MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d1340ed4d24a213ba11b01cc35341c101b25f2317cff99093f428152a2fc634e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FluBot


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d1340ed4d24a213ba11b01cc35341c101b25f2317cff99093f428152a2fc634e
SHA3-384 hash: 1d7abf587bed15c2b405fe95b282168f33d23f317ecc19ada74b41b7411dc1334968b15e7fc5dc9e67095dd85acbefd0
SHA1 hash: 8dbe6385738c51819a9834611eb415f1eea9afab
MD5 hash: 1378457ca7e2373c450c9422eb9ca866
humanhash: rugby-lion-video-texas
File name:Voicemail92.apk
Download: download sample
Signature FluBot
File size:3'998'656 bytes
First seen:2021-09-07 10:27:23 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 98304:zmWywxtERg3J0i4eGsuTDXYoLaJWfqY1Lv:zmfEaPeGsuTjY7Y1Lv
TLSH T14406231DFEAEE426E007F539D1E4958B5808849C4E46FA0B1A35928C4EFBD44A707FDD
Reporter _TripleE_
Tags:apk FluBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
207
Origin country :
n/a
Vendor Threat Intelligence
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.evad
Score:
68 / 100
Signature
Detected FluBot
Drops a new APK file
Kills background processes
Multi AV Scanner detection for submitted file
Uses accessibility services (likely to control other applications)
Behaviour
Behavior Graph:
n/a
Threat name:
Android.Dropper.Hqwar
Status:
Malicious
First seen:
2021-08-15 13:04:36 UTC
AV detection:
9 of 28 (32.14%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:flubot android banker infostealer obfuscation trojan
Behaviour
Uses reflection
Loads dropped Dex/Jar
FluBot
FluBot Payload
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments