Resubmissions

04-07-2024 23:33

240704-3j7w5ayakf 8

04-07-2024 23:28

240704-3gatlsvhrr 8

General

  • Target

    4374_ymusic_arm64.apk

  • Size

    9.1MB

  • Sample

    240704-3gatlsvhrr

  • MD5

    bb8b2754f3a734f4fbcb969dba913517

  • SHA1

    3dbd2d253b5bf38de8b20843079b6e55a2cdc33c

  • SHA256

    50cdaad0f6950610e351fda63c721002ae7ab987102895bf4f89d415e68615a0

  • SHA512

    9dfb7d3b67b234e2d5e432d480b996436d039226e6fca2c5be8629541ff049f1b5f5406090046b32a9b916147a18e9262fe8859eb71a16ad20ee9d69d95833b0

  • SSDEEP

    196608:w2DpxNTXiGI0Sxs3mukYP+LPyI1RiwriuBKsgw8dOJyzct3W:XpxNiYZkY2byIH7DMIKB

Malware Config

Targets

    • Target

      4374_ymusic_arm64.apk

    • Size

      9.1MB

    • MD5

      bb8b2754f3a734f4fbcb969dba913517

    • SHA1

      3dbd2d253b5bf38de8b20843079b6e55a2cdc33c

    • SHA256

      50cdaad0f6950610e351fda63c721002ae7ab987102895bf4f89d415e68615a0

    • SHA512

      9dfb7d3b67b234e2d5e432d480b996436d039226e6fca2c5be8629541ff049f1b5f5406090046b32a9b916147a18e9262fe8859eb71a16ad20ee9d69d95833b0

    • SSDEEP

      196608:w2DpxNTXiGI0Sxs3mukYP+LPyI1RiwriuBKsgw8dOJyzct3W:XpxNiYZkY2byIH7DMIKB

    • Checks if the Android device is rooted.

    • Acquires the wake lock

    • Looks up external IP address via web service

      Uses a legitimate IP lookup service to find the infected system's external IP.

    • Queries information about active data network

    • Checks the presence of a debugger

MITRE ATT&CK Matrix

Tasks