MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 36f40d5a11d886a2280c57859cd5f22de2d78c87dcdb52ea601089745eeee494. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



SLocker


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 36f40d5a11d886a2280c57859cd5f22de2d78c87dcdb52ea601089745eeee494
SHA3-384 hash: 7b355b85cbe20f95c8ec40c944ebaef9a6a23038814f564cba581c5d03b4f9bc1b1a8a0b8c8419fdf3acdb305d5a6ff6
SHA1 hash: ca2e7c66b9eedf95f51204cea8cd2e13ba2a5d93
MD5 hash: 8ce42ae8f1206130aeadaa7cad062aca
humanhash: leopard-hydrogen-maine-fourteen
File name:36f40d5a11d886a2280c57859cd5f22de2d78c87dcdb52ea601089745eeee494.apk
Download: download sample
Signature SLocker
File size:2'046'192 bytes
First seen:2024-03-14 00:12:21 UTC
Last seen:2025-05-27 08:55:00 UTC
File type: apk
MIME type:application/zip
ssdeep 49152:q7PtjuZTUx4vhFm8ynE8F4+jVlWC6ec8RwWwUjtZ:SP1uZTpDm8yn549C6J0wWB
TLSH T16E9512D3A701AC6ECC3C4A3652960B39670B9F256AB7630704443B6D3D7BAC84F989DD
TrID 72.9% (.JAR) Java Archive (13500/1/2)
21.6% (.ZIP) ZIP compressed archive (4000/1)
5.4% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter MrMalware
Tags:android apk Locker Ransomware signed SLocker

Code Signing Certificate

Organisation:873472648
Issuer:873472648
Algorithm:sha256WithRSAEncryption
Valid from:2017-01-04T12:01:10Z
Valid to:2116-12-11T12:01:10Z
Serial number: 01
Intelligence: 454 malware samples on MalwareBazaar are signed with this code signing certificate
Cert Graveyard Blocklist:This certificate is on the Cert Graveyard blocklist
Thumbprint Algorithm:SHA256
Thumbprint: eaa9f05aeab23ec28bbc651205691722f29e9075a163a2e9d044a0d7f142fa37
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
5
# of downloads :
884
Origin country :
CL CL
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
android lockscreen wannacry wannalocker
Result
Application Permissions
mount and unmount file systems (MOUNT_UNMOUNT_FILESYSTEMS)
read external storage contents (READ_EXTERNAL_STORAGE)
read sensitive log data (READ_LOGS)
read phone state and identity (READ_PHONE_STATE)
retrieve running applications (GET_TASKS)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
view network status (ACCESS_NETWORK_STATE)
change your audio settings (MODIFY_AUDIO_SETTINGS)
set wallpaper (SET_WALLPAPER)
view Wi-Fi status (ACCESS_WIFI_STATE)
full Internet access (INTERNET)
prevent phone from sleeping (WAKE_LOCK)
change your UI settings (CHANGE_CONFIGURATION)
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Removes its application launcher (likely to stay hidden)
Behaviour
Behavior Graph:
n/a
Threat name:
Android.Trojan.SLocker
Status:
Malicious
First seen:
2017-06-10 02:40:00 UTC
File Type:
Binary (Archive)
Extracted files:
340
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Result
Malware family:
slocker
Score:
  10/10
Tags:
family:slocker android
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:adonunix2
Author:Tim Brown @timb_machine
Description:AD on UNIX

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments