SHA512

    b425b9b16c41e267480454d3468a81e8adf7badfd113e661c7cf50c1ede84691c67c5aeddbd207074d82d105c69373161b897c4b2ce05b76a2a39ce7539d89ca

  • /data/data/Aktualizacja.apps/files/libaudio.so
    Filesize

    76B

    MD5

    e049f345ced71756099918e6e3289e8b

    SHA1

    c830ebc9085304388ec63891ba8fce983e9b484c

    SHA256

    081e70c8c62b015759be9d8ea24df66648801f2ad43452f987250ec62e60a28b

    SHA512

    34680745885c683bfb64b70844bdc1360813b08ea0b7a8a575dca1f5376dfe8d110fff2c6e593735db71f363b066eee9d5ac1ef2ec01242d2e6cf4c9b78a27e8

  • /data/data/Aktualizacja.apps/files/libaudio.so
    Filesize

    116B

    MD5

    7a65a228b1202d212932e744c4e123cf

    SHA1

    940252eae04aa86cab515a5508d684b68b727639

    SHA256

    f0783915fca65bb8d2b3a6628323cdaff8fb90ac17dab08eaa1b9ce98f1d805a

    SHA512

    00cdcb944b7a54622f83dd9e4792c6fb0783cb644f38603b3cf71e8c484b161c2637c11d06f4b4fc37e6c6ce9c0e75fb89a644f936ed0478695d2824e53f67d0