Managed XDR

23377_rehashed.apk — malware analysis report

File info

Filename
23377_rehashed.apk
File type
Zip archive data, at least v2.0 to extract
File size
1.5 MB
First seen
Last seen

Environment

droid7/x86 ru

Hashes

SHA1
9b33a91f5c8b0ea17dde921bcefcbfc7d2481601
SHA256
df096deb86121239ee8332be356cb47a3c47398cbf8bca775e009e2342cfae3a
MD5
cc1274948304fda99d0e10a01e1fb671

Signatures

Other

yara_rules: Static rules
coper: Coper banking trojan
dexclassloader: Uses class loader to executre dynamic code
metrics: Be used to get information from the screen
is_device_admin: Check accessibility - device admin
dynamic_load: Uses undocumented methods to load apk/dex/classes
acquire: Acquires the wake lock
skip_main_activity: Abort loading MainActivity
accessibility_event: Intercepting Accessibility Events
super_user: Checks root access
get_line1_num: Gets phone number
wake_lock: Creates a new wake lock
telephony_getsimcountryiso: Access country code of SIM
dex_elements: Modifies classes path (possibly, dynamic code loading)
reflection: Uses reflection
framework_check: Checks frida/xposed/substrate
wifi_info: Gets wifi connections data
sim_operator_name: Fetches SIM-SPN
register_receiver: Registers broadcast receiver
browsed_history: Reads web browser history
send_sms: Sends http request
network: Checks internet connection
read_or_write_global_settings: Read or write global settings
shared_prefs: Uses shared preferences
change_state_wifi_signature: Changes the state of Wi-Fi connection
read_or_write_system_settings: Read or write system settings
trowable: Throwable exceptions
start_activity: Starts activity
load_jni_lib: Loads native library
start_service: Starts service
keyguard_manager: Interaction with Keyguard Manager
alarm_manager: Sets a timer
access_network_state: Network state access
suricata_alert: Malicious traffic detected
read_or_write_secure_settings: Read or write secure settings
notify: Attempts to create a notification