Analysis

  • max time kernel
    167s
  • max time network
    131s
  • platform
    android_x86
  • resource
    android-x86-arm-20240624-en
  • resource tags

    androidarch:armarch:x86image:android-x86-arm-20240624-enlocale:en-usos:android-9-x86system
  • submitted
    02-07-2024 05:26

General

  • Target

    1e23a853a7d8694fd4d7d5b752a5f200_JaffaCakes118.apk

  • Size

    276KB

  • MD5

    1e23a853a7d8694fd4d7d5b752a5f200

  • SHA1

    b9fda9610f6b11616d7834a7f6a28447a603c8a2

  • SHA256

    f25766c3780d9b757a02e44678eec92aaa9e19f1b49980472ad3cd2a7fda87e6

  • SHA512

    243d555623ba5b4ccd3f4bd00450ed25adf7e5c2c14f79408112819e40bc4efae711fec9bbc2c9514452841cd5a93b356934a3933c144a08a61c47ff3675e954

  • SSDEEP

    6144:WiuKlMUzrxVBLc1YAlaXUI/igAdgzey7FDNaw4IzEsS/ZXBc2UA5fN4:duYMs7ucdigAdgRlNa/IvcRgE4

Malware Config

Signatures

  • Registers a broadcast receiver at runtime (usually for listening for system events) 1 TTPs 1 IoCs
  • Schedules tasks to execute at a specified time 1 TTPs 2 IoCs

    Application may abuse the framework's APIs to perform task scheduling for initial or recurring execution of malicious code.

Processes

  • com.lima.iiuvk.sprylqiq
    1⤵
    • Registers a broadcast receiver at runtime (usually for listening for system events)
    • Schedules tasks to execute at a specified time
    PID:4241
  • com.lima.iiuvk.sprylqiq:RemoteProcess
    1⤵
      PID:4293
    • com.lima.iiuvk.sprylqiq:guard
      1⤵
      • Schedules tasks to execute at a specified time
      PID:4503

    Network

    MITRE ATT&CK Matrix

    Replay Monitor

    Loading Replay Monitor...

    Downloads

    • /data/data/com.lima.iiuvk.sprylqiq/app_tfile/fields.jar
      Filesize

      151KB

      MD5

      07f164db880c1b6691b5c54862e9a3c4

      SHA1

      6dd9102eff0b0134fb9bbafd0122bfae719565fd

      SHA256

      2e6db810857d45da5ea6f084812401401f0f7a2bd6e7c3a7a96c7d46995551fe

      SHA512

      46bec2510d5ed27d54248f32556d2b7969d0e2557f17fe2f1f6f18177e2dbfc42598cfe555d44b38a2bc2480212aec036f4a4df392ca39dafe09a830b03f93f9