MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 208d68c431d58e6d311ae0f2574fab85a1205fc1597e10690116bf406eb5499c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 208d68c431d58e6d311ae0f2574fab85a1205fc1597e10690116bf406eb5499c
SHA3-384 hash: 1daa9b347204e7c4535838763eec861e816936cb720694b7fdf68e5287679778eb02ea27ef742b3d9c15ceba650bfcc7
SHA1 hash: a86b16798fc4b3170c8c2a3a7a86525bbf50ce4b
MD5 hash: c996f6a2787e755bff241018f54c850b
humanhash: apart-avocado-failed-undress
File name:veradown.apk
Download: download sample
File size:15'219'806 bytes
First seen:2021-08-20 13:57:42 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 393216:jiF3sGLjtYwprTqD6k94ulTbG2qD9S45Y/WCCwkhL7Y6joH7H:43TjhlSJTbGjS4aQwCsL
TLSH T1DCE62244FFA0959AC47A723684ED09118AD35C86CC61961FBAACB58C0F739C41ED7BCB
Reporter Jagdtiger88mm
Tags:apk malware sextortion

Intelligence


File Origin
# of uploads :
1
# of downloads :
265
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Unknown
Detection:
malicious
Classification:
spyw.evad
Score:
64 / 100
Signature
Deletes other packages
Monitors outgoing Phone calls
Multi AV Scanner detection for submitted file
Queries the device phone number (MSISDN)
Removes its application launcher (likely to stay hidden)
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  8/10
Tags:
android
Behaviour
Checks Android system properties for emulator presence.
Loads dropped Dex/Jar
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments