d06fc998c4aa6a7abd294aa3…

sample

Tracked by C2 Tracker · indicators & metadata only, the APK itself is never published

Identification

SHA-256
d06fc998c4aa6a7abd294aa3e5edb566ef2097f897c23c5fe0b34a2c2ea3bd46
MD5
ec0a5270bac7b8da85f1276c85659213

Observed

Families
MMRat
First seen
2023-08-07

C2 configuration (1)

Every indicator extracted from this sample. One row per C2 — each links to its indicator page with Whois, DNS and certificate pivots.

IndicatorTypePortSchemeFamilyFirst seen
202.95.15.135/live/display/ ip 8554 rtsp MMRat 2023-08-07

Signing certificate

Subject CN
123456
Issuer CN
123456
Fingerprint
e4e4b72303db373702d41505a1203eb31f5e759bab62a4c2139cc69c6baf8974

Relationships

Sample → C2 indicators, signing certificate (with every other sample signed by it) and family. Click a node for details, double-click to open its page.

Click a node to inspect it.

About MMRat

Android banking trojan carrying out bank fraud via fake app stores, abusing the RTSP stack for its C2 channel: the endpoints are rtsp:// const-strings in the <init> of the short helper classes under com/mm/user/utils/. Identified by the com.mm.user.ui.activity.WebViewActivity activity.