Please welcome the new section of Contagio - CONTAGIOminiDUMP.BLOGSPOT.COM
The old mobile malware Mini-dump (aka "Take a sample, leave a sample"
) grew too large and difficult to use. This section will allow better
organization of all the mobile malware. There are not that many samples
but it is steadily growing.
This is a work in progress and please send or post your comments regarding the design, hosting, organization and such.
Many thanks to Tim Strazzere for catalyzing the upgrade :)
You will be able to access the new location from contagio - it won't be too hard to find.
~ Mila
Showing posts with label - MOBILE MALWARE. Show all posts
Showing posts with label - MOBILE MALWARE. Show all posts
Monday, July 11, 2011
Friday, July 8, 2011
Take a sample, leave a sample. Mobile malware mini-dump - July 8 Update
This post and all mobile malware moved to contagiominidump.blogspot.com
I frequently get requests for already published on Contagio mobile malware and also new files that might be mentioned in the media and blogs. I do not really have a large collection of mobile malware but I welcome the submissions.
Here is a folder with the most recent files I have. If you use upload feature on the blog (see below) and send more mobile malware samples, they will be added to this folder for everyone to come and use.
Download
Download files from the mobile malware mini-dump (new link)use infected for the password
Current list (~50+ downloads = around 200 individual files as of June, 2011). Hyperlinks lead to Virustotal
Download from the dump link above or click on "download" link if present
- Zitmo Android Edition (Zeus for mobile) ecbbce17053d6eaf9bf9cb7c71d0af8d Download (thanks to anonymous, July 8, 2011) Zitmo hits Android Axelle Apvrille- Fortinet
- GoldDream.A BloodvsZombie_com.gamelio.DrawSlasher_1_1.0.1.apk b87f2f3a927bf967736ed43ca2dbfb60 (many thanks for the sample to oren@avg-mobilation July 6,2011) Download Read more:Security Alert: New Android Malware -- GoldDream -- Found in Alternative App Markets Xuxian Jiang
- GoldDream.B v1.0_com.GoldDream.pg_1_1.0.apk f66ee5b8625192d0c17c0736d208b0b (many thanks for the sample to oren@avg-mobilation July 6,2011) Download Read more: Security Alert: New Android Malware -- GoldDream -- Found in Alternative App Markets Xuxian Jiang
- DroidKungFu2 -A _com.allen.txthej_1_1.0 F438ED38B59F772E03EB2CAB97FC7685 (many thanks for the sample to oren@avg-mobilation July 3,2011) Download Read more: Security Alert: New DroidKungFu Variants Found in Alternative Chinese Android Markets
- DroidKungFu2 -B __com.tutusw.onekeyvpn_7_1.1.6_54bc7a8fb184884a26e4cce74697d3a5 (many thanks for the sample to oren@avg-mobilation July 3,2011) Download Read more: Security Alert: New DroidKungFu Variants Found in Alternative Chinese Android Markets
Monday, August 30, 2010
Mobile Malware Google Group. Mobile malware samples
Update January 21, 2011 - they exchange samples there and have active discussions. I do not post those samples here, join the group if you need them.
If you are interested in mobile malware analysis, join the Mobile Malware Group (Adam Russell is the moderator/founder and he is processing the requests)
If you are interested in mobile malware analysis, join the Mobile Malware Group (Adam Russell is the moderator/founder and he is processing the requests)
This group is intended as a service to the mobile malware research community as well as anyone interested in starting research in this growing field. As such, we are looking for discussions on various mobile systems such as the iPhone, Android, Symbian, and other mobile platforms. Discussions should target analysis of the malware, requests for samples of malware, technical reviews of new methods, and other related material and questions. My hope is that this community can grow and provide high quality, cogent information to new and veteran researchers alike. (- Adam Russell)
Description:
A mailing
list for researching mobile malware. This group allows material related to new
mobile malware samples, analysis, new techniques, questions pertaining to the
field, and other related material. Please describe yourself in short detail when
requesting to join. Thank you.
Saturday, August 28, 2010
Aug 27 SMS Send JAVA Mobile malware
I was planning to do something else tonight when my blackberry buzzed with a new message.Unfortunately, this was not the message I'd like to receive. ICQ spam is common and fairly predictable - invitations to new "cool chat rooms", offers to DDoS my competitors until they revert to using paper and pencil or spam every person on earth for pennies.This one offered a new 3D game called Little Tanks.
