User Beware: Rooting Malware Found in Third Party App Stores

35
Appendix User Beware: Rooting Malware Found in Third Party App Stores Appendix TrendLabs Security Intelligence Blog Jordan Pan February 2016

Transcript of User Beware: Rooting Malware Found in Third Party App Stores

Page 1: User Beware: Rooting Malware Found in Third Party App Stores

Appendix

User Beware: Rooting Malware Found in Third Party App Stores

Appendix

TrendLabs Security Intelligence Blog

Jordan Pan February 2016

Page 2: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | User Beware: Rooting Malware Found in Third Party App Stores

TREND MICRO LEGAL DISCLAIMER

The information provided herein is for general information and educational purposes only. It is not intended and should not be construed to constitute legal advice. The information contained herein may not be applicable to all situations and may not reflect the most current situation. Nothing contained herein should be relied on or acted upon without the benefit of legal advice based on the particular facts and circumstances presented and nothing herein should be construed otherwise. Trend Micro reserves the right to modify the contents of this document at any time without prior notice.

Translations of any material into other languages are intended solely as a convenience. Translation accuracy is not guaranteed nor implied. If any questions arise related to the accuracy of a translation, please refer to the original language official version of the document. Any discrepancies or differences created in the translation are not binding and have no legal effect for compliance or enforcement purposes.

Although Trend Micro uses reasonable efforts to include accurate and up-to-date information herein, Trend Micro makes no warranties or representations of any kind as to its accuracy, currency, or completeness. You agree that access to and use of and reliance on this document and the content thereof is at your own risk. Trend Micro disclaims all warranties of any kind, express or implied. Neither Trend Micro nor any party involved in creating, producing, or delivering this document shall be liable for any consequence, loss, or damage, including direct, indirect, special, consequential, loss of business profits, or special damages, whatsoever arising out of access to, use of, or inability to use, or in connection with the use of this document, or any errors or omissions in the content thereof. Use of this information constitutes acceptance for use in an “as is” condition.

Page 3: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

3

Malicious APKs (SHA1 and package name):

SHA1 for infected apks Package name

c9284224b4a6104debf065b34dce98582cd300ca com.funme.assistivetouch

71f1f99b18d2194779cd69ec022a6fe320453fec roliokhgbfcds.lego.bricksmore

e306aee356b05acacfd9cae7189eb00712114d36 com.facedetect.facetune

7b14eb6807c7e8eac2236b151a544a53e0852212 vilopkjmn.glu.flc2

2b9d11a79d71c1ccc17c79f05d5e7743df98e8de com.ddlions.thunder

22547b544c19a6a254e24363abeaf7d917b8afc2 com.smart.booster.wifi

54771a09c83138bafe20e457aee042a8a991b443 com.baghaaer.freedom

908e3941179b1781181b0f190409dc51ee4281f9 com.brainyideas.gtasanteu.mqzsqf.gtagrandtheftautosanandreasthemev14

bc4db0f46821facc44f4f6401a41ea1ef24d7823 com.armyforare.game.zombie3

f10625159f35423509e8ea6ab11ec27f8591cea0 com.cordiona.Gamekiller

dbf116616e13d12c823f4f87fd12019a55fee4ac mohanerty.sleepyzstudios.skisafari2

69dfdaa53e71d0fc52fbe3bd93724a39e7d20010 com.yuklpol.mojang.minecraftpe

76542589f19219174480ddd50a85e3240eb19ecd com.test.sdclip

cd38e85138b9e0ed9ad677b518de95a8a31616de vinolikaswed.dimonvideo.luckypatcher

8373e4e98866bf820f1b3e94e7e56b8ce29baf9e com.test.sdclip

3b78771eb59e517aac27ebbba858bdf84e5b8d0b com.focuson.googlesearch.org

376b35ffe07adfea19a27655098e25260f65e2a2 nhjukiopl.socialpoint.MonsterLegends

1b8b83cfcc1962c554abfcba95c44cf3c6d2f875 com.hck.parts

5e0910cabb44b39dcca7f56a42b3b2629f27b1fc com.example.homeof11188beauty

015c7df0d2176aad08093c719d327c8eed9e91c0 com.knocker.modsforminecraftpelite

6a38f13de7fd81e21a087effbc26eb74c998ebdd com.brainyideas.geod

45998661893a983fff35d24c8caf5ecf1e7e15b2 com.jsaolpbmar.castleofillusion

ff95431ef064022a9e613ffa0447d99bc55d9c91 ftyuioklmj.roidapp.photogrid

2f630090d141391ad2ff0be0af7ee6fd50b9cdbc sholikasdf.game.fifa15_row

420b4dfa1983fbf841202705bb7c493a1d0df1e4 com.ts.lite.xbrow

1379e11a892485e54d5f6c958f1a3cb989239b64 com.fun.lock12302touch

8a0a644c79f9f64deb257eca1fa612ad13c47295 com.armystudios.skisafari2

c2cb332ef99e93a24e71c8a3cf31b0928ac19213 com.pmplay.tiles2

8afa967554e97652c19c1a4db34243da4f1469ff com.fotijakva.ANMP.GloftDMHM

634e06611a2dbddf800d24564a86dec60723968c com.smart.booster.wifi

838a2c15339f1d5ac7c047614966c0eb30b5565a com.andromo.dev354080.my11241app412250

fdb4bd01a68e6d4e2cdcf4f5cd8258a356625dbe com.ddlions.thunder

b298bb1b5a2d432359c929dc111dbf07ffdafe0e com.viklhs.miniclip.plagueinc

Page 4: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

4

SHA1 for infected apks Package name

96b1924a11748b607a50cdb08fffb73281be8fbe com.rolpotx6sad.geometryjump

ca476de0e649b13c72b87ccd7ac58a22f011ff2f com.ewuomole.applock

dff0af93815c772948a0036af4bc10ba41aed6f5 phone.cooling.n11

ae9b08ec0d0de5fa97ecfd22ca2c8d65687c396d com.uVxmxy.mySAKzaE

5341184f0b7ccabcc1847bb4eb1d2fd24803a06a figaro.modern.combat.blackout

4ad5613b9e8d80094c480edaeba4932de18708eb com.imnet.browser

12eb63e346f2a9fbc20886b4b0f4f953ef71bee3 com.sexsne.mat

3eb7cdc9a5236491c542a9602ccb6917a179f804 dertfgbvhjui.purplekiwii.mbhexa

df11a3a70808a08c85ed8dbdff8378ca59e1059c com.koidaordhar.DreamleagueSoccer

1688c2db51d5fb9eeae4b6040bf70fd3879fd6b4 com.test.sdclip

4f292ac1129dec07e8dfc75a32a0759eb145515f com.asdasrdop.google.playstore

0a121aba478966deaf533e25f64fcb9fcda03b9f molpkiuhjn.aim.racinggt

519b55a141f2d868519869590bf0134d6793a251 com.hd.android.video.threedplayer

e9f30f7ca05dff2dc605430b62a8a5f9c06bf283 com.chratdo.showbox

61ca4a6a90338b270edccb116027afda511e587f derftghujm.mine.videoplayer

d1ddada1b6be51e36ccc77469881fef7e746e4e0 com.wqsatone.DragonballTapbattle

945f84ea20e13c6c8cc9c0e00dc0956c4cd644a6 com.mojang1tixanvrenda.minecraftpe

6ae71cba78820c0b6f975fdd502a3e5bb0622a9b com.chwangilo.geometryjump

9829f3456ad8fddad0ab1a42be2622ca61b321ec com.ieaegas.castleclash

419f2c55e054be24bc5fdb031e9f0a29304fbbf7 com.ddlions.thunder

974d545fdde047dd93f711fe5e943ac52706f3b6 com.mojangchinvolawa.d3ty.minecraftpe

72e0724a80909f58cc2c7456d92c2583ea51b05b jenngs.dimonvideo.luckypatcher

45a41b4f281f118d616360a7fc69da2a503c6243 com.jocors.games.fivenightsatfreddys

932c885e7b933e719d9aed2f8cbf7d5e410ab779 com.yupkwara.Minecraft.PE

fdc3581e0c276730061d7ea019648476f33045b9 vioklpuhfd.gameloft.android.AMAZ.GloftM4AS

76506b2d84c228bfe3fd660dcb5e61dd071ca075 deniklopk.hera.android001

37ec36c1ebb9b3253e4fd50cc83ca7faaec37835 mbvggfdaxdd.google.android.googlequicksearchbox

f266ff31132154ac4dccf277c5d8aafd9d074b5a com.lyh.kkbird

6141ab3180d5566cd8ea36aefdf6bc18734edae5 com.vopwambrohdfull.RealSteel

06e67998c9f9a58e5ddf3b19c40875a104648b9a com.forteongpo.skinstudio

5fe532f98d3ab0eebeb2a5e5e9552469453fb613 gopaling.venticake.retrica

efbcde4ca48bd2a0bfa023c17a5dc483e7583083 com.adianxinos.dxbvcspro

e168f70a0bc926eb70cfddfda1dcd5df25cf20bd molijkhttgdd.halfbrick.jetpackjoyride

7ab0dbcb867556c61ea24e94c46599e2291e4c87 com.ppsspprockxa.ppssppgold

9031aca7fce8bcf549b69ff5ac09a2607fce8ca8 com.dyacars.skinsforminecraftpe.org

20eba3ba734ff82fcf73c5a4a1c1537d76b46048 loipujhkmnb.integer3d.dirtroadtrucker

cefa9e759c4899fceb6fb90003f3107e5e824e78 com.smart.booster.wifi

Page 5: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

5

SHA1 for infected apks Package name

b82b39cea7eb5ba3cfcf3a75b7728ba68b43f43c com.smart.booster.wifi

706a843c02f3a2dfa4bfc032d046477120de4127 com.mojangchinvolawa.v7saz.minecraftpe

8b7516907ca017df3e9f743f2027badf380eeae1 com.mojang12tixanvrenda.minecraftpe

6507152de3c3414f45b940296ab49bfdb82150e4 com.dasretoghrtsad.minecraftMCSM

e74ce89e0eeeb6488b214dd26ef62804cc2672f1 com.smarter.wifi

f902c17f99390406c1185ed73ae702bbadc43894 com.android.security

b136fffbaf8234be61b1144dd35c7e6219fac253 xlonilkjyg.mobage.ww.a1575.Motor_World_Car_Factory_Android

522076d6ceae1305728cf38d7ca1eca227056bab com.daptor.android.xposed.installer

0d5472f88840408f064dc43bbc66c7ae6ba31ca0 org.xka101.bqts

664112449000919f044aa96e09a7130d143c4406 com.kolinardas.youtube

1994e44e650bc02edc273fc62922fb907af83857 com.polumberopa.gta3

b40ae850622a392500907ce98871b5c366f190c3 com.mojandclicnedas.storymodeswa

1ed2e13b256c5e87dbdb48959cc7503243e7bbae com.pulshds.mojang.minecraftpe

38951cde3015618e8030501a5b7fce59e92d311e ggspt.forshared

74c6d0871602db33c39d2099c691306de574c561 com.forumnstar.FreeStore

c306e277fdaa4254ac5eedfbfbb72eae31c7369f com.sportsinteractive.fmt16

c0ac1cc8788bbfffeaed79d5555bfd1809d4f185 com.fitreas.screenrecorder.pro

75c3be4d3fc6599059fb48e6f922cec99b1c9f31 com.gamekiller.goutin

86ffd321290ebb9a5016d30f9d277284601ad694 com.ts.lite.xbrow

4c00ee47f6f51a8d8576ce3bf334162a40e8afd6 com.smart.booster.wifi

5098295aac12aa82355237d6cf702e817111aa58 com.poke.plane.ninegame

874236f6f83705562adb329da7721224ec7d4eb6 jinoligeds.iwobanas.screenrecorder.pro

4e7f9d5351b606b20bd2d78d77a959191d48c05c com.uVxmxy.mySAKzaE

02f142ba879e8150f6883c1fd7ce61f9f82d70e1 jolikenhyug.dreamsky.DiabloLOL

e7a1acc743bf682e991cfbf3040a31e5a8243778 com.biodhan.twofourzeroeight

4db0b359a89bd60c9f8481344887d791abfe9c11 com.gharwa.rockstargames.gtavc

5c0b239fca1ca6d5c4a46672b29077c34be98170 com.tuernela.mixels

6204d23e1d37ac7e656cc4cc3b097c1c9a8629b8 regalets.google.android.apps.magazines

f36a9420c6beb78582d75c35e247413bfff25365 morarijsk.pap.papercraftstudio

b4104bc369794a2e944f7f03239c736f5bbb9559 com.korato.simpsons4

1da5a340f51bcbcad6aa206c7ce714d5cd359420 com.xszgo.mojang.minecraftpe

90c6d26e09cbb3d00aa95496ea0f9dca41848122 com.fopyala.minimon

3a000175ca55a74d7652d2513392a3dea90e8153 com.saklop.autodesksketchbook

4e551d56068827d7239b557cf45b52265738a036 com.hck.parts

5179990bacb422d90b4eaf27109b415da2423003 com.pennie.socialpoint.DragonCity

98ee0568be3b0b74cdeea55ccf2e48a6e4d9a8dd com.kolyartyu.gamehack

Page 6: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

6

SHA1 for infected apks Package name

037cefd400bb64aba178ecc03ba5c824c324af6f com.wasered.full.FIFA

b18be184df6b136bc389e64fc86ae89318d46bd7 com.lyh.popbird

aa950920bd28a16686e66e2c171e613f1c071957 com.thandasqare.gamehack.org

fce18373842cdb0d507c547bddb4d39e27b3d9c3 com.vdfv.mojang.minecraftpe

5e0b67c34acd568b6738141bfb97920c5c25de3f com.imnet.browser

5f6fdd7c0e294d752762d83ebf2ba4ba70b3e4fc lolopikujmnh.natenai.artofglow

fffb089a8a3790bbe383145a6e43f9a99c1472a2 com.gamekiller.kiloutesig.mc

d63f0bfe8f41d9ecdc366eaeec6967ab78c91eaa com.mojang13tixanvrenda.minecraftpe

9ea605fe5f371cbb16c364577be64d606ba3cdb2 com.derandovelesnar.trueskate

481eab25d64c09fe88a9e340e4cfda91debabfc2 com.hck.parts

4de4c8dd7ea54f75bcf8e07aa29beaadd3b52b6d com.sautoghost.trucksimulatorpro

9ab66b6b6a2babbc5acb0fdd96a6ea2f3b594cc1 com.key.thunder

805e4917f65bfc38cdd5b2a54624a9d05fd5b1cc com.akhilesh.xmodlite

189cc9a6aee8699c352390f4cee76c2b7f3f6abb com.haijiri.tdo.showbox

140c6e6c01acc6d6d5c647194650ed15f09f3d81 ceu.navigconuiro.navigator.checkout

b44ad34d5f4229c7bca077554009f485b837f951 com.uVxmxy.mySAKzaE

d76c4000747cd8392328b2d0a3160c552fd1d7f4 phone.n8.cooling.n8

0113572e22648211a5a6e301f0963c6dc8bdfd66 com.bolingad.geometryjump

091b82c55166bad315ea7372f71b7d8253582f00 com.jatradop.google.playstore

cbd4647ec691764641416e862196e342c154cc58 dinolkujtg.animirai.pokemonruby

0633f4e430db32c89ae846dc395fbbb00b6b2586 com.uVxmxy.mySAKzaE

f0eaccc213a9fa97e5a9ea9733a052899bb1d44d com.ddlions.thunder

7d773cb073aa165c41ca974c1e56bf707c3ced24 com.rolpotx156sad.geometryjump

2c77b6f72706e97f69823b9355ea3f508aad921c com.folyouchtype.swiftkey

5cca9ae1ab0fb93ceac1ba09dd9c9d254c362a67 com.ertdqukl.mojang.minecraftpe

cc50ea6b221fd7c2fb50e8840de43d98c778a0f0 com.rolpotx13sad.geometryjump

9b1eeef21f2a245376fd1d18e9450b00f9f6f906 com.uVxmxy.mySAKzaE

9dadbc50fb760d125e14df67cd5a9f7e6253a688 com.fityush.turner.cardwars

df9ed5dc11275617f4b587c24c7d8f3c64989002 com.ralesrvick.ageofzombies

3b6f9656f2debb4d8d083af3425466ee3c8c665a com.demeriasan.WormsArmageddon

57c94b5fcabdcb374845575cce4e75b7360e92df com.forfcomics.anroid.mobile

81f37308c7a8fdbd58b191fb7c6d0fa4d250eb9f com.nothwateftpe.stonegaen

178aa34a79e55db33c97eb428e7eca778148b181 yioplkjewsdfc.gameloft.android.AMAZ.GloftA8AS

