Clicky

Friday, February 6, 2015

DSEncrypt Android sample


Research: Fireye. What are you doing? – DSEncrypt Malware
Sample Credit: Claud Xiao

Size: 1794848
MD5:  568D40CCD7B91951715AC4079A860128


Download. Email me if you need the password







https://www.virustotal.com/en/file/b103f3897b1619dee157e62a1737e864452a85bab613ad971ac6193b3f6a4834/analysis/
MD5 568d40ccd7b91951715ac4079a860128
SHA1 c1ebb205b0c5350b1adb091eba4d3fa92b78b645
SHA256 b103f3897b1619dee157e62a1737e864452a85bab613ad971ac6193b3f6a4834
ssdeep49152:kUzB9t6A3bp+6vUZ4ZG/SWqk0/pqytjbfzzbP3W:kUzB9td3bFeiDTkydrbvW
File size 1.7 MB ( 1794848 bytes )
File type Android
Magic literalZip archive data, at least v2.0 to extract
TrID Android Package (92.9%)
ZIP compressed archive (7.0%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)

Antivirus Result Update
AVware Trojan.AndroidOS.Generic.A 20150204
Ad-Aware Android.Trojan.FakeInst.JZ 20150204
AegisLab Wroba 20150204
Alibaba A.H.Pri.Nbank 20150203
Avast Android:DSEncrypt-B [Trj] 20150204
Avira Android/Kaka.E.Gen 20150204
Baidu-International Trojan.Win32.Banker.adin 20150204
BitDefender Android.Trojan.FakeInst.JZ 20150204
CAT-QuickHeal Android.Wroba.M 20150204
Comodo UnclassifiedMalware 20150204
Cyren AndroidOS/GenBl.568D40CC!Olympus 20150204
DrWeb Android.MulDrop.21.origin 20150204
ESET-NOD32 a variant of Android/TrojanDropper.Agent.N 20150204
Emsisoft Android.Trojan.FakeInst.JZ (B) 20150204
F-Secure Trojan:Android/WroBa.D 20150204
Fortinet Android/Wroba.I!tr 20150204
GData Android.Trojan.FakeInst.JZ 20150204
Ikarus Trojan-Spy.AndroidOS.Wiurse 20150204
K7GW Trojan ( 0049a9941 ) 20150204
Kaspersky HEUR:Trojan-Banker.AndroidOS.Wroba.i 20150204
McAfee Artemis!568D40CCD7B9 20150204
MicroWorld-eScan Android.Trojan.FakeInst.JZ 20150204
NANO-Antivirus Trojan.Android.Agent.dgegrd 20150204
Qihoo-360 Trojan.Generic 20150204
Sophos Andr/FakeKRB-O 20150204
Tencent a.privacy.nbank.[????] 20150204
VIPRE Trojan.AndroidOS.Generic.A 20150204
Zoner Trojan.AndroidOS.Agent.N 20150202

No comments:

Post a Comment