Download Tank_3d.jar 6fe6d19f61f2222421c2eda1f8c1dabe as a password protected archive (contact me if you need the password)
369506328 Теперь новые ТАНЧИКИ 3 Д на телефонах. Скачать можно по ссылке: http:/ /slil.ru/29608317/1326f51.4c78f7e8/Tank_3d.jar
* игра работает только на мобильных
369506328 Now new LITTLE TANKS 3D on phones. You can download it from this link http:/ /slil.ru/29608317/1326f51.4c78f7e8/Tank_3d.jar
* The game works only on mobile phones
Tank_3d\аларм наш
File name: Tank_3d.jar
http://www.virustotal.com/file-scan/report.html?id=bc06cf72c2b44f17808dff5b38373486346ea563220a6c7163e1e115f63f0040-1282962855
Submission date: 2010-08-28 02:34:15 (UTC)
Result: 17 /42 (40.5%)
AntiVir 8.2.4.46 2010.08.27 TR/SMS.J2ME.Smmer.f
Antiy-AVL 2.0.3.7 2010.08.26 Trojan/J2ME.Smmer
Avast 4.8.1351.0 2010.08.27 Other:Malware-gen
Avast5 5.0.594.0 2010.08.27 Other:Malware-gen
Comodo 5881 2010.08.28 UnclassifiedMalware
DrWeb 5.0.2.03300 2010.08.28 Java.SMSSend.185
Emsisoft 5.0.0.37 2010.08.27 Trojan-SMS!IK
F-Secure 9.0.15370.0 2010.08.28 Riskware:Java/SmsSend.Gen!A
GData 21 2010.08.28 Other:Malware-gen
Ikarus T3.1.1.88.0 2010.08.27 Trojan-SMS
Kaspersky 7.0.0.125 2010.08.28 Trojan-SMS.J2ME.Smmer.f
Microsoft 1.6103 2010.08.27 Trojan:Java/SMSer.I
NOD32 5403 2010.08.27 probably a variant of J2ME/TrojanSMS.Konov.L
PCTools 7.0.3.5 2010.08.28 Trojan.Gen
Symantec 20101.1.1.7 2010.08.28 Trojan.Gen
TrendMicro 9.120.0.1004 2010.08.27 TROJ_SMMER.B
TrendMicro-HouseCall 9.120.0.1004 2010.08.28 TROJ_SMMER.B
Additional informationShow all
MD5 : 6fe6d19f61f2222421c2eda1f8c1dabe
Download Tank_3d.jar 6fe6d19f61f2222421c2eda1f8c1dabe as a password protected archive (contact me if you need the password)
369506328 Теперь новые ТАНЧИКИ 3 Д на телефонах. Скачать можно по ссылке: http:/ /slil.ru/29608317/1326f51.4c78f7e8/Tank_3d.jar
* игра работает только на мобильных
369506328 Now new LITTLE TANKS 3D on phones. You can download it from this link http:/ /slil.ru/29608317/1326f51.4c78f7e8/Tank_3d.jar
* The game works only on mobile phones
Tank_3d\аларм наш
The file appears to be an sms sender like many. Donato Ferrante from InReverse analyzed a similar sample earlier this year.