9348f126ba134a5680c7bd31a552c3ddeab4f5b7 com.loryadfren.antivirus

7ba5e86d1951cdf6f24cf2646d320534de27a94f com.folim.imageline.flm

08c1e1bbcbb7f428af6af68894079ab7820d16e0 phone.cooling.n9

acef1f4b9892c88a424830d29acf22f68c8480f7 com.dlpo.mojang.minecraftpe

Page 7: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

7

SHA1 for infected apks Package name

5cdd21f9e4939228f9c4868b2641da9a28e7bf1b golpktyvf.lima.doodlejump

b26ade62480cf4cb9eb290dae27aefdb59f53da6 com.sexsne.mat

07dcc745b14a6f629b3be0c686b50d5ee4ff9a5f com.poinardas.whatsapp

036d3db88ba20bf87916c3603be8d5bd0ab87116 com.rolpotx4sad.geometryjump

91168bf149c70c25e8977ec65ca1a3a46b2f68ce fyuiijko.videolan.vlc

93dfd094816ff5cf924ff58446de583046c938e2 com.n16.phonecooling

e9153dff6901046dca609a99de9992c2152904e8 us.bolpif.vfpal.warspear

af40b853a4ff68fddc73b7ae0d26b842f5e42440 com.example.homeof11281beauty

48042ec9fac84ec2c3bafb4e62df8cf7d90ad0cb qwserfd.wiziapp.app104473

62c1cf9becc00cf0a8265a1f2691cb1f160cad46 molpkijfgvb.magmamobile.game.checkers

bbcdf6d51561b76399f23cc0e487bb912420f39c sidoliya.gameloft.android.AMAZ.GloftM4AS

66a2fa679840014c6dfbf7cf5e669f4c0ebf0f4e com.facefocus.facetune

e15ed98f7b5a87bf2c3e2a7ba1bbbb87171d1c1d ressdds.viber.voip

b6573e173eec7b674c73eee9f95180be3203981e com.brainyideas.geodnet.tkzvinrfe.geometrydashthemev15

9b63e740de4e675f8f620b79b7e14f8b6a94b7cf com.ddlions.thunder

72a94c2c22320cd30f5578639deffb632281336a com.socialonward.twitter.android

607fb9018537204d183a9229f7f495934d5f40d3 com.j9b.insaneEmoji

62dbfdb35ff53d72248fe989b269c55d9d75c6f5 engene.adobe.air

37ae798d95735a3e3aadd3c81a716e9e87e8a10e com.hd.android.htube

685dfc25521716965d238baa6c2d94ff2efd9fa0 com.becgeagame.fifa15uteam

b155bf63fd4dd73bbbdcfda494372e16438ee83b com.samilon.guitarpro

394da9f855731201559ca09f95a11d418c95e8fd com.koniksoftwdsare.snapseed

fa2c848a85b2b49efbf2d9cc38a2b644f75ed890 koplimhjfgty.shazam.encore.android

9de000b03c298d9e0b5bcad4fbe7c95fb48d5ce7 com.fgoptp.nextlauncher.trial

6bcf25cd371c041f890747d1d3e51b23e2bf81f3 com.mcavoe.zombiederby

6f5999d632c3971b280780475b12e796e432f7ba com.fopliaar.scottgames.fnaf3

ae694e1326b724756cf8b056adf4359b5f6f7160 com.favailey.skinsforminecraftpe

bd6c86a3f45cbc920aac795abbfa2ed22dc8aa24 denimjukh.ninjakiwi.bloonstd5

700dfd8bdae61d867a56ae44cc5e6257fa43d4b2 shuresh.skgames.trafficracer

6a4fc9abaa1246465578870ebfafadac44a9a0d4 com.ssdewqa.gta3

93a52e5f438653077d49614a9fb7a939ea76020e com.golpiucngad.geometryjump

4a7fac8b02110d4c0886469b2d709c98eb8e4a0e shilopkyhfg.zhuoweizhang.mcpelauncher

2706f8b502b1afbd93ca3e50320d676351441404 com.doodle.turboracing3d

295f4da31f5408aa3180729b75226ffe8b4fa2d0 com.lopmkifera.gta3

555abb955331d62055b31c92bbdafd6974976821 com.mojangrealted.survivalcraft.org

ecc52acbcbb58f63c91c741faac5547bc0a7f38e com.khilithokdi.needforspeedshift

cb78fed516f65d1ebef997f2280572cec7cebae1 com.eramobsile.lifenae

Page 8: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

8

SHA1 for infected apks Package name

7d5209a831cb2505442546dc3ad78b53d800c373 com.imnet.browser

12ae4ab491a6a9566688937e3eba17d5b141b79c com.mjklo.mojang.minecraftpe

bd8f1e283ba6a079f6fd7ee691a5c75470dbcccc com.mojangxervabherva.minecraftpe

ac390e72cfc8f2315f41a799d7f14c42c1f80e46 com.lomaexmp.audioplayer

bf200a336b16ee342f5ed5c0ab3244cb49c0442c com.pelametry.android.apps.plus

fc80fd15a420c28461232878748a2916c5e8c097 vgfrttuijkjhf.midasplayer.apps.bubblewitchsaga2

690c3fa876037f106a4f84b107c22669c0c5fa00 com.exozerek.android.catan

76b7b6068a05f0e26a48f757a62cc6c7702d84be com.smart.booster.wifi

7d9e87d4abceba6a0646d08ae60d490243c6d4cb com.ddlions.thunder

17db0bc64f9ad1114e7ed40e1f7d0ca03bf691f0 com.loinascorp.LGMARBLE

3435278af7d1241793625672aabccf151847aea2 kolpihnbgcv.indiagames.procricket_android

e749e9fac55fff59b1f58c5702b159e5ed440c97 com.afaerfolsut.CallofDutyStrikeTeam

efcac1bdd82d9b69cfc22379594cd3973f0219f3 com.dfvel.mojang.minecraftpe

c6f7cc2e8fc950f34b3141b773bd9e9d0aabb7b1 com.segagames.fmh2016

e9f23826e6de065a07df61c3589f10b8abe80e47 com.hd.android.htube

491f21f4960134a18d3afe6e4569178111b7a656 brm.sotafkaco.neecdo

4406ada624e7ebc60643c05004ee587166a6d7f5 com.vexa.twitterandroid

c12b2fa66db400f162bd2cbf6a1c3435d10c5da0 asioklytgf.videolan.vlc

bd18a420b0a473c3f3bce90b2ac6e6d9dff9eafd com.pinjoda.jetpackjoyride

cf3166a9c92ac8ca8c7ccebbcce2b597c99b7873 com.ciewsadagopido.chinatownwars

65c70e54990bf5bfc72db4609312a4c2482c2cc2 ganeshikol.aptoide.lite

94cc222d1eaf6129dc71231f4c3b1337c925b069 com.example.homeof11118beauty

0d7191c2a220bd75797abb1893c01e204674aa6e com.ferivyaston.action.NBAK

67f67bcdd816384e05384b8a35140c073558f05f com.pinachgh.gaorimehack.org

03d538d8005bc7042cc11880b66ba08898b8ccfc com.foryorwa.surgeonsimulator

dfccba9eaef154faac6d3aa8beb06975a96c489f com.polidasics.turner.atskisafari

7b1988b63d40265bbecd9894d6e41bd3a5a2812f gokuliyortgh.slf.ListglApp

dd4eedffa50af3c981a49e02b01d2f1844f63666 werdfghbnm.touchtype.swiftkey.phone.trial

19647a25420fdab50691b581c9812476ad2009b6 bomuklpjnb.surpax.ledflashlight.panel

5cda63dcc40ad42d6bba18c9cdbdadb6dd9dc639 com.clapfootgames.tankhero

0278d809caccc2289e6c39339fe824ffd1f7c0c2 com.lekonakisaki.cleaner

53fb45939e98e5480d4dcf1de4047777a3a86e7c suresh.roidapp.photogrid

6574d6938ad12e15260a8ffb0298935f88526305 com.fordikanol.rockstargames.gtasa

e9dc28afe898fa53a089d64fa200263fce3eb2aa com.notridyan.NBAJAM

1ce0fec28ba9946b22c6d20d8147112c02bd3e07 hepnee.brainyideas.gtasant

2ee2a9ce76ae8f9de8337ac5c23dde0632ef3f27 com.mojang2tixanvrenda.minecraftpe

95890c4bab12a48194aed84b3591948cc5abd16b com.aliamcruz.unturnedday

Page 9: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

9

SHA1 for infected apks Package name

b11b2b488b5595d0ac5b97028da810deecfdf78b com.test.sdclip

fe6a08a8abbe4dbd5b98d04d2a0286d59aaa0059 com.pinaras.lego.bricksmore

de731775205b1826d2157975ad46e542f7d75c77 asedrfgyuj.best.online.live.tv.free

ede8bd8d2fc77fbc4dacbdbead37e14c03d0d197 com.detraghav.showbox

968b3a41b0616bb43280d36cb1d3d1d07e17e4e5 com.example.homeof11117beauty

5fa423ea5fbbb611bf312f8085f6f04ee844bda1 hioplkmnbg.mobirix.tkochess.wgmf

926362d4dd1acb5ad518fea970e91e262e0974d0 savaliya.com.outfit7.mytalkingtomfree

9cdd686babfd82116739ad13508e9ae88b4edfce com.Antwifi

5aac9c4c1189e5bebbdd3f5e2b71e2bbbdd4ebd5 com.ruijumspgames.rswrb

9a7152a2a91bc6c82c332b89c8e6d83705f094d1 com.ghkwara.Minecraft.PE

214235587137436224eed9fb497556a091e089c7 com.brainyideas.gtasantcom.qmnwhmtxg.gtagrandtheftautosanandreasthemev14

9b48a79053a60bd2c0686e4b245efa865da4b98c com.devream.studio.ageofwars

59e840965859decd9988cf9909dace02d51f834f com.jitenosde.mobile.metalslug3

f9027e7b577e14ae62995e95318561150f514cc4 com.forexsewas.BridgeConstructor

fc6b469a82424f41a20472da4b69d45e705aa386 com.volimaitryhi.askfm

629d07aee247988c67c0d59da33e59de5db96611 com.bacaraisis.Edition.Minecraft.PE

25a0d97de396ccb376009c6ab6725c8d4be2afc6 monalishertf.dianxinos.dxbs.paid

84387ce4a4c78d6068d11c8be58aa7ab878fa63c com.iligsg.castleclash

17310d915c87eaad0cd1a3672b0cfbe0df57a425 com.bkianers.rockstargames.gtasa

19e04d530cb64c51f703f1ce0067e6cdabc4e1ed com.star.tuner.freedom

4f58254b83c8080106b7358b04b0121d1a699646 com.deluzxfun.galaxyempire2

8a4a5e8c495a0f7ad2cfd8de44f1ed4497de6b53 com.funme.assistivetouch

7e1a7c3d5a90179ad77c3b95ecf5cecfd25cc34d com.frtsinal.supercell.boombeach

8c5f3ce189fd8c7f2fcfa91bb07f1b2beeaea4e2 nilopikewqdc.tdo.showbox

cec3b18c70f76796c4ae1921546df477bf8cdd19 com.google.android.apps.maps4ui

b833dd743e049f4f77ded78889af704fa0870196 com.faetilgirta.ANMP.GloftAMHM

5b31d88b167bc4551092c255a8ffc342ddfbdab8 com.dianastar.barmfera.gta3

34ef9324c5cc1520efe1af8f2450a34ce2f0a41e com.funme.light

6c56b07af6a1b38c6376a24442daacf2ae86d22b com.tosiaela.fivenightsatfreddys

a7ee1d2810456c60f1694eb3d2e12a48d10a89be dfrtuijmmbc.rovio.angrybirdsgo

7a086cac4881d3b4b232d38375467f5b8bdbc739 com.sajant.shazamencore.android

94305c899e318bddc081e76a1a951a739d34cf08 ganesh.divmob.ageofheroes.braveheroes.battleheroes.epicheroeswar.epicheroes.en

650bef556e5f52ef2132d1b7b7bab16b42271186 resbenr.mojang.minecraftpe.demo

0a5bbf7a375ed1f28d3cfa68ff14893b29626ace com.wulonala.kingroot

0ab4bb549271778ddeb3ecf44041f09d7421c465 com.julian.fastspeedracing.cy

Page 10: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

10

SHA1 for infected apks Package name

2c7150fca4a8f99e4ac638e98c341f1f4d45afca com.brainyideas.gtasantbiz.nzoqslsa.gtagrandtheftautosanandreasthemev14

28e5d2dc2b62c440fb6283c458060e010290ff18 viomjklfrdv.wargaming.wot.blitz.appgia2

965b84be5f8bf467b5d9e50b56c934a20f686534 com.fiyajav.guide2015forminecraft

cb2171876004bcb13b1b51931fe91d9dfb14c8ef com.ddlions.thunder

48ac6b93a77f75c13ccb5acd3a07625ef8cafa75 com.ghtypol.mojang.minecraftpe

9c7bfed6d701a99581d05ea97a182df3bd0f7fcc com.ddlions.thunder

227071c874dcef02587d54c252af2bacf42c718a fifolikawse.speedsoftware.rootexplorer

07a9eb404b78a6aa5ecb17fb6216cd38a693ddbd com.khuiw.skys.raider

986c6de0138871724ba164e2ff117c12b7f383af com.mojang15tixanvrenda.minecraftpe

b445b3a11c4fc27e08a049831c9f9bfa2bf99999 hikolpdfgbv.gree.warofnationsbeta

3d9f41469825c4381e0e6c426026596c1f958721 com.ddlions.thunder

fd92ef33c6a87aea6f52c3ef0341e7d891e954de com.foiras.chainfire.supersu

2336a2026a8d5bcb893cd56187de197dc44b203b com.bikowartife.full.FIFA

8d785b36e88079d376f17e36d796e64e75fd0c64 com.ddlions.thunder

758c0086e46920c8ba59ab313f612c37309d2302 com.hck.parts

d08e8b7c339b0952a522d4502e4a877bc2e4465a com.junglesemonkeyrun.saga

39bc566a89f67862e82fcbc21f2d867c1f241bdc com.uVxmxy.mySAKzaE

678a8f6393b957518b3ed34f787e0791c059bcc9 com.inopolikva.mojang.minecraftpe

c4bd96721a7f2003a4906f934f09b22a8da892e0 com.n2.phone.tool

c11e36f1967b119e3681e11c8d09869670fab829 com.rokitijoki.letson.mobile

0b6f80be5db02fe1118943cfd543c4cc26d64887 com.brainyideas.gtasantorg.tzxpkn.gtagrandtheftautosanandreasthemev14

1f6b778f0c83e5dfaf81bc2b8540f81ce577abd6 com.tobykurien.batteryfu

a0387e8d4229c557df0581ebd9055618d851efff com.setago.astro

826adf0290b21225155b476b2fbbe7f89da2c798 com.koiila.opxassell.flashofclans

2dbf51cf65830076481a6cb0cc38e3203d50f998 com.uVxmxy.mysex

ecfcab5f504e68620b71129971a310450752b064 resdenna.zedge.android

f417320122612aaa22083c18a4719ae256ffab4c com.dertawstar.barmfera.gta3

7535e343c26db235f2e21118c18cc4a18d3eea7d com.test.sdclip

03dbc07e2f61fd0465b1a04c9684c6f4ccecb308 com.mojang20tixanvrenda.minecraftpe

e2aa4883d4e620c46ca6f095de0f0fa1e1a12084 com.forwsentoun.FreeStore

273b30eb2effa7def3952f78243d8d7ee4131863 com.julian.fastspeedracing.cy

9f06ae79a21a07527844c1e175727333018507a5 com.brainyideas.geodeu.ybgjf.geometrydashthemev15

1897075a5298b0e3b9996a3cd45b5d99bfc80a6f com.kicng.defarmheroessaga

614b2640f05ee9178429cdab64e22f450dfbc05e com.example.homeof11262beauty

fd0b8350b2396395321ac5335b86cf00d672ecbc com.queenroot.kinguser

Page 11: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

11

SHA1 for infected apks Package name

61fb9dbb903d3c84026561f8b719754734e6da6d solpikjmnd.paypal.android.p2pmobile

427005264305b5c27940569d89ac95a9bc59f369 reghhj.zhuoweizhang.mcpelauncher.pro

90f6542a9a30b0ad1e778888c5966e8c1c4e8d4c com.j9b.insaneEmoji

e583ba6da8c68a315b8e527cd017701cb385dce8 jilokpyhgbn.dropbox.android

ba945ae7f2c98872a57ca11f4fb7dfe478f79a59 com.rapperson.prison_break_free

32ef4b695fe1b8377884d2ec9903f85a6337fc24 com.rolpotx12sad.geometryjump

13c57f984d096b928b0379be31cfc5f3e901c223 com.android.sexy

f88d3d074f9afe78e7c3bf9c1eb6d1cef540fd98 cok.desmrah.airstream

59877fc420d7ac35e080244fa0007e3ac0beeb19 ghyujkmndsc.chobin.android.psdxlite

0b4cba5904daf22dfb970efe0f8d74874c40a7e4 com.mainoygodot.supers.full

fdd2bd7df3cd47bf5b9ce6a5b96466bf228163f6 com.sdcvtrifera.gta3

c7f0298e184c6354e0059a429dbe8c859152a8c9 com.fergotown.whatsapp.sniffer

fadf26a7ed50b38f67adcac776d45f98c1e37d6b com.castragon.trucksim

72586a59085cfe894ad327eecfb990de0bd46a64 com.loentin.freedom

1c642be16d1df46068463620f84597ab649d542f com.gohibisystems.officesuite

9411df77afe49cd08fc9905cc1b5902940f3c44b com.pinarodas.whatsapp

fe495cea6dc5ca4fb04d801b00763585b1901741 com.mojangchinvolawa.v7gha.minecraftpe

7753b0bca5a3683926126f0ff0d2e6a10017b4a5 com.polkijhug.NBAJAM

9f1b05f6dfc02fe6399fccb20ff9fb8c1c626bea com.kelabanare.Minecraft.PE

099b2798249a4747e362b2e1fc63262b620c394d com.htnbriges.ledflashlight.panel

f2325c3d5ab3fdfe759c90089dda246af1775612 wriujyhklm.dnddream.headsoccer.android

944ad5bba26544507158fdea24f3f257977b6633 com.jerigoodie.survivalcraft.org

bdf24a6c46490419cc8b0502882a2930d29bd3b3 com.test.sdclip

bc477e5dd5baeb53f37c67adb883f29e38732acf yolinjferdcb.v3s.furious.traffic.rush

ef3aed8e17549fcdb02b0dc6531d2b0fde682a35 com.n16.phonecooling

33695ebf5160e4c5f08be92eb166ef56fc9960f0 com.brainyideas.geod

1c2eba8e6a7838612664245f68005c1ef2a66539 bhyuipkmb.imangi.templerun

9b3c137709cf5b29b10a6626f43d1c18b6c6df70 com.dploedaedas.mapsforminecraftpelite

24f3d00c8720513ec5ecaac67466e9f75661a1e2 kanolika.gameloft.android.ANMP.GloftAMHM

867f73846265083d8132d35fc2b95b2e0e671d5e com.mojang8tixanvrenda.minecraftpe

7ec246f4d82c13b3df5e1a5ce40098f50be1bdff com.topwastolboxof.ClashofClans

e3ea2b981b16c9b4089e99d884b786c6c4c67eec com.fetroshura.teamspeak

d8e078b6bb6cf276e3ac0ac1a38983c394bce393 nolikjmnh.runtastic.android.pro2

eb59455ecc2c0e4e561e8f8adc7aa0fd756b8d45 yoipklngg.SandStormEarl.MC2B

053eafb4414e21d3f6a9d6eb4ce59b88132c77da com.cojoenix.montreal.hitmango

05928ea14d179362a4181b6a51c69714d70c3eae com.nikibavas.rockstargames.gtasa

15cc4768ad9b9fbb731eef6d4eded07d36c73ea3 com.andromo.dev354080.my11172app412250

Page 12: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

12

SHA1 for infected apks Package name

2fc8754175601cd39dcf8744993963bb595c26e2 com.tobykurien.batteryfu

b50161474446051f448212dd70236ab0732cef38 com.mojang.tuner.Minecraft.PE

47092c7d047056136116a0c474d8604ed02eac7d com.sceeva.coityrush

39623250257960cd142414791edd6df445c144f4 com.adaklopsi.sega.soniccdlite

5983e092669b9c979737ae6ce562506f81d744c8 com.borfvlpif.vfpal.warspear

a78ae75a18c625e870a36c1e283cd72aabec4d62 com.funme.assistivetouch

bc14826f9da99a5f764738137b67600e2c62d3a7 com.smart.booster.wifi

034aa1cce4f264b275d3ede56c8bf706589739a2 com.tofaco.warspear

111be4c7ba4657d9e1dac05d44bc02556ddfac66 com.test.sdclip

e1293fe58d773087349446c560502888b81e238a com.wbogael.goinjustice

87192729bb1dfd47e3e8612465863bff299c9046 com.viocresc.entmoon.games.redlinerush

32ff68d03ca749846b0ae4af4e002b66cca523a4 com.dertocotar.barmfera.gta3

a2a4afdeba0b4f66e2236cb2804e668263b16988 com.penisarus.gunsforminecraftmodspe2015

048f01ac570e891d4b820634852f0d615c993850 com.gkolas.fastemulator.orggaju

0cf76814dd3beefe9425bc62f43deba5d08fcc79 com.uVxmxy.mySAKzaE

fc0f7935cf48ba7f5552b00cce5090322e77e678 com.test.sdclip

efa055120f68c20169956c196d29c5aa5ec54ddf com.fipolsabigame.zombietsunami

867854c00df4f74d76ccbd5760d104660d651a54 com.craliamuz.unturnedday

973a6263f484faf1605c9d5ba824b95515c8f5a1 jogilontrsed.instagram.android

de16f139872b1baed5d5fd5580318200e2af9b87 com.derwasfwars.fnaf5

de2a770de06edabb293b47a2a36fd879a70167ef com.vitsga.kingdomconquestii

6a63218debb7e9d86e13f8a8e731de47889a7c22 cgthhyiolj.atv.blackops

2fd30f8f9d26fc0add1d1a5398cf875c4b9de3a2 aliokpmjn.theonegames.gunshipbattle

f9e40715e29bd7faf6fc3451d84d57abbeb933c9 com.uVxmxy.mySAKzaE

c6aea71178a3b005e51857fc1862f5876f405ca7 com.vuermaer.rbomberdino

7e41b1d91bf198c8de09cb06f64242fe048e01cb com.hd.android.htube

9b6a893185e5e92b73f290abd560e9531fe91b51 com.ddlions.thunder

e8bb03840bb5c2097887f993a0a3232695228731 com.piklemefad.minecraft.story.mode

99bae1216e54d78bd20294478b43cd758ca0a163 com.rfeade.flashplayer

c3728300571bf26b390e405137c4ab07ae636b89 sholikujmhn.jundroo.SimplePlanes

f878f4e0eb9246d7e5225771a7a6649a8be8e4b6 com.ttrolik.apkeditorpro

32cf7cb13aad73b60c61bd5e9b8adc16b6b54593 goplkmhg.gau.go.launcherex

63b9797acf543d2a1af3390584b8a084e9f13df2 com.ghkoaul.robtopx.geometryjump

362ecdd404b8ed4042815263efef679b81103d12 com.rfroflpscal.cartoonstore.cnrace

8aca5077faac21db996fbc8deb6a25672f3c778d com.jipasagholi.AVPE

8c6e68297b76a6350be1706bb3c61e04e27aff1a com.vareirajag.cardwars

5b7f933ca264f2ea66f044f996320a132d778220 com.aqo.mojang.minecraftpe

Page 13: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

13

SHA1 for infected apks Package name

1a9fd533ccf6245b3f733a6be8aa51957d130cfd aswedvgtyu.brainyideas.geod

d7332ddb5b24ce935ab9c0fe8d6fc555b4575c3b com.polkidulako.playstore.services

8a277815a43b3e146793a608f92194d484479303 jioplkmn.rockstargames.gtavc

4cd31979466a5568451816a7b6a763a69aff2a37 com.gkolas.fastemulator.orggaju

51bd2606304ce5d2a2f67a56fb281080468d0f27 com.example.homeof11181beauty

766701e66a78ac4f7a12422b1a540eccaad0a326 dtryuijnmh.fdgentertainment.bananakong

5ccd1cd4521bb23ad31802dfaf222a925405b754 yuiopplkjj.xs.armysniper

5ce43847409d437a48b7ccfe133b268b03b1119f gyuiopkjd.reader.laputa

13f94260ff8df18d59a0347d6890b870a5b1799e com.j9b.insaneEmoji

0b4d0915b72a9184a414185f587d1b4e740bb9f1 resweene.venticake.retrica

244cbafbf0bef73395622798f531add07b0b41e2 com.uVxmxy.mySAKzaE

e0bfa0526d88eb83cf54eeb943aadba6a7fdd693 com.dotunaras.gta3

fc1674e203e87e40110b2d8d4fca86824aa4cde3 com.evi.games.sfmh2014

ffab692a2577006d31ba558d2fdefb273384866c com.sexsne.mat

71e6adbe94c483c4e3c0016fea0968dea9f19356 com.dopacing3.armambroe.row

dc7a7843ccf77528109dc6bf1879259fc1615ccb org.xka101.bqts

18f8aa4fd2d5d0eff9940ad6d2eac6ec3a06b668 com.rolpotx7sad.geometryjump

b6ffa662556f89fe75ef6a718e17804d26703d25 com.uVxmxy.mySAKzaE

d62012d8f5f42f4a20175a20068316bf630e4a35 gionlpkdes.mobilemotion.dubsmash

64da37df7e9698cf0a0ef56cbf47e7601c035026 com.pepsi2012pro.evolution.soccer.org

315b4d96d4ece234cf45f562e15a91aa29c472b6 com.fdvdfyv.mojang.minecraftpe

b949ff134c157dfe04af419b3c1b1459a18cf853 com.vrfgongad.geometryjump

1ed94cb29f329c1c2bf38f3ad9b24b8582460df4 com.btnhongad.geometryjump

0475b0ec15daeeb6f364fab909aaaa432ad71995 krishnacvb.whatsapp

c89aadffc9381c76e2aec892e7f5bfc280a7b784 com.folpdas.gamecih2

ab59f1c5671275ce5b34ffeb545efa201c1ebf20 com.polidasics.turner.atskisafari

1a5b35bd51973409fe8717aaeaf203ac6b457b03 com.kiggser.clashoflords2

8dd15e4f96661aedaafdcbf0242844dcb16bba59 com.lopewol.wargaming.wot.blitz

9fdf6eea534269aea97bf8c4349d866c8b5db9d6 bhhyikoiss.appsbar.CalendarioSant78354

ee696d7ba021b5904e0399dba6ea18965f6ff438 com.armybaly.minecraftstory

29460cfe3988d3d4b5b863df5382ca6fa68e2f78 com.smart.booster.wifi

f0ada8afbd177d6478c8db82ffb460c89ba78165 com.imnet.browser

3fc3d0f9683399f4b916be7a230312f3d60be4dd com.evc.strongs.android.pop

0cc1c2a53760646b523797c2ff8fe2a83f1d105c me.pvadedou.app

7955ef6302a14c3eb84ea0d54dbf19d98b97e006 com.folpoides.appsstore.FreeStore

6ec4fef8e4edaaf42b0e22d836a9c209cea88ef8 dfrggtyhnmju.soundcloud.android

7cda8f09f2121dc5404e8d5025e5929549915e85 com.rolpotx9sad.geometryjump

Page 14: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

14

SHA1 for infected apks Package name

0e7bbfe01f259102a4525d426150b490b3ee70d8 com.gameloft.eranm.gloftjdhm

04c6d262a7a55d83b30f73cf389f2e454b12293b com.tinrajakola.showbox

9ce796fc438dc23df6731dd550769d4c9148d0b8 com.funme.music

39f399cbf3a6eb61206c2f8d62ea599551c1b7aa com.dasretorestar.minecraft100

f773ce6390f90436fb82a4f8a9009faf72041a4e com.smart.booster.wifi

240f530bfc70a7095f1e5585770f7efa5d2fba5e com.wordsmobile.zombieroadkill

caa8c84f581f4689ee1abdb4738de1abdf0f2c0b com.j9b.insaneEmoji

11a3787f353d50ee4d10489b9ab665122fbcb6e2 hioplkmnb.happylabs.hotelstory

6b52976f1b7b9e6736dbaa5a7f4b81d44ea96fab com.pelametry.android.apps.plus

8109166f1eeec5a5211483f4f58bd0b9182ab03c com.olafaerfusut.CallofDutyStrikeTeam

7c41cb9ad55dc31e512713feedda53b4c1091c2b com.robengo.kawasaki

7b4dbf931c9a417593cbfd0594516da93b5d059e com.smart.booster.wifi

3f24cf3b57f053d6ddd3700bd7b4439540a9371c com.lopsadaki.sega.soniccdlite

acc332417dc737a482b69e45fab9749c540c5840 com.golimar.minecraft.story2

3a989b7ec613a14792c7e4cb0d391813a108cda5 com.example.homeof11231beauty

bbb8e006a769fd681917c4194a8c60b695e1e00d com.fkvtana.dotgears.flappybird

062a31ed64ea58fa05c0eb031b51960d325492e9 com.uVxmxy.mySAKzaE

cb4a07271d4d81698de804ec868dc4cdbe196d70 org.xka101.bqts

dd9d495ae293156bcf7f7f898324cb2594e3e209 jolpikedsf.netflix.mediaclient

4b824b9432fcddc0380c4e06de2d1134a9ed1e16 com.vivosauare.gamehack.org

6cdd9f191720d3d914b158d0ca652d91253bca44 com.chawingo.mojang.minecraftpe

ac258a41ab40208d4e6b4806618c55361f3ec165 com.brainyideas.geodeu.htpwsx.geometrydashthemev15

106e5706b090d7e641a95a2cfb51757047765eb9 com.white.browser

900e96222e7bf9aac748813fce8e5dc113972dee devinmoplk.imangi.templerun

4f68d705985e0bd1aa0bac1a3e1e37996f62d993 com.forestforsto.action.NBAK

2ddf91406aa793a535dc00c9a27d3e1bf0467b50 com.leryawderjano.gamehacker

c4e055f9005bd48dddd962f96fe7f6e2e5244715 com.example.productso

615066c8243a18b7afcc8afdf90d7f1a99788e7e bolikaer.viber.voip

a139d87c81c5529a0eea483c0cdb3b52ee6fd768 com.lyh.kkbird

fb8444a6bdaed37f4e2b7c00a2854345ef54ccfb com.isaredam.editor.officesuite

0a967340cc66b9ffbe79cca2252041607fbb9a5f com.lopeiydeswa.hitmansniper.org

b701cfc8efc6f70c1ad70e3ebbbe2187cfb1894d com.ddlions.thunder

15a4345a9cd84c382ff8ca6f7bd186c325d7d341 com.part.mySAKzaE

3fbd3bd4b60baf361860185fe55aa15286fab97a com.google.mobile.play.games

4571a6ae778f349c2284544e22ffb91a17e22983 nhjuioklpmn.cleanmaster.mguard

33ee0512b3da36fc2ef1ce8f75f098be0ef6d59f com.hck.myplayer

f27bdcab0284157ad5e502cd3b434b198f078804 com.uVxmxy.mySAKzaE

Page 15: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

15

SHA1 for infected apks Package name

db9601b3d3d774d0e9264cd73d22c913d94888fd com.retrigawas.mapsforminecraftpelite

0284c52a0742c4f7af489385d8c77dad05be13e8 fiopklhj.nekki.shadowfight

42f77aa24fc6a32ad2c54b651bf7a978fd8e4a07 com.jy.car.ninegame

a9083418345e8bc1fc62a1f9e90b49ce88017ab1 com.funme.assistivetouch

a222937fbc80c23a3275bbb54fd7a5b81f5c8b04 com.white.browser

c00278ae2dd136e7f13db5d1e1293afac5f9a98e com.cvecruc.chaton

32e029dca2546ba8a74603f6d4f1dbb980d38903 com.stildok.rockstargames.gtavc

34432a86b7f150a03db0030866f5808e2b9d6cd3 com.tobykurien.batteryfu

3914eb93294460b4970003521e574ed243d7f8ed com.vivodpolimarew.gamehack.org

33fe45f406ee1e5e6bb013ee894ece974d610873 denimhyujk.eamobile.sims3_na_qwf

9517c1ef618608c02d0abb52a6f040c9af542da8 com.sac.ninegame.killzombiemayhem

e315e7117a8aa775a5d099ef2f9a024e7f56fc0d com.dawresqas.DragonballTapbattle

1e598f1236dbc0821bd8c12d47cbcc34782d9d54 com.strongopido.chinatownwars

8e4e9010480adbce416be33f00fa10e4bd1ccb3e ghyujikolpd.games2win.parkingfrenzy

98f4bad2b0999da4467e761df2935bae99d41ca7 com.mojangleka.mcpelauncher.pro

f637b709df9e3f68775957200256a21ad4e060ee com.polikinova.mojang.minecraftpe

c18cf5b32b9d92e9ba10a48967181112ee670c67 pl.rlosoldidexplorer.unlocker

0a40e4ed62eb63fd84418857ab1dc15dda4f9ded com.lsapradsl.cardwars

65648618ea6421bd7a5982442e52c472eced04b3 com.dfestiru.fastemulator

7ad1608c69a6c6e00692d32353632f01fdb30e5d com.uVxmxy.mySAKzaE

bf7adb079b28eea1a9dd109600f7750b9123569d com.elatedroid.oultimatejuice

135edf4e9a96e2adf8588b164f25990cff366649 com.imnet.browser

9fd0f6d496468a20f474866f7cf9382ce982d8b1 com.nufolpinockstarwars.gta4

1e9371c439b5e0a38051bf6b6ef558db354a01b5 com.example.homeof11262beauty

29e93bc2af29cb690265aa3001ae1aec1617e465 gokul.supercell.hayday

f93d3b9a567d93e07e0850fd2cceb02e0b4f21da com.smart.booster.wifi

99fa9626eeeabe764ea26a39d2c6e0abe123907c com.forehdedit.google.earth

cc868919473ac32227f798e1e807ed49b2a50c10 cwem.corgwtrueskateapki

d1d033438f8b8984ebb3a52129b89121c6a9a8e1 com.poucenga.farmville2countryescape

58fb4767894adbaaebdfdf9a327b84474116afd2 com.tobykurien.batteryfu

789eb11aec83c28f2d2fdde374430b47479666f7 com.Antwifi

d189c6c360f4f4b7279f4fe29efe26e5fbc619dd yuiopkjhgfv.minnavinet.marinesworld

cd1e769f898419916035ac54388754c75b4a76e3 com.fueseveds.safterlight

487a728f724ce856bae768b4732eac7eaa33c3a5 com.nolanrtdo.minecraftpe

6a7d7f1e09a95ac016eceae59d9029252a12b80a com.swdetrard.titaniumbackup

93a516587d1d9c60ea58911e626507754e461bf1 com.ylsportife.full.FIFA

57178ffc5033d3fe5d8cf293e0ea58b1e03214b2 com.hck.parts

Page 16: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

16

SHA1 for infected apks Package name

8ea8163315ae284c803bd520e46cdc53c5fac28c com.lbras.gunsforminecraftmodspe2015

9a146b215efbc22f13805012a85b226146504081 com.ituyopas.whatsapp

d0b313c6787140baffaadbbf66a814f5ca7f60d7 com.artbtwodboy.worldofgoopro

43c71d3fcece0c31a00a8630c592e993bcc7c1a2 com.test.sdclip

e1dd1dc8d3bcc566a4e2303d4ac894f74bb85a14 com.lama.trueaexis.trueskate

a403e9af60a75202bd84116159b2b5c085aafe6f com.gthuy.mojang.minecraftpe

2b928cfa18d503d1a7e42b086ab80073ae6de33c dilopgrt.rkgames.smashyroad

3ddf654bb65b6db3d1c7d14a7e5d989335e790e2 com.gherufak.jumpingfinn

4e750c4ba42ebcf768836d6e6be851ea6e016e62 com.lorajackue.antivirus

c2a6a932dd4c0c37cb701932af2e25d7e6653466 com.senmtyuopa.gta3

064a78d7d1699bd20f8bffd863d4869bca38763a com.folpwsaygames.fnaf4full

0d4e09befd7fc963059278d8ec04e6b66793b9bf com.makacyenlt.stickmanepic

2d56c40d78e1d7492ac0f2cf59de49deae464994 com.brainyideas.geodeu.zrypaznxb.geometrydashthemev15

524be626c5a0008d681f55d8bde24ec0e68fbcef com.lopikjditor.mctoolbox

ffe339b6846ee8c087e65fa961064db7ca31afb3 com.sportystudio.askfm

9e65f3971ba3b9b669c5e769a8df30467eb68d3b com.fun.lock12302touch

6637569c3666b2328ec059c0bed2b9a889aac272 hiklophyrtdfd.gtarcade.loa.ph

8f9320eb3e41234cd09d26bac51ffda9ca09d821 com.folimareqwa.surgeonsimulator

13df23f43dfa8e4d43e7c3a41fe1115fdb304ea8 com.tgreagh.itraveltech.m1app

de67d90812ff028db72ba1f1e704db3734a83d17 com.gianonandme.candycamera

993120519e516d49c9e8f6188618985b1d09fe61 com.test.sdclip

466c96f4c33f122d1a52ed022e4f5f7894fdfcd8 com.ddlions.thunder

4fae87e8ac33d06e123e0e602344afde50cfbb44 gtyhujkolm.dnddream.headsoccer.android

017363b3f44d8920c5f8fb5a0b8689fb52dc8f61 com.rolpotx5sad.geometryjump

afb3193e6112c5218ef8f17b4ec8b296f3ba4118 com.smart.booster.wifi

a5e6b43defe73d839b48618c4006e0d0ab0863bc com.smart.booster.wifi

c963a1fef201b5ce22f3fdf15d35542865c72d31 com.mojang6tixanvrenda.minecraftpe

61e3eba91b23fe3ce8e27e22b62095567b60e60c com.smart.booster.wifi

6647b722fb2edd5b7faba36dd9264790425185cf com.roltox.geometrydashlite

8ad90faf2ae79a0c449fba381dc921c02331bbc7 com.rightswar.screencast

c2a76f0de7b04178d733f8b8e949b56784dd351c com.iolpuo.mojang.minecraftpe

286a2284c3e714d5adf40c4b8a33aa2257a32d72 com.jikolbrosed.copatoon

0229885fdb73855abde501bab22bcc6fa066651d com.hck.parts

34ebadcdf1ca5660f8262ac424615771f3e79d4a com.sac.ninegame.killzombiemayhem

a0d8e6369f2f7ce3869a08b33130c06fcb6b56b7 com.test.sdclip

d63671d227de6dbaf539e032f27821111c8a7dcb com.chiwodis.Edition.Minecraft.PE

5104c9fdc09de64e5969fa9f3011f90ce09424ee com.fcvcaapp.milkdrops.beentogether

Page 17: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

17

SHA1 for infected apks Package name

22cae78a15e5bb9f46f725d31c71cb64c8da28f8 com.powedro.rockstargames.gtavc

52859355666ef5899260e5b9e3b658ded105abe1 com.lyh.kkbird

2dd3c0b882103126bfd1f71c6229d050e394f95f jilopkyfg.wiziapp.app104473

1f0d3a8f36b23f0aaaaac9eb88660e3cb2f8cada com.ddlions.thunder

729ca467e999aba4ae34f1bbcb18348c4b858227 com.nadoturas.gta3

8840ef77a3529b68c410223b976f7f08c22c7e26 com.uVxmxy.mySAKzaE

3a59fa076415b5e382a12796dd36c5820ddf94bc com.mojangcota.storymodesq

3d3e67bd84c25155874ae2da376e5622c0b3576a com.owasdwating.star

e924485d119468fc1984eeb746212a4b9b8adb8f com.zakapoli.goatsimulator

ebfde5022530f57d73b2c85ee17b54b92e1ef4af com.sceiozone.snowboard

552458fac25bc209754c9ef6f97a5da5311269c2 hinolkfrgd.ansangha.drdriving

8f84d0d6f90bbf293288f162bb41f11d8b81988d com.gaschinell.clashofclans

474a4b87dcfcf4900d1fc328fae393463ebde258 mohan.sec.chaton

ab3834aa07d3ccf20e68f59175e01363b89b371f com.jy.moter.ninegame

a52fb1ccf1231e440ded442b57695ab3da8a7306 com.test.sdclip

1bb69094fdba7f94a7fc6aeb2554c5e10410310a com.uVxmxy.mySAKzaE

169471d4f8b931f29ae1372f19f9115ca547933f com.dploewames.gameform20

52013832b61dd5a0c1e6d6bf478ccd7da9c9ac3a com.uVxmxy.mySAKzaE

06f80c5eb1531921fc8f1fb74dc763c280f6b650 com.brainyideas.gtasantorg.uwpkmgse.gtagrandtheftautosanandreasthemev14

83c6c99b386bd99032abeb09bab694e9d92071ef com.chingasell.clashofclans

6493ae1983349c2bf411bc8a9e200c7612a4c01e com.asretrigcal.cartoonstore.cnrace

f985f41b23905ec5926c6c49e10fb65180b2addb vinodlijug.lego.bricksmore

e11cd763bda5fcced7baa1e3c2a849c0a4541ce8 com.fgthtrojkloa.teamspeak

81b7f79e9ccb189a848817ede92d3ada93a87417 com.mojangchinvolawa.w3dc.minecraftpe

f3144a8d9b133233f2570e754058e716b2221e31 com.tfacebook.korca

754bed2a748880bf7c3692ff18dc1583f741ba35 com.polugu.turner.cardwars

70a66844bf1b48c67b8a5ef5fc57fec48bc32f6f com.rotyuas.easy.goatsimulator

c59427d82c9f195c298caa2e8efd0197562eda49 com.armsender.android.scribbleremix

38205f949973db67c9efe09c40a698d17c606537 com.nobokajima.minecraft100

b0e5b12bc7f4aab6d0a74f0bb99fc3a9a25c1dd7 yhgnbvmjkio.tov.google.ben10Xenodrome

38c560d2353cb804a0f46a73449d25e5f3c23122 com.mojang.seval.Minecraft.PE

56a375e465827333872a7aa8f6fc455c01859a5c zdrtguiopkj.google.android.apps.cloudprint

