MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9624131c01da6d5b61225a465a83efd32291fa3f2352445c3c052d9d8cfb2daa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FluBot


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 9624131c01da6d5b61225a465a83efd32291fa3f2352445c3c052d9d8cfb2daa
SHA3-384 hash: 9bd0db407b3a8a12a8ac6619078dfb75a507cb101d6c66d1cf3e138287cbfb74714bf32a355d8ae53c5afc546042e4e6
SHA1 hash: 949fe441372aad3c1212cc9c09641074f5dd3269
MD5 hash: d7f56c6c1f77ea488e7f0ac18d3b7ffd
humanhash: friend-robert-carbon-lima
File name:Voicemail89.apk
Download: download sample
Signature FluBot
File size:4'391'872 bytes
First seen:2021-09-07 10:48:07 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 98304:kHVEQyY6+r+a37N8U6xJPS8DWNJftpcZOGVSrH9923EVl:kHGHPLa3hDhwmJQIrH9923yl
TLSH T1E5162211BEAEE427D047E0359365E5A7990C844C8A2AFD1F6E22914C4DFBC05AB0BFDD
Reporter _TripleE_
Tags:apk FluBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
208
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.evad
Score:
64 / 100
Signature
Detected FluBot
Kills background processes
Multi AV Scanner detection for submitted file
Uses accessibility services (likely to control other applications)
Behaviour
Behavior Graph:
n/a
Threat name:
Android.Dropper.Hqwar
Status:
Malicious
First seen:
2021-08-23 19:41:38 UTC
AV detection:
9 of 28 (32.14%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
android obfuscation
Behaviour
Uses reflection
Loads dropped Dex/Jar
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments