MMRat
Malware family · 5 sample(s) · 5 indicator record(s) · 1 signing certificate(s)
About MMRat
Android banking trojan carrying out bank fraud via fake app stores, abusing the RTSP stack for its C2 channel: the endpoints are rtsp:// const-strings in the <init> of the short helper classes under com/mm/user/utils/. Identified by the com.mm.user.ui.activity.WebViewActivity activity.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| 202.95.15.135:8554/live/display/ | ip | d06fc998c4aa… | 2023-08-07 |
| 202.95.15.135:8554/live/display/ | ip | 124d3a55770d… | 2023-09-03 |
| 202.95.15.135:8554/live/display/ | ip | 51847406cf99… | 2023-07-26 |
| 27.124.3.165:8554/live/ | ip | 68abbf83f53f… | 2023-06-19 |
| 45.61.128.113:8554/live/display/ | ip | ac2f69c3b940… | 2023-08-07 |