A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #33255  by KevinGre2020
 Mon Nov 04, 2019 8:00 pm
I am looking for a ransomware for android called porntube.
The ransomware displays a message from the fbi and demands $500. It then attempts to set an unknown lockscreen passcode on the device.
I have found multiple package names and hashes. They are displayed below.

Package Name: com.android.porntube
MD5: 4b4d8abbca536c987fca430af62c9bc8
Package Name: com.lemmslen.ntdyiea
MD5: 82990aad8c1a1894d7b7fd56e78c3a6b
Package Name: com.tartiap.lnnhdatu
MD5: 187f7d5ae06b386581f5f177340ca2b7
Package Name: fpgb.xpgbuoz.exug
MD5: f65657f31da966e1a4f52488f91d9e90
Package Name: dwag.jvykqfj.brgnx
MD5: d7fffb1934fd8abf88a4e6a4c1d06a7a
 #33256  by FakeAVHunter
 Mon Nov 04, 2019 9:38 pm
Here is the Archive with the FBI Virus some variants are locking with a unremovable pin so all malware you requested are in this archive :-) :-)
password : infected
(6.65 MiB) Downloaded 19 times