0c015ee207f63f5e707939618814daabb3fa4211 org.rckubisoftpremium.popclassic

c2ca77c23bfcb4bd1cfcbbda836393d2492572eb com.allclear.cleaner.optimizer

8b36c04e291b165322077dfb32691b13482b43eb com.boplongad.geometryjump

c6e6e48e4132434cbd157da639230013d61b844b com.vocimithi.askfm

Page 18: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

18

SHA1 for infected apks Package name

125d24e47753467766f5892381d9be34a8a8fa89 com.mojangrfdgho.minecraftpe

a85d7592d2b0fb32d1787128f3daf22e0a1220fb rrmd.gameloft.android.ANMP.GloftDMHM

db24ee0f344ef7d9e233aae3634b870dbde2c177 com.ghikfadas.whatsapp

fde5e94badf8fea4d8bdf3d75280ba27d40e2604 com.goilei.stextplus

f9445bcc3a020485b3a9673932b1777c38e26a3a org.xka101.bqts

21dc08d034f294c4a169cc745be14b8079c0ae9e com.puppet2.tool

c7d3694daa13b4e119a1bd5670c9a93a486d58a4 com.smart.booster.wifi

846be5e638f1ca14ec10c4910deab61af6e806b2 com.stafedast.metrydashlite

ba9ec63c21f248eb0703f29ffe0257c313ae6d13 com.imnet.browser

0a4220ffdac4923f19950d8f198bee5f172d8322 com.blokwise.slocecnrace

78523a4a5c9870a55c31c2d033d853cebc789a73 com.mxterisdown.videoplayer.pro

1f66afc9acaa462167bc8fea5a38373083f014ff com.sidodroi.chrome

9bb94ac138c1afedd29b40858ddef52067eba83b com.ii.jj

1ffa4ebc651490307a1e066c1a4ed5464653e9c8 ffsedes.ijinshan.kbatterydoctor_en

a0de2228036c013d241f7d3d3aab6c34af18ac85 com.pelawanota.kingroot

b8f301b62eccb7d296ed7c0712816047ef3ed993 hiteshikolp.dropbox.android

e02f35e20a5b87f68116f420090cd55b41cc3f65 com.test.sdclip

403f91426081bd26b05500e211b0f1c2e86c4123 com.whangouts.talk

f6a3ec821cb10fd3002491bf6b7ae2243cecee51 com.ddlions.thunder

c96dceaf14c3eaf3c45b9e1a8a58a037221a10a9 com.delyux.galaxyempire

7e6dd1ffb39f08b563cc5ea8f9c2b13f8e9b43f5 com.wcsen.candycrushsodasaga

81f360de09dc2b83176d83bafb0651e8136343ad com.fw.myappshare

59d76d4a162eabc2a0d4f0ac4e7edf96607ec083 com.grokinot.gamehack.org

f812ab62b5f8c6f0831d97fae5dc0c8d34427944 com.waheifido.android.angrybirds

3f20d16ef9177902c1b245d5978361ee28672150 com.chicagoplay.cocoparty

6a0a94542d92223d5c829d3a4f8fbf5f227e17a3 poiullhygr.android.vending

d3cb4f70b033db410e40baa72ea128e321ed382c com.awero.mojang.minecraftpe

92529f00f0559bda721b3828602f2b6ec0599098 com.mojangfdrtnblk.minecraftpe

34ecf82769d423e2cbfd8ec1b2e8e33f7d82ec6e com.ghuo.magisto

8da015df9174bece9819eec303c804f58ab645e2 clom.oedgamestudios.empirefourkingdoms

8ce09642aee30037d299c1308cd3a0c138ad5779 divaya.brainyideas.legob

6ab001c8223bf19a1bdbff3ff7fca7ff5c7cf811 com.Antwifi

b9aed5d59bbf3833f0755fa1968cf30d27b038e1 com.uVxmxy.mySAKzaE

a01879d9353b0f67bcdd1a1b40c461ad96fe3258 com.hd.android.htube

b9b5f987f49ea69db0c9e1441c6b52ac5debbf8e com.ertunazas.rockstargames.gtasa

56892972a6e7c8c130c316d181a2bc02470be0d4 com.smart.booster.wifi

4a6098855d5c3b60f5522262180ff552e6ed12f6 com.akidolak.sketchbookhd

Page 19: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

19

SHA1 for infected apks Package name

9c4ad43ca99a9fe4ac1a24d89776248a69450d61 org.xka101.bqts

57ec7ae5162782f800881e8d6c4de9b913629ceb tghyujioplkmnbf.optimesoftware.chess.free

9a700e4877cc5e1310eb3126192827e17ba64464 com.smart.booster.wifi

82e04cb73d4e6369ee56936613bee264f6f1e1a3 com.smart.booster.wifi

c37ea15668a3371ab6f32f38a00d3150c3f595d0 com.brainyideas.geodbiz.doaxadez.geometrydashthemev15

6d3556c5e95d1141b2cc1c6527352b5c80e4862e com.linecorp.a143.android

3abc86d958913ddb7a44b22d0b77d54c284a54ca com.android.security

cd47e5522f1f5af3070b93848c9b9eca14fc5ff3 denimuyhjk.com.jumpgames.rswrb

a39c058aba3588033a6253d22bbf9d38150d1593 com.lovalame.loft.android.anmp.gloftsihm

ac1eda7fa567618520062b9037ea3d9b977adb42 tyuioop.HardTime

f52d1cc1347fdae2a551147df810736664d58c08 com.fordonetyu.rockstargames.gtasa

f0d86c571fabbebc8afacbc8cedf9345aa3ee0df uyjhkmngbvfdc.mastercomlimited.plumberworld

54ab87fffb896e472390a7823237e192096cd8b2 com.ddlions.thunder

1d846db649d27a141ba73bda8036b5ecb9d4b332 com.wasoutfit.mytalkingtomfree

960b53350472a56d1778ba5c7c80f7d1ddd381d7 com.ddlions.thunder

dfbd885f4cf69db9cefbd7cd59d0e68be25924a3 waqdcfrghjok.android.chrome

bd5422bb39b4a47fc008a436d302ef7221602438 com.gfgringad.geometryjump

1c29f325e9325f1b9ef06f69396af2ec2406ef93 refendi.zhuoweizhang.pocketinveditor.pro

73e059129548158df3fb2ffd97f61b036592448c com.peokluar.prizeclaw2

71ad5ec4b624e3294357eb7b715261e91b4bda27 com.funme.assistivetouch

6474be0ebf4fe04bb2e407565489f63d81edc30b fennst.supercell.clashofclans

f6b44dad5bd75a4093082fa180158a2c59534c93 ftyujkio.mobadu.Maze

2d258db4abecc2794e5d82e09d0fd2b516a2fdda kolktafghbn.widgapp.NFC_ReTAG_FREE

dddbeaa558ee9018a6bdcb3beec6c2deb0cf9a77 com.poswafree.whatsapp.sniffer

4445332984dc38bb6cbf7cac8c8a26d3e81d66f1 com.adowknok.videoder

a3274ab7b02a4b8b678a8c9ad67dd341ac0fef2f com.fopowqlsde.mobile.metalslug3

32c02d978c5268c4035162c1196d163ad4da592f poliyo.underanime.android

641133ea985de5e0264008cda3f1b96d07f59e36 hitaeikk.mozilla.firefox

69eda884ed87b7bc714319f88d63da08262c3fc5 com.smart.booster.mywifi

5cd687f4695cdbfc81a4a3a814216496e70cb12a coryona.trueaxis.trueskate

02189ec00059eae8e72a77ceb6774d3580794050 com.themesapk.appleic

2ed068d36d7a8072dfa56e55a6ac5463a33a7080 com.pinkeolash.geometryjump

991c676d55b369f0d21fd5acc23075f68119f304 com.uVxmxy.mySAKzaE

0f4693956191b5ce4d75ce8a18ef9d63c1b73e92 com.vinayakapk.jumpingfinn

a12f172427f22084d8486aa90c91b10801d36772 com.mkolpongad.geometryjump

d6be56ddc4bef3095a77f81e1425cbe68cefc850 com.poacd.projektred.twbad

9cb0472405a9926afbda969e82a0403b49aa22a3 com.stardonet.metrydashlite

Page 20: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

20

SHA1 for infected apks Package name

e68c4dfdbd7ae9efb7e4e5dc90bb6b4ae378cbf4 com.hck.parts

bb4b62d80bfb69dadc0fdd83123b956568dec205 com.legopus.lego.bricksmore

c57cd8cb35fffc67d937b0aa716e8f84983a235a com.ceva.redkstargames.gtavc

ae5e241da69bc9b0aeea3dc7d2bcf9acc70d5e90 com.konatam.kocmobile

b8e8d958e614c14b5f65e25cfef4ef1025fec73c huikolpmj.com.jumpgames.rswrb

8111cc39180ae9f6148e80a46cc59bc932c2eb7a com.donenjaim.gangastarvegas

cd82556643520138150282dd5c60865da869f9cd com.sexsne.mat

699047582be206a650967742b7119be2f69bfad0 com.uVxmxy.mySAKzaE

895bca25a588771fcc64e4cf0480687f5a75dd64 com.Antwifi

615cdd66e646ed096e065ad16fb2b5ba11d9ed80 com.crescentmoongames.blokcy.roads

a72501cc64d34e934ed88992a6d3f80d659eebaa com.sevabanare.Minecraft.PE

350778b615f5ead626e239b930dc060e981c9c1b hiteshu.fingersoft.failhard

7a84b3b1539c5ec4709c7135aa74bde0a5c99668 com.jintamaintra.minecraftpe

1cfe3a5b3dc443a38695827fa51380f3bbc876d4 com.apkinstaller.my11251Cleaner

6ea5b064a9ba4928265dc95445d3aba6327e1224 com.chichonala.kingroot

277b944c9a6cc103a7af542f83b7b1c9be3e195e monalikderf.mobisystems.editor.office_registered

652cdfa5e253cd01ed2770677bb1ad37553b1116 com.vaedarek.electrodroidpro

5525f9d616db1b246eabd366f9fc250930b62ae3 vinod.droidhang.ph

b4529d2dc2fcd1b6674df6dcbd41a1da2e52f610 lopjmnkyghb.Relmtech.RemotePaid

1001950c9d69e40c507dfb62f78e7df99af2ef74 awedrfvbhy.socialpoint.MonsterLegends

c75037e178146293ed03576ac915951e54aeb7b8 com.sealbrocks.fruitninjahd

b9dfa01e167060d9285965b78a5bea838e675c98 com.android.security

41f3d484c4bb71f3784c15788b917c5f08680a97 vinolikasder.ppsspp.ppssppgold

88c39676f92f1d802d3be28affad9d98c32c5934 com.example.nihao

0af124e98626fdbde9940bed84f51d8f917e8814 com.dakseplodeui.letson.mobile

0be1b49814a2750d148ffede31db6f7d80128615 com.kutawil.erire.happygoat3d

fa5faf1cf9d51af493b21189db3c8aaded1b85a7 finoluhg.fc.snk.nine5.mobo3.SuperMario

b771848ea96aeb2f6d817a98cedf66fcf0f5e3fe com.facedpolwaq.facetune

1d04857bd40ad70060eb2dfc69252845b5408ec1 com.kecamoul.republique

9bdba394275a49fd0215114b23b43857005f6d28 com.test.sdclip

d46251d62e10182a74d490c000d5467891dd7ebf com.dcavally.robtopx.geometryjump

06f2dc278ed37d206956165cdf3f27120ad052a0 com.descotla.fnaf2

9c7da2e115c2cd40c05ee8add56d1e003acff915 com.funme.assistivetouch

0d268f2c47eebd5f6e28a666f1a00d571bf9393a com.folpijapps.remotecontrol

907c167f552989fafcfbdd5be3e7c44bee05b4fe com.ghorisakolsh.LEGOStarwarsitscompletesaga

8215e8021ee5f311366726d6286ae6c6ef9b0441 com.relobond.mc.sq

cb612dd59ab5127919a3414ffd753ca4b99c55de com.lego.goog.lnjgo

Page 21: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

21

SHA1 for infected apks Package name

6e17f812046f5fcd85b9b64737c92d283d4947ed com.bokajinoma.minecraft100

05a8481fc2324ab4c15fd489b41b4c5c76ebe81f romino.t2ksports.wwe2k15mobile

5608466dc6dffe6b949a68acb062c1388c32134e com.cefspandroid

03854e8b290d015509294ffcc4b3edf8270d6d4e com.ddlions.thunder

b20b11919b4fe2a4999021665c0752b62650659d com.reruerb.checkout

1a6a175951973a6a84fd66cf7c40d81792ab3c74 com.brainyideas.gtasant

682c453bccfe07ff81324d3e39737f27ae41e306 com.koparrodes.rockstar.gtavicecity3

60b4b78e83960aa4defc0a7b3b6450e80eaf6929 molpkujhg.dianxinos.dxbs

f0281eb165820da56e9ccc18bceb39067ce65c6e tiuyhjkolp.eamobile.sims3_na_qwf

1800aedc01ea3181e331776f104caae07b161128 com.gamekiller.mojang.mc

75ec58dc4147a8e2b041f99e55d84db8b0721bfa com.test.sdclip

5660d32654a564e398a94a50620c717cf2248f5d com.tuners.rockstargames.gtasa

66abae610c0c35f0dd580dbcc923878df73bbb83 com.uVxmxy.mySAKzaE

7ea2b3e966d6ff127f06a3c6d0ce3aabcfa3e1dc shreeji.creativemobile.DragRacing

7a1434ddeddb2106acf89db9a0f11db02c1bdc40 com.tobykurien.batteryfu

47f618f7d1326baaae768fd9042562abecaeb7a8 com.wasjangad.geometryjump

e9368bad6592ca4f33018930b2bff683ab09712c com.rodesopar.rockstar.gtavicecity3

af9a74fbc562decafb1b81d75468ebc8748efc77 com.movajand.Minecraft.PE

9d6ebd46dc940618723fa724d25dd75a24afffb9 com.example.homeof11262beauty

a812e4f9d43133a33989435248b69f3cd7a4dffb com.awretrigas.mapsforminecraftpelite

fa708c0fa728ebb7a9a281438cb290cf2374f80c com.lonwala.kingroot

f99e3a1a7c846beebd8acde8f088495f74a8865f com.foitradorngfg.mobdro.org

a31c69cca6e2e901937a04b6b9f81b06f98a8fc6 ioloyhfrdcs.mail.games.android.JungleHeat

37bf0f78aab35fcf7182975b4999e859757378c0 com.mojang.application.minecraftstorymode

aba137c31293cfe5834d7d740530b7637e96bb54 com.julian.fastspeedracing.cy

e7d9e21f340a415c1cd1d2c953798c36851cb3e9 kolpimfrtgh.facebookhackpassspy.com

e8affe5f2e658d7292273b80cc73df7345fe0c0e com.felophis.googlesearch.org

8021c9c0f612b7434f0432cd3bd802a2f97cd8af com.gameloft.android.gdwangloftm3hp

a6b814766c6480a572b8c6c705968d4bc49b7f8a unolikalisegh.king.farmheroessaga

40e5fcb0e57644f9f6f214d775dba2f92ef4493a com.kegitlp.nextlauncher

5405666770bc15cd9d563643993e162a1ce0e3a0 com.example.homeof11116beauty

f7e5614c1f2f5b44109960f97c93025285f451df bjuilopkfrtd.dsemu.drastic

63ff05edb9ca81b6d59d02c78b3850fef615ee67 com.rockstarbhikrawadiyek.gtasa

b349bdfd28966b2cf0fb32b071828f1b5ba1903b com.maaircomndo.airflight

12122c2c8eca75cae7571b0c727b9e3ee14e350b ghiolkpderfg.cleanmaster.security

d8dfba56f04d56dfa0502d6cfef055419ca9862d com.forplay.android.mobile.Terraria

7d77884aa564916f4a24fc8823be1f937e0498dd com.robtopnews.geometrydash

Page 22: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

22

SHA1 for infected apks Package name

2c421744d50c1bbd4099006534eaa2519e086226 com.golimaru.leaguesa

e3ec598fbbc0e74eee28956e2dd440fee93ac89a com.mojang7tixanvrenda.minecraftpe

2629ac389d48d777f3dd8bf0a776ff475b83455b com.forplay.android.mobile.Terraria

6cbad6ddcc84fd543d1f8d8e5e9f03637a1cfbaf dertyujhb.chobin.android.psdx

149c9d001b893105c199f18a033822e76aa421a5 com.actionofwars.clashofclans

52692a7dd0eddb58df63c74de333d14a9b79f37c figarolkj.dnddream.headsoccer.android

ae0882dedb5621ee35d61f5b5666b7bd2b970869 opilkuhyg.fgol.HungrySharkEvolution

0a5216400e637975e5575752897628d1e0a2b704 com.beojandgo.minecraftpe

d95c4b348df1e45c154a4510eb95d8c579a50b83 divyan.forshared

d79822250bbe503d151671cacd0ce9a992ba0ba6 com.uVxmxy.mySAKzaE

71e5bb5cc3ee063b667acf15a8e47ae030e888da com.uVxmxy.mySAKzaE

fb8f393aa88afba5698ae4f829cc501934b571be govimnople.runtastic.android.pro2

836b41a5346c93e16ad5fa35bcd07fa87c1ccaef com.poke.car3d.shanchuan

992c289f6844a00527ffa7275b17a44b1d9c127d com.brainyideas.geodbiz.vzhgpswpm.geometrydashthemev15

