MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2de70ca737c1f4602517c555ddd54165432cf231ffc0e21fb2e23b9dd14e7fb4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Triada


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments 1

SHA256 hash: 2de70ca737c1f4602517c555ddd54165432cf231ffc0e21fb2e23b9dd14e7fb4
SHA3-384 hash: ed9269762c4184b37525852557faf95741c40a94d756e4e2eca9367cc86a4b932b0a187818d2e6a3f6294e949fc3a1bc
SHA1 hash: 5eb26f69caa5fc281eaba466ead6a968545eab4f
MD5 hash: 06b80586f3db28fd0886c68d327e6d6d
humanhash: alaska-missouri-jupiter-ohio
File name:MOD APK (Pro Unlocked) latest version.apk
Download: download sample
Signature Triada
File size:75'607'885 bytes
First seen:2025-02-28 22:38:25 UTC
Last seen:2025-05-19 20:32:48 UTC
File type: apk
MIME type:application/zip
ssdeep 1572864:J/2LZ1VbXhETM0kZlShysJPC2DLPwpJ08w:JaZLbRuk0TjH
TLSH T141F70193E32C9E9AD0F3D332A676C15268264CAC4707D3771D18B97D1BB39C3A60A9C5
TrID 30.8% (.APK) Android Package (27000/1/5)
24.5% (.OXT) OpenOffice Extension (21500/1/3)
15.4% (.JAR) Java Archive (13500/1/2)
12.5% (.CATROBAT) Pocket Code/Catroid Catrobat Project (11000/1/2)
12.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
Magika apk
Reporter aachum
Tags:apk signed Tirada Triada

Code Signing Certificate

Organisation:Android
Issuer:Android
Algorithm:sha1WithRSAEncryption
Valid from:2008-02-29T01:33:46Z
Valid to:2035-07-17T01:33:46Z
Serial number: 936eacbe07f201df
Intelligence: 1857 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
iamaachum
https://tria.ge/250228-2f1g7s1qv8/static1 => https://apkcomod.com/?title=Anydesk_Mod_APK => https://www.1024tera.com/spanish/sharing/link?surl=oAhxG8bYaUhtR_N8MK8Arw

Intelligence


File Origin
# of uploads :
2
# of downloads :
156
Origin country :
ES ES
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
fingerprint persistence signed
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:triada android discovery execution impact persistence upx
Behaviour
Checks memory information
Registers a broadcast receiver at runtime (usually for listening for system events)
Schedules tasks to execute at a specified time
Uses Crypto APIs (Might try to encrypt user data)
UPX packed file
Acquires the wake lock
Queries information about active data network
Reads information about phone network operator.
Patched UPX-packed file
Verdict:
Informative
Tags:
n/a
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Triada

apk 2de70ca737c1f4602517c555ddd54165432cf231ffc0e21fb2e23b9dd14e7fb4

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
commented on 2025-02-28 22:39:33 UTC

Wrongly pasted tria.ge link in the description when it should be https://github.com/kjueo/derosk/blob/main/Anydesk%20Mod%20APK%20Download%20Latest%20Version%20-%20(p1f3r).md