PULSE NAME
system.img - Unidentified Android Ext4 filesystem pulled from my machine
WHITE Merkd1904 2024-05-31 Modified: 2024-05-31
2063
IOCs
HIGH VOLUME
Honestly I can't recall where I fished this out of, but I had stashed it on a cloud storage drive for later exploitation, which is what this is. At current, I don't have the slightest clue what it is or what it was doing on my computer. But with majority of the */bin/ files coming back as symlinks to */bin/toybox I'm assuming it's nothing that'd enhance my day to day life for the better. Standby for further analysis. At current these are just the SHA256's of the filesystem itself.
Indicators of Compromise (1 / 2063 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 562f65566ca95a89b9fc50917f6cdd48e4434bcb SHA1 of 423765ffda6a6bb311166f41c91b3fbdf06c06b5616bc9146ac6172a9c805a51 2024-05-31