Analysis

  • max time kernel
    154s
  • max time network
    144s
  • platform
    android_x86
  • resource
    android-x86-arm-20240624-en
  • resource tags

    androidarch:armarch:x86image:android-x86-arm-20240624-enlocale:en-usos:android-9-x86system
  • submitted
    03-07-2024 22:01

General

  • Target

    18db090d98b4ee6d95cdd49eecfce7825a27df6a5dde6071f69635277a0fdc57.apk

  • Size

    1.8MB

  • MD5

    d57981eb8486459fdefc0cd250e6ec19

  • SHA1

    53142e4ca1093d39d618569495e1e225d86ee91c

  • SHA256

    18db090d98b4ee6d95cdd49eecfce7825a27df6a5dde6071f69635277a0fdc57

  • SHA512

    1d1b260564770496bc0cddfa19e705dcdfc84ea79db94b8dde6386fbdefe8c3fbed40fd6cf8e8fedcc7ff644ef35b223f0296a56212ab3969e8067c959b1753d

  • SSDEEP

    24576:bY1lJJrSINXEO3IouJp8P9KSDS6YOOXDtXUFLwKpG4Sj3gezmMY64XR4FjHwD3L:bY1lfx3IPa4m2OK/QSoMBlu

Malware Config

Signatures

  • Makes use of the framework's Accessibility service 4 TTPs 2 IoCs

    Retrieves information displayed on the phone screen using AccessibilityService.

Processes

  • org.zzzz.aaa
    1⤵
    • Makes use of the framework's Accessibility service
    PID:4318

Network

MITRE ATT&CK Matrix

Replay Monitor

Loading Replay Monitor...

Downloads

  • /data/data/org.zzzz.aaa/files/profileInstalled
    Filesize

    24B

    MD5

    798459e77f5f1d6a6c5eae93d5063891

    SHA1

    99e28f59daa601f83e19bca24559c2ae1fe31832

    SHA256

    fdbd570efdfbe32a662127ae3a14d1b611e46d5f9317f70a8aef4758a80877f1

    SHA512

    19ada353fca7ab4d4d9745fdfeab0fc50e7a5f94f0b6cf8e6d51f09734b8158373155847426bc462cc7b8495e0cfb9ad9b80688e0f9070fd0008e7bd1790e1b7

  • /data/data/org.zzzz.aaa/files/profileinstaller_profileWrittenFor_lastUpdateTime.dat
    Filesize

    8B

    MD5

    9daa752ade169fb8b2779e54851e6534

    SHA1

    52117f8be5a2f8e8e1f3a55e7822462e993993f9

    SHA256

    4cb5939b30d9c54d31a444a2b64ba064898b9a45374460fe223d791a73734fe5

    SHA512

    3848cedb8509524c791d5d417900ac98f71a4768c3d1cfa6f3ff33cb2dc08119316fc642987a3d58ec97b0c29880d95710b5ec4dd0ff9cd1fa1f032f22a6cabe

  • /data/misc/profiles/cur/0/org.zzzz.aaa/primary.prof
    Filesize

    1KB

    MD5

    c808cf32b66c19d7d1c0ee8622567e71

    SHA1

    4487b4de0b5055d076885c91a158054b41d3a5a2

    SHA256

    3f68d32bde60ff4f3259b49507a4bd48d61804a2d19cf7706de98a323578b37c

    SHA512

    faa157d709c609f10ebd6067cc55af620a8d06bdccf80d83083c0fcce5c1596341ff26447c680b753abb2eecf95a4431416bac8fa715b3248dd9edaf2d04b0d6

  • /data/misc/profiles/cur/0/org.zzzz.aaa/primary.prof
    Filesize

    2KB

    MD5

    9b8bfbe222e64178f767205f656830dc

    SHA1

    f6889b9b688eeddbf2eb16c19c8142e4408222a2

    SHA256

    e242cefd36c5122d0b9c7961e32d9dd8ee4bb027a74297cfcaede14614c9c290

    SHA512

    cd917066a1ddf70ec50b8417d96aeb5a300754154344c08b82be0eea742555d93e3cb47625769958f491f1c30eebf2bbad815eb971a848bce58d04fa96b86bd3