Thursday, June 23, 2016

Hacking Team / Crisis Android samples


Sample credits: SentinelOne, Tim Strazzere

Additional files and information



Download. Email me if you need the password




List of files
00d430877eed07d10c1e730926dcca9f82f282af.apk
0a3ec1fd0256736aeff449a2c9b7b656a6862eaf.apk
0cbcfbebfb33fde66c282fec0248b0d99a829eab.apk
0cc2c8461c78394b186a599c2d5baad364fb41c7.apk
0e8236ddb163e7f3816cfef38b92c6e064887b3f.apk
0ef158c897f91a58aa2a13d25cd3019bc19b9954.apk
153c94a6d464497b07f1ea3511b87206a3621efd.apk
156790b2ef37080cdc301324fa3f5a28d4c310d3.apk
232e08bda4856b56e06a45ac5c27350fb30ddf5c.apk
314d66e71040b36ba63ad5a376647dd63ecf3a5c.apk
4d3a1a769255402be23ae5e6b3445d79b7b4b702.apk
4e80480daf4ab573121d839c2c74cc845945be38.apk
55d716895ea0934c4a91e1e2cfbd682dec30cb2f.apk
55e2a4d0d89bc70e84159385ed9f078c5d7d9947.apk
561b37c04e92e1a4aadbc51138c787863408a014.apk
564431a34d65836481741ed83d6cb21c9a9bb7ba.apk
56b70b6d31dc3315cdd3b448416f2e2704a1ab25.apk
574e59a377b696c4bdfb83d4bef5478891c000e0.apk
57e8901381a4e9de94b26f458499c49051b19af2.apk
57f21111f6da9fb9a18af88dff688e59e8e24156.apk
598df80d1d5279e3204ef023dd4dbbe08be6bbd9.apk
5a37e9dd95ffaaae0c29197d2b45fd2afdf77f05.apk
5af738a737ce7ab4005505ab9ca43b08d4e3b503.apk
5c325c70250cbd294fae4cb321b3d8d39f1c1cd3.apk
5c53c9e54294250c0318c35086523449fa917f5c.apk
5cd906b76a1c15373bc7a0ed0d24ef69f84b2c28.apk
5cddd6f6585b0dff93ce1ecc6d8680e83c61e5b3.apk
5d42e63a02548c15801c2da5b16cbcfb33c4230b.apk
5e9a4e1bb7fb4c94bceef4cd2af54bddaf1f1c34.apk
5f0b8bb59061451a5e45241858c3f8ac62569371.apk
5f0ba094e83ee321b331a3acd7252ae92b4d5734.apk
5fdcb3d86a949d73ddbf721640733917dc300d41.apk
60761527bdec07e7cf5fc35c8aaccf4de7617649.apk
6107f1f26bcd78b628f80e4531998c4b9444ca77.apk
613398fef32a47a195ae493c8e635ceab6f4fcbd.apk
6214285ed81d3209d4947efe3a2291034877d417.apk
6260c6ba44308c0c4610468784b055ad69fa1095.apk
62bf7ab29610d47737ce01b9becbf4f56651e367.apk
62f6d3b57f0bcea6b9edebff7d67b4a1fb7ece7d.apk
634283bcea6d075b157b76a5f88d23cee733fcb7.apk
63616b5ed2253761c3e9aa47bc155a1743ac9a6f.apk
637d93c7c4d63b5c5d292c24a4a3ddff0f89cb99.apk