3dce519626c130381474550b9435ed3bad9b7423 gangabjuik.king.paradisebay

4c67a3aa40406957dd99446a8247645c0dce46b1 com.lsapradsl.cardwars

2b7421fd999969852763f541b2dbddb3b8a2ad2a com.test.sdclip

1f32012ba224b5df29a0a6a468fcb5af7222d4e1 koluihtvinol.qihoo.security

323eb2bae88fc8f45744db044d3de302fe2c5e3f com.voranotam.music

3316f26db616133bd56fec5ac36b86fcd0da5992 com.golimaru.leaguesa

b75c7c7ea7a58792ce1aba85dd8f8411e6ee847d com.brainyideas.gtasantbiz.zqqfj.gtagrandtheftautosanandreasthemev14

500e7bdc2a08beaa8e787d4104c13f02dc41484f com.faerwstar.barmfera.gta3

312b2f26e18aa471bd2bf4b146f8aa63486baba4 com.aghosnfull.gtavice

19e235840ccc16485c12f02181f36da204509bda com.brainyideas.gtasantedu.tszrc.gtagrandtheftautosanandreasthemev14

3704711eebb4f3bfdf4feb38588984e04b520945 com.dewqawstar.barmfera.gta3

e531b096c575f196943770fa64a193a86bacbe8f com.smart.booster.wifi

886f8617b1b0db89023acff8998bd6439a9be5bb com.dromakala.ANMP.GloftAMHM

f9dd25458271f73d16d94462d364e4d0c619c315 com.tobykurien.batteryfu

d217cfa1ca4e78184f228ea50e9438c6064e6c00 uliopjkmfrtg.saradiogames.fiven

8d0107b95048c682940ce895708f94582304a002 com.polimetric.GangstarRioCityofSaints

ff7cfc1277806e2668dabb8e26b63cd876e3c480 com.kitanemaser.bocina

8053c141b5dd2a0508f713e65eb10e943b22a089 com.brainyideas.gtasantbiz.tmjkgzavc.gtagrandtheftautosanandreasthemev14

620718d6c3bf126f45c8fa680ae8f88b8901e185 com.nvbcngad.geometryjump

Page 23: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

23

SHA1 for infected apks Package name

7bba357218ec919b1311b5c7fa85b61794eb9119 njioklp.animirai64.supermariosixfour

b4a3ba7655bbcfc8aa10c36feac1b2659853e750 jom.livyanotaput.turner.cardwars

a4cb5978e8af4bf65b7732741469793638b5455c com.andrid.secuty

f6c0621f58c99f8b0ee095c267f54056c78bf6ea com.actionrockstarwars.gta3

490f1aa8751ea1e24faa7e914c5d2884ce2a6e30 com.pokiiskydot.vector.full

320df20f7893b009f02687e74d1c84af2365abde com.fgvjb.gokeyboard.langpack.es

d4f923e976e752de27cfd0ff0c610e13fa98eb8e deloipkmjhn.evilduck.musiciankit

53780728204302a1ca10b29077d6d01b78b2a523 com.mojang.bokanetry.Minecraft.PE

401e73ae754ed167af6c486e65ad38666d443e94 vftgyhujik.avast.android.mobilesecurity

922405aa6996723e8460ef57c76371d21164a0ec com.jackichain.geometrydashlite

b28d8069c3ad895473e9b004c1b9c58898452d70 com.test.sdclip

a8f25602e85f457e0846896e1e0ca2ff8f7a8b31 jolpkiubgfv.bfs.papertoss

a4ee3385fe0167eed62182bc6d5ce0213c201a52 org.xka101.bqts

5740cecdc37ad9f9d68574f9a589ae585f2ffdeb com.ealaogames.simsfreeplay

8d2dda6da1d89bd4bd56bef3411ab58425e717ed jodhaakbar.google.android.gms

18c6002144313149101a79586683ed186422b7db lopikgtyfvb.ecapycsw.onetouchdrawing

ff514bd8962fd76d721e19f6fda7479772f505aa com.uVxmxy.mySAKzaE

4fdcecee55b5455a1968112114c85a812d5926be com.kingroot.gamehack.org

51c51e8e977bced868fb27086642d1f5ecaba3f7 com.receiogames.nfs13.row

e2a4837c581ae553f7e47e79ff5bcee6ed255d2c com.smart.booster.wifi

7d5b0e7f6127aaaec49d5bc33051cdb7d821fec5 com.lyh.kkbird

18d78edb53a1947c46386c9e856f81e4b217a111 com.rolpotx8sad.geometryjump

3297cd7f68c33c64bf9aefb97fbcf5b5985c054a com.dinshawaoting.star

6450e391d16481f7354c9e06d83e498cb4c1463f krishnajsk.instagram.android

867bb266c1891c421d824cfb1712598f69e4f92b com.smart.booster.wifi

94e1af8ac0ea0c2c0e26e7436a41e8687d26780e com.ifgbvmojang.minecraftpe

2910191f70cb1f222675824a84234a2f6b2a18b0 com.loriganad.xposed.installer

9d7274d9c638b5c8c00be5dd153ba19d6baf51c8 com.polimgar.photoeditor

44b14ec2b4646831de799683a767f6178bf08b25 com.dafcare.tdo.showbox

4bc84e44f3e9d5636f9ef3a5e67c6d30bbfca15f com.maboirajag.cardwars

5fecfb62ec1159a9fb2e241c77252d1a94f8802c com.femizone.google.android

95a2734bbcc2720e03cfc0a7030dc534e1f52850 com.gjurora.zsra

dd4524d36d8b68a25b55e475e42fa8b99a085b68 com.doodle.turboracing3d

acc7d273848ad3cde6bc4133b6d1fdca74c32e4f com.uVxmxy.mysex

d97a7d9080f1a58893b910581f1b7a1754889430 hhpt.evernote

b48523f124f3ed395b2bde4cef50d769af70efba com.poliugue.minecraft.story2

83c62e9655bbe1faa745e9def963f2465b2113fa vinolkuyhg.nekki.shadowfight

Page 24: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

24

SHA1 for infected apks Package name

efc8f7bceb3d327c97a86feb373d4367b3f51e45 romrom.turner.cardwars

faccb3cb140ca578a535b4d99e4e3bd43a9f1d55 gbnhjklop.igg.castleclash

7cb14fd0316eca48f1641fce544db316c363562f com.test.sdclip

d54045dca2f8f52ed73acb048ca73a0a9680c7c1 com.test.sdclip

4adb5d857ac50f54a42a37b2a39be2342dfe805e bolerdftgh.estrongs.android.pop.tmp

850b7baefe1ffc250f2356f1040714fde9110a4e tutanota.spotify.music

7c87c6c088928135de7f604ea9b383560e1a9aa3 com.fw.myappshare

7eb3c3b2d0e01d6093747a5739b18ddf94b48dfa com.finalminimob

e60ca84399d004d0f7fbfcf0b9f71ed5b36194c7 com.freetomy.mytalkingtomfree

9a5c88aeb3e70a85b8a65bbc0e2e4239805290be com.rolpotcdfasad.geometryjump

de1de8a4dbc4d4d9614d5094baab036224695d34 com.white.browser

1e8f91e117fdfe98ad36743cf4306bbd0a5a44a3 com.vihants.nno

8af64d5eddcb69f93affaf8b64b3af8b5d3c65d5 com.locktars.rootcheck

594efd6f0f6636c43619d22bfc9c17816f7b3327 com.ghirotas.prisonLifeRPG

83a192b02bce01006a9c4c32ba890401a62bab48 com.brainyideas.gtasantbiz.svelr.gtagrandtheftautosanandreasthemev14

a0df44056e5a9d2659668d159e63ef640c5ad3f5 com.robtop.geometrydash2016

390b8d145aa9ca2c6d7e2210e92d1f0a814442c0 com.munda.kyrlo.pacmanfriends

17fcd6c9d98bb3a7b1bed108dd093f8f56a13877 com.sac.ninegame.killzombiemayhem

d73b999fb43bbf32b5473815b15a2e5a10ad66b5 com.elopewator.deadspace.fordhan

318e9cc28bf757d8a4e8b4dba03e7ca2b108d38f com.minecraftpe.stonegaen

ee1fddb4f4daafcb9ef86fb29c718655a9b77a65 titonikoleds.ea.games.r3_row

6a58f69e9e949556ebc3907de0ff757d9418bf3a tyuikjmnhgbvdc.disney.WMW

7540354d746e793ddee34c33a38bebc1614afcc6 org.xka101.bqts

09749ebd382ac235bfa8624424dcf29c356b0c9b com.vaoenamobile.rasaw

5fb0f83cbe6a00f9013d3a01fc31730d0066a657 xzcdfvtgh.amphibius.prison_break_free

421e5fd8066fb6482bced8cbd1e49415527751d5 com.sremal.capinstaller

1191e8565538f238d9514b1590cba6cf8819fff6 com.brainyideas.gtasanteu.ignhp.gtagrandtheftautosanandreasthemev14

de763aa829770623dc8596989e90d279b50ce260 com.mojang9tixanvrenda.minecraftpe

d5e7b9463db0f7ee1ca403ace38d162780e8c14f com.eqtjangad.geometryjump

ee57a719cebf83c17352d6b5f019345a659c4db3 com.pinachgh.bikmimehack.org

351b83b207fff6c40ac39a0fa9616944d8bd1dde com.dockrawa.screenrecorder

1f2d95cd8829c53f9584dd52bbfe580dcc49e6cb denimhjui.lego.bricksmore

8b2a828aade424cdcb2ef79ce46d3e8b5f436bf7 com.lagrik.supercell.clashofclans

ac0862de676e755231aaab307d5fe28b927d2d40 koiila.supercell.clashofclans

9a6a32012aaaf9c500f15e6946274ff9ac4d1b1a denilouygghfr.avast.android.mobilesecurity

Page 25: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

25

SHA1 for infected apks Package name

1cb150a990f1914b25c0a7ce541c2ba71d93f83d com.droidhen.game.fishpredator

fc8697eb0dff9614595127cfe4a542c92c967040 com.actofwars.fnaf5

000cd99be96d33eb4ae348228a3119c81d0103ab com.ytfawara.Minecraft.PE

b5cc87e7c70b355082deeebeecbcbc55a0f3547a com.sac.ninegame.killzombiemayhem

45cb4479f7a1ce3f7618621953d09736115f8eff com.koncreseate.mobile.epikskater

15f75a0061e9613c96a2af1c3b8a6eb0b7090a4a com.forutosh.hitmansniper.org

63439c75aae19b43c4cc59a4d89de9659f1b7712 com.jkolpwstar.barmfera.gta3

3e752aa0136da8d85eb15bb9c588ad9f793e81fb com.example.homeof11251beauty

d2e2622024b870bb675d56372af101194b15bbf6 com.smart.booster.wifi

baa34bb7ec296517919bd5c9914c3054af0ccd8a utiliti.nekki.shadowfight

a6c8aee4e9c951cbc157ce974aad0a444fbce585 com.beice.games.racingrivals

ecf96cac4862ba99c6ece98714851ced62b0342a com.brainyideas.geodnet.seoskaxr.geometrydashthemev15

9fe8a5925e38c1cf91c0d7261b53d22ddd9072fd nilkojhgvcd.v3s.furious.traffic.rush

030ce7991dd4f53eeda8913c0430c8ddfe40eee7 com.smart.booster.wifi

b0954388a0a71d557853f3ec6c12b42412606ad6 vinodlika.creativemobile.n2o

f71e5d079879aa26d7c11ad7b783acfa1cc986a6 com.mojanglinkijiki.minecraftpe

ab68ff0ff6b8b84785c40cae7363bb51e7f22105 com.funme.music

1f2c459ad535f8a47a67b703ae09db3eb5952023 sishoklrcvf.sbtools.gamehack

d5fb646b4ec353abb6a5bafdf07683914ee7bb04 com.white.browser

9a6ea70391177424e778e20cefa93024fb82b590 koplimjufrde.tivola.horseworld.full.gp

35d60f73f1033f68f0b60abd2fcf0df34530469d com.aspolidics.turner.atskisafari

541cca0b9a45f51a911f2b1259a90cb3a8a94bfc com.fun.lock11241touch

1dd23b23f02e3748b300e681247b5cf65b72b797 gognoiuj.amphibius.prison_break_free

a71e833b47e3bb396fd940bb744d39c388cbc72f com.nhtyuiongad.geometryjump

3abb8a53fd906ff1b60b626c2d04c2278ebbe09f com.stoneforam.music

af70b2d0b0d50b5a8aa979610e6a33390aba65ae com.morden.pixel.Minecraft.PE

e3d7c024eef23e8f9f5f0c9e60aae07fc06ebe61 juliokpjmn.viber.voip

aa366a2899e67ac23be27914b9a942dee52b8143 com.erthyool.wargaming.wot.blitz

8d9a0e908e09220eb7c21183be8eeaec3a3723fb com.lglopaa.boombeach

138eb1159bcd9afef9468eb5503e3de402937190 com.j9b.insaneEmoji

d1fed511fb6d8b422bb6636aeba3fce2ca535022 com.white.browser

4cc141bf9fdd5f3cc2dd9b03054a273654668791 denilkopjh.unbrained.wifipasswordgenerator.app