http://www.virustotal.com/file-scan/report.html?id=bc06cf72c2b44f17808dff5b38373486346ea563220a6c7163e1e115f63f0040-1282962855
Submission date: 2010-08-28 02:34:15 (UTC)
Result: 17 /42 (40.5%)
AntiVir 8.2.4.46 2010.08.27 TR/SMS.J2ME.Smmer.f
Antiy-AVL 2.0.3.7 2010.08.26 Trojan/J2ME.Smmer
Avast 4.8.1351.0 2010.08.27 Other:Malware-gen
Avast5 5.0.594.0 2010.08.27 Other:Malware-gen
Comodo 5881 2010.08.28 UnclassifiedMalware
DrWeb 5.0.2.03300 2010.08.28 Java.SMSSend.185
Emsisoft 5.0.0.37 2010.08.27 Trojan-SMS!IK
F-Secure 9.0.15370.0 2010.08.28 Riskware:Java/SmsSend.Gen!A
GData 21 2010.08.28 Other:Malware-gen
Ikarus T3.1.1.88.0 2010.08.27 Trojan-SMS
Kaspersky 7.0.0.125 2010.08.28 Trojan-SMS.J2ME.Smmer.f
Microsoft 1.6103 2010.08.27 Trojan:Java/SMSer.I
NOD32 5403 2010.08.27 probably a variant of J2ME/TrojanSMS.Konov.L
PCTools 7.0.3.5 2010.08.28 Trojan.Gen
Symantec 20101.1.1.7 2010.08.28 Trojan.Gen
TrendMicro 9.120.0.1004 2010.08.27 TROJ_SMMER.B
TrendMicro-HouseCall 9.120.0.1004 2010.08.28 TROJ_SMMER.B
Additional informationShow all
MD5 : 6fe6d19f61f2222421c2eda1f8c1dabe
Tuesday, August 10, 2010
Trojan-SMS for Android
News
First SMS Trojan detected for smartphones running Android
First Trojan for Android Phones Goes Wild
Technical write up
Download Ru.apk (pass infected)
SEE OTHER ANDROID MALWARE AT CONTAGIOMINIDUMP.BLOGSPOT.COM
RU.apk
http://www.virustotal.com/file-scan/report.html?id=14ebc4e9c7c297f3742c41213938ee01fd198dd4f4a5f188bbbb6ffcf4db5f14-1281468088
Submission date:
2010-08-10 19:21:28 (UTC)
5 /41 (12.2%)
AntiVir 8.2.4.34 2010.08.10 TR/SMS.AndroidOS.A
DrWeb 5.0.2.03300 2010.08.10 Android.SmsSend.1
F-Secure 9.0.15370.0 2010.08.10 Trojan:Android/Fakeplayer.A
Kaspersky 7.0.0.125 2010.08.10 Trojan-SMS.AndroidOS.FakePlayer.a
VBA32 3.12.12.8 2010.08.10 Android.SmsSend.1
MD5 : fdb84ff8125b3790011b83cc85adce16
SHA1 : 1e993b0632d5bc6f07410ee31e41dd316435d997
SHA256: 14ebc4e9c7c297f3742c41213938ee01fd198dd4f4a5f188bbbb6ffcf4db5f14
classes.dex
http://www.virustotal.com/file-scan/report.html?id=3ac25c787686082892d94d625e64355000aac27d4bd1ddf4ea06b4aed9e9aaaa-1281470565
6 /41 (14.6%)
AntiVir 8.2.4.34 2010.08.10 TR/SMS.AndroidOS.A
DrWeb 5.0.2.03300 2010.08.10 Android.SmsSend.1
F-Secure 9.0.15370.0 2010.08.10 Trojan:Android/Fakeplayer.A
Kaspersky 7.0.0.125 2010.08.10 Trojan-SMS.AndroidOS.FakePlayer.a
NOD32 5356 2010.08.10 Android.FakePlayer.A
VBA32 3.12.12.8 2010.08.10 Android.SmsSend.1
Additional information
Show all
MD5 : a386b4b56e3e5df95f75d3f816dd44fb
First SMS Trojan detected for smartphones running Android
First Trojan for Android Phones Goes Wild
Technical write up
Donato "Ratsoul" Ferrante InReverse.net Dissecting Android Malware
Analysis of [Trojan-SMS.AndroidOS.FakePlayer.a] by AegisLab Security Blog
Download Ru.apk (pass infected)
SEE OTHER ANDROID MALWARE AT CONTAGIOMINIDUMP.BLOGSPOT.COM
With many thanks to kind people from malwaredatabase.net
RU.apk
http://www.virustotal.com/file-scan/report.html?id=14ebc4e9c7c297f3742c41213938ee01fd198dd4f4a5f188bbbb6ffcf4db5f14-1281468088
Submission date:
2010-08-10 19:21:28 (UTC)
5 /41 (12.2%)
AntiVir 8.2.4.34 2010.08.10 TR/SMS.AndroidOS.A
DrWeb 5.0.2.03300 2010.08.10 Android.SmsSend.1
F-Secure 9.0.15370.0 2010.08.10 Trojan:Android/Fakeplayer.A
Kaspersky 7.0.0.125 2010.08.10 Trojan-SMS.AndroidOS.FakePlayer.a
VBA32 3.12.12.8 2010.08.10 Android.SmsSend.1
MD5 : fdb84ff8125b3790011b83cc85adce16
SHA1 : 1e993b0632d5bc6f07410ee31e41dd316435d997
SHA256: 14ebc4e9c7c297f3742c41213938ee01fd198dd4f4a5f188bbbb6ffcf4db5f14
classes.dex