6386ea80441002cbfd69fd8ab74b7921d4378abb.apk
63e46c5c180d9b83a5866e770df00cadcc746e6a.apk
63fc9581928251540df5a811eb20b9024065fcc9.apk
6414962b8bdc09247d92c1317a3e0aa31a973de2.apk
64a8be553cd05c4ac08738df819f231fc16b4b6c.apk
65324abd9ceb8166487d756f474c04ab618b5c30.apk
654d374da14a9edb95f85651be60e1888f237b98.apk
6594767af663113e6c46d2a3ede5d87ec1d034ee.apk
6599cffb03d95b07dafe8e1be726b160d7541c33.apk
65d40b7b0e9eda5d5a209f3d34ed93357289dafe.apk
65f66e7b862db8c23074da1c2fe697d594ca1cdc.apk
661cc12f341af0120fbe74b33a8bc4863cae37b9.apk
667a3d0763101b1494c981fbdb9f6f18a41ecabc.apk
669f41369d3bfa56439e7fb6ef01a4a36e08729c.apk
6726709a16a54d457a8d4da73cc45bc5295d7168.apk
676d73270dfd198a8d7867e1df243dbb9b0e102e.apk
69be497da755a8259af5cdeda4ac0c9de67a81e2.apk
6a6176fc043b821b1ceb48425f2bce9c1f3a6cb8.apk
6b26dd8548bad85e2b4bbf2650dc3c5879abc029.apk
6bb6b3143790f0870f39e80cd3d6bd78fb3a9a57.apk
6c0b900a17faf11d9efc68951b2d04fdb180bfe8.apk
6c13a359586f9cab20f2bc9b4fd8294e61e6e852.apk
6c93ef2106647eb9e9322de5d106ae9df6146277.apk
6d02439c416349545211e382bc0f27b2383123f1.apk
6d6b779ea0b3d31c9453db8268b1e85463fe4725.apk
6db96e8a52382fa6f2d3220b592d7ae92f1d78f2.apk
6dba2c4cc420d3c43067cd0f8a86e1718f9639cb.apk
6dbef6bf711c74227550da5a033a0ae4c4c1c1cb.apk
727a33c78e4329ee5e1586a13ee867132790e436.apk
737395cf1bccbc23531fb109b4a8ee1e8cce26b4.apk
73ff558ea62c0835761eced6b292cc930728cf43.apk
74333980ae5bafcb25a9031fb46275435cdbba2e.apk
749ff6f09b3b6de044ddadf447860b7fd63d8672.apk
74d9dc5a2c95e9eaa880ec11a32d9b109794474b.apk
75459a5009bf08067a1e15ee4e2992c23e00433c.apk
75f31fe1a07986080b6a6f4cd2d9347cc72201b4.apk
761c6c36d81c1edd9e0645447a4e638d7d88356e.apk
766a65fe6d1e4be4551d7d30a1b4539f19991e0e.apk
76f3739c16fb978eafde4ebfae105dc8a94731a5.apk
780b5f7c07ab98de7d8d07eed781973a415ebc5d.apk
780d5124b448249d948a60b43775a424634024ac.apk
7828066c4804b6364a6f55b6aff3b657899a9d99.apk
7c0e0b1ca01e97c2f0d043eb0aabe61cae6216f7.apk
c85d37585dbe2ad77572d9a27165ed63c9c8685e.apk
caa04deff90081fd4b0b441b9bf16edeb05f52ee.apk
cce1a35b5fee30883ea3ddca8312109691116cba.apk