3c029b21ec0119a52f38f4ba353b3746f1a1bdb9 com.yhjabanare.Minecraft.PE

59ce7f40ac0b812c9ed8ce59ad398cafe7cf35e7 com.ghotrawad.titaniumbackup

464dc8cde679d07e1688372a1c5aafc14b1e6646 org.xka101.bqts

5449e628112b92a3bd29a5f0969259a95bf55b69 com.gwasdaolug.rootmaster

83756238ce8f32756867161c4c22a7b430c80038 com.rtwara.Minecraft.PE

Page 26: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

26

SHA1 for infected apks Package name

a89cd8b899710c26d69b483a506543f51aef67f1 com.simulatorfortuner.AVPE

9cc77a5e6df4969f93f381aa9b3ce6a11270ccc0 com.HungrySharkEvolution

e6f7cc6cffabe3fde46e434a21338c813650db31 com.uVxmxy.mySAKzaE

fda1e4f84bb5985a2e3e05e194bca3262d77973f com.sac.ninegame.killzombiemayhem

21c429212e09f99a8c8788d7bc93b55fbe3dd9b5 com.droidhen.game.fishpredator

a4efe837a5eff2452c2b841171934b0538b7bca1 com.operaoff.shooting.star

5f85d93d940bb5dd5aeeb0abe0a0bbc6d5731b09 it.aciaus.cnemars

309c4fea2944253da494c45dec8f5b6cfd936989 com.cfvrermfera.gta3

42e33697420f367fcbb67d0d58e082bef196decf com.test.sdclip

7aaefe3750aa305b614fd03c01d581eb6ed3c0a9 com.mojangpiranha.minecraftpe

f75fc8d3de8071a90b6719c2ab2054af7cbf2773 com.funme.assistivetouch

8ab76804642a2ea61b7ccc03185b7ff8362138f2 com.themesapk.popinsic

bd5216b6638f2b054548aabf0d7fd46c7a8cc548 com.mojangchinvolawa.v7bras.minecraftpe

5275db5094d6b5355563d7a8392041d38630da4d net.betzhu.mcpelauncherpro

a877536edc3a36e44131b0b52f88cba8f47134cc hhempler.installer

acd13c7bad1c5fb0d70c28dde6ccd32da838216d com.uVxmxy.mySAKzaE

31234c8f6aed9265b3a4559c759ad0cc7346d2c9 com.gpleds.king.petrescuesaga

79eb388bc1d54a7ac2cffbaf8259b48fe7e2f56e com.vepaoer.vending

407da8a3396111f00cbe6382e24f152a45e373bb com.ecrerscell.hayday15

9224def779f66b58473d085b9d4d0c42b2734120 com.saxzasrow.needforspeedmostwanted

12f537d708b33867fa97b97ef99be04ca6617a50 com.remhid.senrida

48718d9dc211ffbe427bb4cb15f63052c1c62dd0 com.mosuleud.mosa.puffin

98731ad01766fcf9d3a5fa7d1cbc1a786dc8180d com.nafagma.games.bubbleblast2

73c4cf99760bdbf31ff3d4b3f453c2586aa4c742 quloipkmjnh.sega.sonicdash

5b72c2ff76b142c80d9e78910b0bada66781cb04 com.bedotsgears.flappybird

6a4a300b027ea17d597c6c0e101ea0d96c7af66e com.n6.phonecooling

d680d26451e1caacc418c41f2219b3d427f9fc4b org.xka101.bqts

c39fcdbe3e82e23cc831f1bfcd1b656d2dba35c7 com.umangajohn.mcpelauncher.pro

6b38b3a95c7478ad3d79f21af40e780aa0338f53 riopujhgk.dnddream.headsoccer.android

9a17e2a45eef8b9021392fa5377ba5a1edb5fd9d com.white.browser

8a919a45e5e5c5a03e24de25cc32cd8b47ff3cef com.foplaiele.downloadmanager

773a662a2d0cb148460a697a6cbe73c7e25e7b87 com.qsaswara.Minecraft.PE

10f26239e5adfd1cc190ea2d26e72c0f088d6ba7 com.chawajad.mc.sq

e64b1276f71109505a01b6236f5bbd875b7cb735 com.lglopaa.boombeach

e854766aa3b8b773cee56defdcd2e056bf232841 com.kinjolineira.geometryjump

de867e37bc9badd438394136b42264c5250f71f8 com.folitutor.mctoolbox

c52968ac27ef6df3c902869383a9b90705511293 com.white.browser

Page 27: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

27

SHA1 for infected apks Package name

db7a3bf81d51d55cb3d81a36d034cfef9c10e53d com.dyacars.skinsforminecraftpe.org

5b8aa0a77a1cbac38587e9577815b9c606f19113 org.xka101.bqts

0d44c2a87f355c569225502b026d01b88e490300 com.mojangfosaphlate.minecraftpe

3632a379e432aa48b786bf71b7d243ee6baaf46e com.funme.music

b12ee63b186680810e682b024f6198e38bc476b4 com.tpad.change.unlock.iphone5sfour

145c6cb21e39f399b54570401b12bc1816a2faba vfrghyujkic.mojang.minecraftpe

6cd180e4c59785838e33498cdf102b8319059089 com.tobykurien.batteryfu

7a160db13ac2d6aed6c744754895fd438fc2f4d3 hilstsion.spinmaster.techdeck

16144de21362559ab7e646c02682d1719253d388 com.gangsaga.gangastarvegas

74958c0a7838dc9d233ba409758d7ddde074fcc3 com.smart.booster.wifi

851230393d3d0fc3d133dad7f39d5ce4c87c837f com.sac.ninegame.killzombiemayhem

29e6f508ad4aad11a6f8ffd0ac43bd0f5064afa6 com.gamedaycty.room3dglobal

8b707716b730fcb7230ee5f87901524550acbf5d govindhjk.cmplay.tiles2

fce7cbc87b7c203fcd127c1974b8f5db2f14ffd5 awsedrfvgty.com.jumpgames.rswrb

034891c110b56fe2d8a32dde7bb33b5b569b2085 dilokyhjgf.microsoft.office.outlook

d0610f56bbbe1d0e5a00b9c25d3f07921be4b0c6 com.hck.myplayer

8fe6a00237e25f1b4897d3e4800606957c5c6e15 hendigyhuj.instagram.android

655de1055e9b16176b8d234907bd7bdb5fd53ad0 bilopentyuhg.creativemobile.DragRacing

cd7f5521f1cadfd196c101c5c94880966e50d7ae genffe.dianxinos.dxbs

e1cd8d1cf5b98f7a21525df3534fc064106f2af6 com.auelk.game.pacificrim

786e522df0f76dfc1219c78982d65826979899a4 com.wadafitu.setcpuforrootuserspro

27152a66427d4fc860b52c8628f6efaa09e5c579 com.caxjangad.geometryjump

6de2312df83bda9068b9a271ccf05194c4731ec2 com.j9b.insaneEmoji

e7b682095365bde56ab92f4801320a691dd5b96d com.sportylife.full.FIFA

993ae494c3f88e0ddd0878feac6d51927d65747d com.kopeer.modsforminecraftpelite

b614185a4e775b6a48ec9708a47c13f080425a8a com.sexsne.mat

88180072271b8a853e33131e7798731de1452ba2 com.dasakeg.midasplayer.diamonddiggersaga

26d670659b8f6c2167f56c00dea34f3530b833ce telinorhjk.gameloft.android.GAND.GloftN3LT

4179da227acd56a63b9df3eebaeeca7429f9a994 goikljhyrdws.miniclip.eightballpool

eb526c97bd836eac7f9de233b8d5031cd0b99902 com.Antwifi

a94f770fec61c23d928e762017098fd438ad3509 gopalalio.lege.pink

f9e293db5b4ed25899ffceaccd68de99b30bdd7d com.donetface.king.farmheroessaga

f8302d81de8fe260145f339c1bf085a2dd92cb23 com.kk.desktop.brow

7968fbb3b689ab764f6bd2e2a6782d8eb5f852f9 com.benjapal.Link2SD

faece629a7d28579692118d28e4f11f53f71ac64 tilopjhkmn.gameloft.android.ANMP.GloftKRHM

59fc32cc12d3809d47ab36abfbd183e1fc075574 com.smart.booster.wifi

eae0d5f02407822b5daafd812d5e5d25c905d535 com.mexteich.mxvideoplayerpro

Page 28: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

28

SHA1 for infected apks Package name

3ff64d96f4eb0bdceacbafe417582585e1fa5190 elopujnmhbf.playmous.godoflightHD

351a79f41053ba97f4b6d0b41191668e7ea33cff com.funme.music

4edd402995997632d0ee84f3db9ecbc521a7b133 com.j9b.insaneEmoji

74df3eca8c231af21d0e0dfa666db461e56fe3e9 com.dorasoft.raymanadventures

48f434b8677231bfb3f02dab389bf9626ea1b6d6 unioplkhg.devian.tubemate.xia

e7e26af1ca03ce472735377bb0b0fe071eb12acc tilopyuhjg.moonton.magicrush

c1679d414b2a73d9336788313855a6fa1a1d0a7a com.hd.android.htube

d2c9a1c5e753bd1cd1489573acd1936e95d7620c com.fw.myappshare

a34797356bf04abbfd383d7f4b55be064242a6d6 com.andromo.dev354080.my11191app412250

14bd0bcc759bc6f0e24aa3e09253f92ac60e2a2a apps.felipboardapp.magazine

4d3852a213b1887e6f70a3e3b661add080a56824 mobi.mogvek.tunnybrowser

11692c0e95d3f3af8c8fb3d16777ce9e4e5ccfe2 regrete.ciegames.RacingRivals

aeacb6f2cc05a59450f9d801cd8b828d875b70aa com.uVxmxy.mySAKzaE

f05dbc1aaff833db4772a146e79d823f4a0ce47a com.pelajavanori.turner.atskisafari

3994bc39c88ce56ff4fd9389a1137bebb6ef0571 remmre.dropbox.android

bdb06209eca4194e522087658efc0010188ab5b2 hioplkmn.google.android.music

1775fd0baf83c55c9e5da1fcdbc11fb50eaa36dc com.yhnmukl.mojang.minecraftpe

0fc61f21f7d46e70b3b2f0726c5b34fc52f80ef8 govaliuohjug.miniclip.agar.ioyuiu

fc7dde65e2c047b76de38d4d748987a669f6bba7 com.donshooting.star

2090f81f2ef614af8463ee58712666763763282a com.rolpotx1sad.geometryjump

1f8078e9d6ffa22501ce8a90495b52e76774c973 com.julian.fastspeedracing.cy

0472e65eae800b12e83a418732fb4a551b701bd4 hiokplytdfcv.halfbrick.jetpackjoyride

b654baac1ba555fe5248457acb53577cb830dd0c com.funme.assistivetouch

2f5d2836bd0efabe83dca08d8597ae6402966601 com.funme.assistivetouch

79430bf3a5936a88a8434660e3de9374253cba1c com.formula.t2ksports.wwe2k15mobile

ec445634785035f17538ad7f63054a52fcb043e7 com.mojang14tixanvrenda.minecraftpe

29a13d6e7668a9e75e927441191cc0c427dde878 com.ffolurstick.GangstarRioCityofSaints

2db8c92dbf2b8ad1af249f7569e36d55c59ca1e5 com.waitanda.Gamekiller

dd83c0d802005a40f2c1f516857799a652e154c0 kopliujmng.seventeenmiles.sketch

1c1725c62288d1dbac07d9fa0e1ed05758bba166 com.geoogroid.gms

914fc58db8117f4a7a21bcef5b7b0c34e412ae10 rtyuhjikolp.animirai64.supermariosixfour

513a1f4a8f256a305085e5ed679837d50b69cf95 com.nymolongad.geometryjump

7778121e02df0d99152de8b42e08677110291326 com.kohlbtrue.antivirus

bec66cf8acdb5ccddc9744ef099e7cb0af0615b0 com.falanng.framaroot

c399e8600f486015d73858d091fd7a0a159d7c00 ftyuiookljmnv.brainyideas.gtasantcom.oclrqgjww.gtagrandtheftautosanandreasthemev13

7765a62108f72b7d2b26d51fc9d05791b6458b37 com.icooga.phonecooling

Page 29: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

29

SHA1 for infected apks Package name

454be8b51930df48f43805f137871eb107694bf9 com.bigfishgames.solngoogfull

75311050a8a93f19b6ccb917e4752ae6790279d9 resdel.miniclip.agar.io

76ad2bd1b78815b4740b821daee5ce6d3cb13657 com.veardo.flashplayer

2880c722603166bf7d58bbc6ccfc41ef2d993d55 com.tuner.mojang.cardwars

a3f382c5aec38472932fef417199f2aa3b6822e2 com.xjjs.flashlight

fe758fd335b61394b9d004003ff550971f2c7f91 com.earock.rockstargames.gtavc

2104a7f3021d01536c4517beccbe262f550fcf23 com.cavome.zombiederby

3f1d4c9625d695abb1114e87819db2c4ecef2b1e com.lokinakis.Edition.Minecraft.PE

b471c7f732d2f9f472c751bebc09a7f8868286d1 com.sanafaghoull.gtavice

a170d83a91e36764ca63e94cbc54531232112506 com.faddulop.autodesksketchbook

d287442bc4b239afa3acc24cec5359a0e8b6b77e koidaslo.nekki.vector.paid

9bbaea04344dadabde799ea8ff56c91de69ed1ae com.kolagiri.rockstargames.gtasa

f97c415ed43d4838ed6fc7f957e75b89811197fc com.ghgnmocotar.barmfera.gta3

188aca1ede37c96787f3ea8c81338646e5d2def2 com.kojpnaver.line.android

2a8ab1c5faca03a74bf25ea9909047d852fe9642 com.divasazar.farmingsimulator16

2cb71a8aee15a01cfc6fe1576a7df07fc71b58d5 com.kilasrme.cobo.launcher

502e86674e63f42751a661256a03dfbfb0cb43eb com.iorhjf.showcsd

d6e34ce7c0ffbb31ab462287955bc6c7f491c6be com.hgftrcngad.geometryjump

2d1f500503e9dedf7c945c05809cd02869d655f4 com.rolpotx14sad.geometryjump

082e709f560c48e4752eb5cf05bfa4ecc41d8f8a lopmkjngtfe.rockstargames.gtavc

2b517fce3db8a185e1b03da6cce76b125bba0266 yuripoyan.threed.bowling

19927f42e623b8581ed2cf639634c155f3364d19 yuhjikloopfeds.halfbrick.fruitninja

96896e6f9bd9714d22b4bd041c1fca4254a8bf3a com.yuchico.socialpoint.DragonCity

00ceb2d171533891fd109edd8da59c1041952a85 com.mojangchinvolawa.w3ty.minecraftpe

1fabd3f8d97da502ccb3c3d12c98fa6479ebb4dc com.hck.parts

4af3b808f25c497e43a325bd83da02caee2912a2 com.hck.parts

68a60970af73b71e90f6b2551182f260da8682e0 com.xs.armysniper

72df4b9c02d55dc5029b80e82cbcac773d0f6a99 com.ramatolina.mortalkombat

c06b31f41c4dc7233dd0fca27451838e0698b613 com.timberabarmfera.gta3

fe3caac8bce8f07d30a1470d04973a5f30a37061 com.ts.lite.xbrow

8f77a26b10bf1b32ac6b354bbebe30778cff7bcd com.ghorpaidar.minecraftpehacked

10446fee3f43e000407d57a0e27120c69d3eefff jioplkmn.atv.blackops

0082f41f4cd329fe8a8c30880523e7e12f22867d com.hck.parts

2dd1b01707016982ccd5278378128a11b6d7f3a0 com.gamekiller.janmog.mc

d16f2f621893f7c78af66cea2edfc2263bd4868b com.hck.parts

0051c2cb2f1455f95916f64d6ce11f96e86b17d0 com.dacdna.lojav.jb.gosms

f798c6db388c3811827b9249cdc3a92c9ba2babc boplkiujm.ea.games.simsfreeplay_row

Page 30: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

30

SHA1 for infected apks Package name

c9104ee8d3ab10290f66b418a38440936a1b9910 wnecvbghy.microsoft.office.outlook

e4fea7a86087e5b84508d2083fb5ed3840191ad2 gemhhr.qihoo.security

63c427d9b22cb8ae557887ef445ec8eefa119b91 com.aircommando.airflight

9c9014ee2899ad0a1e7d8bcaa9f38090f704fd2d com.example.homeof11183beauty

b0ee4a4f60ae154ae8eae5294d196cc085bf2f76 com.bigfishstudion.solngoogfull

5e06ee83f0f5a2c67cca4c76abdb9a70f4976e49 com.smart.booster.wifi

a6c970caf9faaeab7bf803f3d59b71303f907ba3 com.rolpotcd67sad.geometryjump

43c422330a229f3d19612544ecc7863a9b88cb95 corijava.ppsspp.ppssppgold

ce3fb321e1a4e6075f221ad3ebbd56087c2b81cf rameshuiop.magisto

78eac8e97c11d2c100a884ab92c9cd3390734c38 com.popcape.crpvz

6dc04f7e493fe624b21d4588e0ffb0eda9f70076 com.fdooogle.android.marvin.talkback

101888f04821f91a4a0400539b9fa91574d177e1 com.forexdept.BridgeConstructor

85116472d0bf6b8437a0a5f973a8201ad233a6ce com.example.homeof11188beauty

2f18eb2878d3826d199bb629ae5c42bd01fc2e48 fiolkprdws.a43107034151745d2baf12d6a.a09974956a

b442841f6be69258bd806a9fad275e32764ab88a frtgddessws.android.vending

180959d046ec8edefac8a26c907ba15cae611964 uioplkmhfff.com.classteacher.main

c87b40a595817736cf96bca153be3fa77cbf1f57 bhyujikolpc.dropbox.android

c530f1e5173784acb383f44ac8a75aee9859f049 com.perfaapal.avgcleanerpro

5deb11c2e0ebeec45c1dab092b9d41977f6bf068 kendef.ppsspp.ppssppgold

cdaa1dbdc13fa6f3cca38d3d54e951c60b6d775b com.android.security

59a49616429eebae4d83d91ef0eed7ca7273331b com.test.sdclip

4c6e1132090b8e366949e1e642ec9a99e3eb1bab com.anipinirow.arowupermariobros

b6186929d2147888a460b97fd34bda733a69139c com.pepsi2012dasaa.evolution.soccer.org

1a8f671701edc952fd935f07b5e1ce8f8b9f9816 com.gbnmwstar.barmfera.gta3

18da828cdaeae97bf0d217913c3f94fb64910c34 com.hck.myplayer

602f57b78931eee9bb7b614f5d3bf8a695711df5 com.smart.booster.wifi

d8c649618ca845c0dd5785b6b818c0658c93973b com.forteondass.skinstudio

80222496c9ade23bcb18be58b47f7996005f9156 com.uVxmxy.mySAKzaE

42ea2937838c70b8e2309e720853bb13ca432624 com.rome.radio

3773766232fa68c98a1041e6c11febc664d15e2e lopkijuhb.scottgames.fnaf4

7b098c56d598c553e76c5f9b6ab012b563babeef asdefghnbmj.noodlecake.zombieroadtrip

94aef4959a672ae00bdf46bf95ddf6f4169f538a com.brainyideas.gtasantcom.zbwsgwpu.gtagrandtheftautosanandreasthemev14