http://www.virustotal.com/file-scan/report.html?id=3ac25c787686082892d94d625e64355000aac27d4bd1ddf4ea06b4aed9e9aaaa-1281470565
6 /41 (14.6%)
AntiVir 8.2.4.34 2010.08.10 TR/SMS.AndroidOS.A
DrWeb 5.0.2.03300 2010.08.10 Android.SmsSend.1
F-Secure 9.0.15370.0 2010.08.10 Trojan:Android/Fakeplayer.A
Kaspersky 7.0.0.125 2010.08.10 Trojan-SMS.AndroidOS.FakePlayer.a
NOD32 5356 2010.08.10 Android.FakePlayer.A
VBA32 3.12.12.8 2010.08.10 Android.SmsSend.1
Additional information
Show all
MD5 : a386b4b56e3e5df95f75d3f816dd44fb
Posted by
Mila
at
5:01 PM
7
comments
Tags:
- ANDROID OS,
- MOBILE MALWARE,
**File-Analysis**,
Android.FakePlayer.A
Sunday, April 25, 2010
Jan 17, 2010 JAVA Mobile Malware #1 by Donato "ratsoul" Ferrante www.InReverse.net Post #2
The following article was written and published by Donato "ratsoul"
Ferrante (www.inreverse.net) on January 17, 2010. His recent java analysis publications attracted attention of the exploit kit owners who launched a heavy DDoS
attack on April 16, 2010. DDoS is still in progress today, April
25, 2010. They sent their demands - remove the analysis articles
because it hurts their 'business'.
www.inreverse.net
is currently inaccessible, therefore, we are publishing the
InReverse java analysis here (this is Post #2) but this time together
with the malware samples provided by the InReverse crew. We
ask antivirus and security companies to download, analyze, and develop
protection (if you have not done yet). Thank you.
Download 9 files listed below as a password protected archive (please contact me for the password, if you need it)
All Virustotal scan results are from April 25, 2010. Compare to the initial scan results of some of the samples (1/42 a 0/42 - see post #5
- 8d499308df04932ed1b58a78417d6fb9.jar from JAVA Exploit Kit Malware #1 Post #1 Virustotal 26/40
- 7e92d280472ca426aff1c20fbeb8d2db.jar from JAVA Mobile Malware #1 Post #2 Virustotal 17/41
- 38f083169319d0141532db992d295448.jar from JAVA Sound malware Post #3 Virustotal 11/41
- 52586e8a85188a0ada59294650c91362.jar from JAVA Sound malware Post #3 Virustotal 19/41
- 3af7627af6348a76d1bf3b7bf31514e0.jar from JAVA malware family Post #4 Virustotal 20/38
- a022524cb52223a939ba50043d90ff94.jar from JAVA malware family Post #4 Virustotal 21/39
- d45a156c76f3c34bac0cf22cb586fdd1.jar from JAVA malware family Post #4 Virustotal 16/40
- 2138bfc0c92b726a13ff5095bd2f2b72.jar from JAVA Malware evading decompilation Post #5 Virustotal 11/39
- a0585edf638f5d1c556239d3bfaf08db.jar from JAVA Malware evading decompilation Post #5 Virustotal 10/40
-----------------------------------------
Sunday, January 17, 2010Donato "ratsoul" Ferrante
JAVA Mobile Malware #1
Hi guys,
today I will focus on a JAVA mobile malware (md5 is: 7e92d280472ca426aff1c20fbeb8d2db).
It is spread as jar, containing a class with an attractive name. The jar contains three files:
* a java class (the malware engine);
* an icon image (it is used in order to be attractive..);
* an inf file (it is used to extract sms information).
The following is the class code after the usage of jd. I report only relevant parts:
LoadData:This method is used to read the inf file in order to fill smsnumber and smstext fields. It uses the first byte of the inf file to know how many sms should be sent.
InputStreamString:This method is used to read user-defined strings from the inf file.
Posted by
Mila
at
2:38 PM
0
comments
Tags:
- JAVA,
- MOBILE MALWARE,
CVE-2008-5353,
CVE-2009-3867,
inReverse blog
Subscribe to:
Posts (Atom)






