68abbf83f53fdcbd04e0d39d…
sampleTracked by C2 Tracker · indicators & metadata only, the APK itself is never published
Identification
- SHA-256
- 68abbf83f53fdcbd04e0d39dc2152b0c31ef663c0b042cc1e918836cf2b69f5e
- MD5
- d73bafe83b8f0b56f26cd2d1f06fd993
Observed
- Families
- MMRat
- First seen
- 2023-06-19
C2 configuration (1)
Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.
| Indicator | Type | Port | Scheme | Family | First seen |
|---|---|---|---|---|---|
| 27.124.3.165/live/ | ip | 8554 | rtsp | MMRat | 2023-06-19 |
Signing certificate
- Subject CN
- 123456
- Issuer CN
- 123456
- Fingerprint
- e4e4b72303db373702d41505a1203eb31f5e759bab62a4c2139cc69c6baf8974
Relationships
Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.
Click a node to inspect it.
About MMRat
Android banking trojan carrying out bank fraud via fake app stores, abusing the RTSP stack for its C2 channel: the endpoints are rtsp:// const-strings in the <init> of the short helper classes under com/mm/user/utils/. Identified by the com.mm.user.ui.activity.WebViewActivity activity.