Clicky

Sunday, October 23, 2011

Legacy Native (LeNa) - DroidKungFu variant


Name:                   Legacy Native (LeNa)
MD5:                     com.safesys.myvpn.apk 1F5628300EF2A477E39E226FEE73CE51
MD5:                     com.safesys.onekeyvpn.apk EC056818D38D18CB940A64BF89714DF2
Sample Credits:     many thanks to Armando, October 21, 2011
Research:               Lookout
Security Alert: Legacy Makes Another Appearance, Meet Legacy Native (LeNa)   By Tim Strazzere



Download both samples - password infected

 com.safesys.myvpn.apk
Submission date: 2011-10-19 17:39:11 (UTC)
Result: 3 /43 (7.0%)
http://www.virustotal.com/file-scan/report.html?id=a5b9f74afbc3f6b634f0b80aeab6512ff1760e431ae8d96844dcfc514928ad35-1319045951
Antiy-AVL     2.0.3.7     2011.10.19     Backdoor/AndroidOS.KungFu
F-Secure     9.0.16440.0     2011.10.19     Trojan:Android/DroidKungFu.F
Kaspersky     9.0.0.837     2011.10.19     Backdoor.AndroidOS.KungFu.hb
TrendMicro-HouseCall     9.500.0.1008     2011.10.19     -
MD5   : 1f5628300ef2a477e39e226fee73ce51


com.safesys.onekeyvpn.apk
Submission date: 2011-10-15 17:00:29 (UTC)
http://www.virustotal.com/file-scan/report.html?id=d695b7310bed20e3ae00c0c4754039c3bb095062f4d746897bdf417444f454c9-1318698029
Result: 2 /40 (5.0%)
Emsisoft     5.1.0.11     2011.10.13     Backdoor.AndroidOS.KungFu!IK
Ikarus     T3.1.1.107.0     2011.10.13     Backdoor.AndroidOS.KungFu
MD5   : ec056818d38d18cb940a64bf89714df2

No comments:

Post a Comment