Saturday, May 14, 2016

Android Xbot ransomware



Research : Palo Alto New Android Trojan “Xbot” Phishes Credit Cards and Bank Accounts, Encrypts Devices for Ransom by Cong Zheng, Claud Xiao and Zhi Xu

List of files

ea6d01f87f71afc7fd131f492385d164 93172b122577979ca41c3be75786fdeefa4b80a6c3df7d821dfecefca1aa6b05
79e2b3abdbf33552677660069f891b88 a22b55aaf5d35e9bbc48914b92a76de1c707aaa2a5f93f50a2885b0ca4f15f01
748a81df76ee7e691682e64867fcd48a 20bf4c9d0a84ac0f711ccf34110f526f2b216ae74c2a96de3d90e771e9de2ad4
246f497dc26d18d87f9398758ca1bcc2 f2cfbc2f836f3065d5706b9f49f55bbd9c1dae2073a606c8ee01e4bbd223f29f
7969e4ef1b2fece87b806b5dfe25a3bb 029758783d2f9d8fd368392a6b7fdf5aa76931f85d6458125b6e8e1cadcdc9b4
8e82a09c50b787b18a612addfcaedfab a94cac6df6866df41abde7d4ecf155e684207eedafc06243a21a598a4b658729
538ca97778ac886e121bc054574d7478 e905d9d4bc59104cfd3fc50c167e0d8b20e4bd40628ad01b701a515dd4311449
d5c63390f8a42e051d0ef9fbe7f08046 d082ec8619e176467ce8b8a62c2d2866d611d426dd413634f6f5f5926c451850
6a4a011115e6ab27c9941a849ec27dd2 4b5ef7c8150e764cc0782eab7ca7349c02c78fceb1036ce3064d35037913f5b6
756340895ce28c745d0d6a5409f5ca0f 33230c13dcc066e05daded0641f0af21d624119a5bb8c131ca6d2e21cd8edc1a
d846f7ac66a9a932235fb415b96fee5d dfda8e52df5ba1852d518220363f81a06f51910397627df6cdde98d15948de65
e06dd5ba1a101f855604b486d90d2651 1264c25d67d41f52102573d3c528bcddda42129df5052881f7e98b4a90f61f23
4ed28716716a7f6dc9f6ad1526512b26 7e939552f5b97a1f58c2202e1ab368f355d35137057ae04e7639fc9c4771af7e


Download. Email me if you need the password




Tuesday, February 23, 2016

Files download information




After 7 years of Contagio existence, Google Safe Browsing services notified Mediafire (hoster of Contagio and Contagiominidump files) that "harmful" content is hosted on my Mediafire account.

It is harmful only if you harm your own pc and but not suitable for distribution or infecting unsuspecting users but I have not been able to resolve this with Google and Mediafire.

Mediafire suspended public access to Contagio account.

The file hosting will be moved.

If you need any files now, email me the posted Mediafire links (address in profile) and I will pull out the files and share via other methods.

P.S. I have not been able to resolve "yet" because it just happened today, not because they refuse to help.  I don't want to affect Mediafire safety reputation and most likely will have to move out this time.

The main challenge is not to find hosting, it is not difficult and I can pay for it, but the effort move all files and fix the existing links on the Blogpost, and there are many. I planned to move out long time ago but did not have time for it. If anyone can suggest how to change all Blogspot links in bulk, I will be happy.


P.P.S. Feb. 24 - The files will be moved to a Dropbox Business account and shared from there (the Dropbox team confirmed they can host it )  
The transition will take some time, so email me links to what you need. 

Monday, February 22, 2016

ZergHelper - Pirated iOS App Store’s Client sample



Research:
Pirated iOS App Store’s Client Successfully Evaded Apple iOS Code Review by Claud Xiao  

Sample credit:  Claud Xiao

File information:
“开心日常英语 (Happy Daily English) / Zerghelper

File: EnglishStudy
Size: 7925888
MD5:  00C7FF895B8707C2D63BEAD4D5ECC9F6

File: EnglishStudy-v5.0.0.ipa
Size: 21506666
MD5:  8135A3E8EF90558C70223EB00F9B19C0

File: Installer.ipa
Size: 6576644
MD5:  ED9C55AC907F0FA6D8FF6693C3B14835


Download. Email me if you need the password (new location that works)

Sunday, October 4, 2015

YiSpecter iOS iphone malware samples


Research: Palo Alto.  Claud Xiao  YiSpecter: First iOS Malware That Attacks Non-jailbroken Apple iOS Devices by Abusing Private APIs

Sample Credit: Claud Xiao

MD5
File: ADPage Size: 2570560  MD5:  8E93947DFD1B11A77A04429BD8B32CED
File: ADPage.ipa Size: 1484304  MD5:  62C6F0E3615B0771C0D189D3A7C50477
File: DaPian  Size: 5978608 MD5:  3A41BB59E2946A66BBD03A8B4D51510B
File: DaPian.ipa Size: 2826575 MD5:  6E907716DC1AA6B9C490CE58AAAE0D53
File: HYQvod Size: 1984256 MD5:  35EE9556457D6170EA83C800887C1CBE
File: HYQvod.ipa Size: 2154552 MD5:  97210A234417954C7BBE87BFE685EAAE
File: HYQvod_3.3.3 Size: 3347360 MD5:  304A10D364454EE8F2E26979927C0334
File: HYQvod_3.3.3.ipa Size: 3148992 MD5:  29E147675AF38ECE406B6227F3CCD76B
File: NoIcon Size: 1426368 MD5:  E6B45FAF823387BCA7524C4D0329543F
File: NoIcon.ipa Size: 581136 MD5:  FBF92317CA8A7D5C243AB62624701050
File: NoIconUpdate Size: 1427040 MD5:  4460F3D29A4BCE8AA8E8FFDE4A467B70
File: NoIconUpdate.ipa Size: 590191 MD5:  0B98EE74843809493B0661C679A3C90C

 Download. Email me if you need the password (New Link)

Tuesday, September 1, 2015

KeyRaider: iOS infostealer



Research: Palo Alto: KeyRaider: iOS Malware Steals Over 225,000 Apple Accounts to Create Free App Utopia


Sample Credit:Claud Xiao






02464AE6259A2C8194470385781501B7 9   catbbs.ibackground 3.2.deb
0F710F8397EC969AF26C299A63AEDA8B 9catbbs.iappstore 4.0.deb
1DD1A8C6C213E3B51CD2463D764A9C62 9catbbs.MPPlugin 1.3.deb
3838A37A9BC7DF750FB16D12E32A2FCB iweixin.deb
3C57E433FBBA1AC1E4DC1B84CEC038FB repo.sunbelife.batterylife 1.4.1.deb
CAAF060572E57B6D175C3959495BCDBF 9catbbs.GamePlugin 6.1-9.deb
DDF224F63EE9C7FBA76298664A2B0B00 9catbbs.iappinbuy 1.0.deb

Download
Email me if you need the password  (2015-09-03 - fixed zip file)

Tuesday, June 2, 2015

AndroidOS.Wroba.x / HijackRAT - Android sample

A variant of

Research: Fireeye: The Service You Can’t Refuse: A Secluded HijackRAT 2014

Sample Credit: SUVsoft

MD5:  a21fab634dc788cdd462d506458af1e4
Size: 403974

Installed apps:
com.ahnlab.v3mobileplus
-----
com.android.internal.telephony.ITelephony
com.epost.psf.sdsi
com.estsoft.alyac.ui
com.hanabank.ebk.channel.android.hananbank
com.ibk.neobanking
com.kbstar.kbbank
com.kftc.kjbsmb
com.sc.danb.scbankapp
com.shinhan.sbanking
com.smg.spbs
com.wooribank.pib.smart

 
Download. Email me if you need the password. (New Link)



Android Locker Ransomware sample

Monday, May 25, 2015

Android FakeApp.AL Sample


Research: Scareware: Fake Minecraft apps Scare Hundreds of Thousands on Google Play  -
Adware

File: com.xcraft.mods.apk
Size: 341376
MD5:  ACB66E858D54C61AA10E60276001C02B


Download. Email me if you need the password





Thursday, May 21, 2015

NotCompatible / NioServ Android sample



This file has been spotted as the response content of the following URLs.
hxxp://91.194.254.107/Android.Core.Defender.apk

File: Android.Core.Defender.apk
Size: 64345
MD5:  7079D98E70EA31EA8F1DA54D160979EF

 Download. Email me if you need the sample



Wednesday, April 1, 2015

Hacking Team RCS for Android sample


Advanced spyware.

Credit: Anonymous

Size: 2392347
MD5:  904ED531D0B3B1979F1FDA7A9504C882



Sunday, March 22, 2015