🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8fb42bb9061ccbb30c664e41b1be5787be5901b4df2c0dc1839499309f2d9d93. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 8fb42bb9061ccbb30c664e41b1be5787be5901b4df2c0dc1839499309f2d9d93
SHA3-384 hash: 6ae46d0e23b72de920c91e226c20abc60761a57ea65ac980954e4441a60e007c4ce277138bb3a4caf1ecc1863e54e7a3
SHA1 hash: 95f08250ac90aabb4c94811d75e34cedabdcaf62
MD5 hash: 71b63d2c839c765f1f110dc898e79d67
humanhash: snake-robert-july-alanine
File name:SecureTalk.apk
Download: download sample
File size:2'104'948 bytes
First seen:2021-12-13 13:32:59 UTC
Last seen:2021-12-13 13:33:23 UTC
File type: apk
MIME type:application/zip
ssdeep 49152:eZdja2OsPJku4CpTuLg4tUgiztvWF2jTG:eZdj1vJkQ4Xe9TG
TLSH T195A50188EF85AD1FCDF794320BA7462611620E8BDA82D713786C721C5FB77940EA5EC4
Reporter Jagdtiger88mm
Tags:apk APT37 signed

Code Signing Certificate

Organisation:Nastcha
Issuer:Nastcha
Algorithm:sha256WithRSAEncryption
Valid from:2020-08-06T02:33:14Z
Valid to:2045-07-31T02:33:14Z
Serial number: 2eef1e3b
Thumbprint Algorithm:SHA256
Thumbprint: a581a920613914f610aa548f1bea2055eb6530b23546bc3c323192e2ef565541
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
329
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Result
Threat name:
Unknown
Detection:
malicious
Classification:
spyw.evad
Score:
64 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Removes its application launcher (likely to stay hidden)
Requests to ignore battery optimizations
Behaviour
Behavior Graph:
n/a
Threat name:
Android.Spyware.Chinotto
Status:
Malicious
First seen:
2020-09-29 16:26:15 UTC
File Type:
Binary (Archive)
Extracted files:
251
AV detection:
16 of 45 (35.56%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
android
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments