🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca0d2a1f8081e66130801082ced73f04b8ac4f33adf6de58d4ca2a84bb6d799b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ca0d2a1f8081e66130801082ced73f04b8ac4f33adf6de58d4ca2a84bb6d799b
SHA3-384 hash: 0804148c3e38bed093f03ea1a35f624ef086213095c9bfd74030ce1bcf867b38f3ca90b3ef40c61fb76db9468737f3e3
SHA1 hash: 9cbe8496d7a9bf177279b8970d10bf7c1c633dc5
MD5 hash: d01b86faa1c7265b55edcfde4099c2d5
humanhash: lactose-ack-quebec-mars
File name:Sana.apk
Download: download sample
File size:1'379'127 bytes
First seen:2022-05-26 11:25:15 UTC
Last seen:Never
File type: apk
MIME type:application/java-archive
ssdeep 24576:NOWuKYfLwXIpaW2vcJKkYtHd/pWb2gN6rcNcq0Yj1V506irr1Ica8uPbExu1w7ML:NInz8YLgPxWb2gN6rec2r506mBgnjE0L
TLSH T1FD55234BFD9BF046DA43543B90B4E113458A430F5C8ABD1B3BDC09A40AF2E927A57F69
TrID 60.1% (.APK) Android Package (38500/1/9)
21.0% (.JAR) Java Archive (13500/1/2)
10.9% (.MAFF) Mozilla Archive Format (gen) (7000/1/1)
6.2% (.ZIP) ZIP compressed archive (4000/1)
1.5% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter onecert_ir
Tags:apk iran malware phishing signed sms SmsSpy spy spyware

Code Signing Certificate

Organisation:Android
Issuer:Android
Algorithm:sha1WithRSAEncryption
Valid from:2008-02-29T01:33:46Z
Valid to:2035-07-17T01:33:46Z
Serial number: 936eacbe07f201df
Intelligence: 1875 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
onecert_ir
Malware Phishing system of Electronic Judicial Services System Iran.

Intelligence


File Origin
# of uploads :
1
# of downloads :
453
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
android mobilespy remote.exe smsspy smsthief spyagent update.exe
Result
Threat name:
Unknown
Detection:
malicious
Classification:
spyw.evad
Score:
64 / 100
Signature
Antivirus / Scanner detection for submitted sample
Drops a new APK file
Multi AV Scanner detection for submitted file
Removes its application launcher (likely to stay hidden)
Behaviour
Behavior Graph:
n/a
Threat name:
Android.Trojan.SmsThief
Status:
Malicious
First seen:
2022-04-28 03:26:00 UTC
File Type:
Binary (Archive)
Extracted files:
122
AV detection:
11 of 26 (42.31%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
android evasion
Behaviour
Removes a system notification.
Reads information about phone network operator.
Acquires the wake lock.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

apk ca0d2a1f8081e66130801082ced73f04b8ac4f33adf6de58d4ca2a84bb6d799b

(this sample)

  
Dropping
smsspy
  
Delivery method
Distributed via web download

Comments