0e529e64da49cbcdbf90fb4cf37fa8c5024aa57e cgtyuoklmjhf.dianxinos.optimizer.duplay

ca48968f4b6d3e01aa1a65a0b31ebefa5c8c7ed1 com.kopidostrong.chinatownwars

0301bbf22419a9d6bf6d1068c908cb0c96e1b29a com.gheuneapp.mapsforminecraftpelite

1ba2081953874e9ca5cf688197a76973f8f8c021 com.jemsisuti.backflipmadness

Page 31: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

31

SHA1 for infected apks Package name

bce316ec558f9b223338f6f7965deaf0c37be7aa com.copasada.turner.cardwars

41e11968452038e2930c644459d0708e6a4b532e com.finalminimob

23787256120c516b691f0fdf70341455b08b6947 com.brainyideas.geodnet.wofhj.geometrydashthemev15

d12188b066f888c535a36388fd604317165969f0 com.mojang5tixanvrenda.minecraftpe

2e72d4f1d2250c233e4e5e0bc59583405f66eadd com.funme.assistivetouch

112212a86c7dbc3f641bc98e5649af9f8abff029 vinolikjuhg.smalltech.battery.pro

26f71b2f2d9b7de71faffe8634abbc0ed6932d11 com.smart.booster.wifi

0413d22a54e0138d1f29e7701f567e94b7e79a3f vinodiklu.outplayentertainment.bubbleblaze

e98850ec8c1033b05e5bd0163681e1751f92cdbb com.hjnkmojang.minecraftpe

085db78b269e994df085fb2e1e15695f8cec5e77 com.hck.parts

0d619729acf76ee643ba9436a3085c8c4f6edff5 com.bunnafor.simpsons4

f166b3f89b302f2cf73324e327f79285a3aacd15 toyatasd.picsart.studio

ddc259d8835872373b64a17d2107c86651232b46 com.part.mySAKzaE

ebc224a07b33c0da9069811eb81297b9491376c2 com.streamyouplayer.pyou.free

2599a84e3f7c68ae7f3ed5ea8ef46ce10f2c9eee resttf.ea.games.nfs13_na

229fc2f5c1113f830bef20f7dadc8e68fa49fb1a com.perasrue.rammanagerpro

b9fe6089dcaf7ddca78de8d6d09abf8d6f3a3d2d com.kolinarmat.mortalkombat

04a2c5210fbadb98d332461b8de530497707c16d hitashi.tango.roadriot

4a4236679e6327089c2f78ad7199aef03a969eb0 com.fun.lock12302touch

ae8b29386d1ea98221fcff3dceb0dde641b5533b com.agoodsnowman

3be0cad3dafeb24e4b02905b2c73f5c89e7230d2 com.donnyzstudios.skisafari2

735e3ff11f26002a91ca12d40d69e916d65601a6 com.ddlions.thunder

d34272a80d091f11b5ee330997ee19dad0af8d24 suoipklntrd.dianxinos.dxbs

f96c15dbf59fa95db16356f2ff7514546623f87d com.ddlions.thunder

d4b602ad18c08aebfdb8bbe6bfb79bbd91f08880 com.jamestoymes.fnaf4full

feb181b5286b5f38a744ba8bdffeda1eec7ce1fb com.mojang4tixanvrenda.minecraftpe

8319d53c43ddcc7758d74dd58b82fa7010fc83c2 com.fordacatgames.Xplore

dd115520efbf1b318fa5e8533bfd3d33a42b8526 com.lelawxcorms2armageddon

6e02a33ce12d03e0e92d2a2c52b4cb2b69c9c87d hitom.whatsapp

96a9304fb173a863330e46c6c5b3ed40d46f8d4f govind.google.android.music

12c4c9163ad795a7bf755a3e56081b5e1201aac7 com.gfgtyolgilo.geometryjump

71e4e83751dfe86f5db328945181af7746867793 com.anipinvatka.arowupermariobros

c1079f16eb8a572b4c1410fafeda0a6e871cee7b com.leonesgame.ngunshipbattle

bca1fb1fafe94293cbb6d979637b54e16fbaf330 com.skigui.survivalcraft

87a76c9be337b944bab8e4e5f3e633fdb1690d48 com.brainyideas.gtasantedu.ijfjsd.gtagrandtheftautosanandreasthemev14

648535fb2fca9f39634ebd246ec1f534d90c511b vinodghyjj.outerminds.pewdiepie

Page 32: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

32

SHA1 for infected apks Package name

f88a1e0e086f1078781b91bcb80aab3b6e02b4dc govind.ggnes.supermario2

f504a89557f078beb06f04691c754d90eb596038 com.gaijin.ecvent.mc2

d257c653af4f4d04e3f048559850a17461d9dbc6 com.forplayapp.editor.officesuite

4ae969c287719cb631a185558ae9ddfe44df33cc com.jockeynlesnar.trueskate

bc45e8a75bc86afe7245979de5d6465aaba0d50d goklpi.magisto

ac9ccf8a3a6267d35e8d5263d4204b3c9abc10dc com.maegngi.detemplerun

e5994fd031ea46280ef197ba150051f1240fc761 com.forehdedit.google.earth

96df729feac8d1731169e3533e0c0fd95560c7cc com.bocewili.advancedtaskkiller

a3b5c67f358af4e7292850c0a62920ed56b2f126 com.dafao.mojang.minecraftpe

18ad0c61a19e6bdf252e1df0989b895630608408 corleene.sbtools.gamehack

fbb05e63ae12b7f1cb88e318b9dae8b71cbf6672 com.andrid.secuty

7f2bf42dc57a5199e7bc46fb76f1305c5f492fda com.smart.booster.wifi

c6cd68ff9bb7f9643b304e59f8e1a013371551a4 com.ddofgane.superren.clashofclans

51d01bec6765131c3dd54afbad3c7673d22e9077 com.lopachpa.mojang.minecraftpe

0b5e8e60486712f540f7738c3bf18deac49eab62 ghoria.outfit7.mytalkingtomfree

742fe8d6d58309019d2708a53ad11ad4d9381400 com.mojatunerg.cardwars

39b1c9ace38fd22ed4281dfb92755154ed606c2e com.biajierav.teamspeak

b8bf966b96241545d2d5d2fd77ae937755c67cf1 opg.slideers.camerazoom

95b5b0b05733f0ca279ba16ebffc4cc3d0bbc781 com.smart.booster.wifi

c89224376b069310ff32552e674ea13882f4b1e6 com.smart.booster.wifi

fc94e2b57686cceb18783ab0717863ad6fcf643d com.mojangvvageusahebminecraftpe

fcf3606f48ef4d7c701de81187ebee1813cf26eb com.lokorah.jetpackjoyride

cdd7119fd1f12c8792cc470b106a8626a60aa301 com.lojiarmlock.NBAJAM

fee599b8ce8c7af6612f421fdddfd7ab50a9e72c com.mojang.pelametry.Minecraft.PE

805677376830135d9d44b110bd513c393afc71ff com.traftuoppz.audioplayer.unlock

f6aaf5d10df5aacf52bc1d45ec5ff9e605296663 com.mojangchifada.minecraftpe

865ee2c5fa3907234de05a5947357d1539d47c84 com.smart.booster.wifi

702ce3439a81beb4686a6ccbc3fe0b51b70e4492 com.sarbefakun.trueaxis.trueskate

f4627b63b865c900b03c2ca090d730e85d621a08 vionlkigfd.evernote.world

15c09477b6928ad410e3085e52cbfdef3a4e4d2c com.uVxmxy.mySAKzaE

34e6db6aa8c6d7d8e5c816bf1311a13207e9d7cb ganeshfg.ea.games.simsfreeplay_row

cd42e691aeb51be6a5ef52acfeba2515c65b341d com.riyaghco.dsemu.drastic

07906c898e3ac10d9e7179fba9335a2cd1cae931 com.dolyanas.youtube

e36f1ec2c88240f867773fdb5c493e1b6bc361a4 com.themesapk.glassic

7524c565635eeb21d2e73eb2d812d8d902b316de com.thaui.whdwidgetsfull

8c47b0a226d85c7578876673557696c06c6fd845 rolipkujhnm.mw.rouletteroyale

1d5103683f7d04fc63e95cb93eb85fcb2d49bfb7 tilonjurfed.jumpgames.RealSteel

Page 33: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

33

SHA1 for infected apks Package name

63919faca7f2aeb8b4606a3af745ed1831ac241f com.filingshooting.star

cba45a105d932bf028675db396d4e00753982100 com.madefarolda.clashofclans

bfbd592ba117ca8d866e22c94296069f0202c669 com.magic11174mod.mmweather

41d8210d439862383ef9f45228058e2053839efe com.n7.phonecooling

6f7109e2d128bef2025bee7c35e9e3d40a435b15 com.magic11171mod.mmweather

9918c6e830396cf23b3d58d080113a238329d3a1 com.vinbanjsa.wars.clashofclans

6948651e948e41736043e7f84d16fb08c89ef050 fghyujikolpd.ea.games.nfs13_na

54d16ff281ef23aa8bebbc0c3d987e76224861e7 com.test.sdclip

99910a814369a08d13955a1f92bc6b66764c9b77 rtyuoojnbv.theonegames.gunshipbattle

6d41f2ea19fe151dbac27d2c4cd45635559bcb4a com.s.video

e1a513028a4d68158de0f493353565973448a6d5 com.example.homeof11201beauty

01e1642d09ec90c901c3c3f9dd12d98163ea01b7 com.vecalagame.fifa14row

90346902010e4068bad8d442ababe90f94607e32 com.white.browser

b4d7133f2fa2ee7c6df87933283f58f78dd1c973 com.hck.parts

fa2e1a13cd1bf63cc0e23442b9c01edbe6793562 vipulokjmn.picsart.studio

b4f366a0e26652c84fbccbf0d0176b7d382da61c com.shark.superflashlight

6da0df198a261855a5913b1da1ea09bec4d7f7f5 com.kk.jdm.browser

f629b7f7d4171c9bed65e7e8e6e1980d19df04f8 hiteshnjiol.facebook.orca

28992675e278f36b05c179d7c026127e6f26f3fd com.neothila.LEGOStarwarsitscompletesaga

4e985caae5bcc7eff3d4d3c11fad3993f6da37eb hhmsden.tubemate.home

73203cbe1c8b930c4074ecc7d8948759f4ffff1c com.crdfdmy.robtopx.geometryjump

4340fbdf3c9dac6510823292118a8be4e02ca43c com.minecraft.afadus.storymode

6cfad31857c88a7be9b3b3110532cecec385e3f5 com.fun.lock11261touch

bf6adbb571c7095bb5ff1c385e329f0b97e0b0de com.part.mySAKzaE

17444b00910de8ccba2234abf039c8d89db035af com.ary.plants.zonviws

d85675489956e4653c507fb4ce0f89e4375d311f com.robtop.geometrydash2016

9a48fac1fd96f2abf7e83138db6419c127961a50 yogeshjkiol.happylabs.hotelstory

bd5186c3c2aed9a0644047e1da1a7977d20f5ded com.xjjs.flashlight

d31fa8a56883a64743cebcabc852cc9dba092ade com.fuygwfren.catskisafari

de20b7d33315129b7f08a98d2b5f34ed6cd3963b hjuioplmn.snaptube.premium

fc85a54d86cc2504f677da399ce150955eed2648 com.uVxmxy.mySAKzaE

b48c82bffe5179226c145962359f290bf3ef7888 com.velbro.facelock

a8b15851a1191b3c0f9c3dd628547f84cfce513a com.poke.car3d.shanchuan

c902079e0e8abd39e5d58bce4f299f3c341543ad com.vertohongad.geometryjump

4ff6bcb7d367e96c3c3c7eba388a96369f14e89f com.tustarner.freedom

f605ba7e4951e5ca71055ad0e39728cf1e625b4e derftghju.snapchat.android

62a6fb1b46f7fa8d79e11329d560ac18e12ee4b0 com.uVxmxy.mySAKzaE

Page 34: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro | | User Beware: Rooting Malware Found in Third Party App Stores

34

SHA1 for infected apks Package name

ded749f26e7b5301db6eb8f977ac9a7100546316 com.halfbrick.fadrefruitninja

92e75605d418adf745d58cef183a197e2f7d5166 com.ts.lite.xbrow

58efcb9b2c471431836de40f760c23f178424c0b revines.scottgames.fnaf4demo

1aa0921124d420d561e0d37bbcbcd7a53842b687 com.xjjs.flashlight

4178b5bb2126b13bb340e2b08a6c7e29ebba8afc com.owsaz.turner.atskisafari

db5964c9c401e0850eadfa4b8b5a1b95edacb2e4 com.lpowyuar.jetaudiopluspro

f8f5c13065c13a542c0449384df7ff67a5ffbe5c com.filipains.goatsimulator

8465878d1016a7e64ae9a8f1281c6e73fbfc0296 com.mojang10tixanvrenda.minecraftpe

b333a9a447468eb6d66c1b2f533185cb2e810882 tyujikoldvz.v3s.escape.the.high.school

bada0a17bd379292e48d7a8d3a70bb6bcfbb7ef2 com.ddlions.thunder

80851c9b4d8647701ed3eb93007000d8f8090cab govinda.flavionet.android.camera.pronet.kmeqi.camerafv5v2791

15f5da8afda48ff1aa042f8182a68f48a28d8890 com.vocabmy.mytalkingtomfree

46cbf186864433b87a5cc27c96b0e9c4e6765eff com.ddlions.thunder

5e863582887c37b80e33ad70016706e8104a3894 sushidyuikj.soundcloud.android

d5d49bf069ec03bd74030fe3077a9e9ba0d6cf97 com.reverse.mvagent

3a562ac7ab1069deb0746552ed8b22c07b4c8314 com.fvovixxzxa.google.android

5dda10244b3204f4e8fea5c64c0a9a4aa24bcab1 com.eacoyote.systems.android.seftr

eb6975aa4a297548e84775686c880fa57c6845f0 hoiplkmn.threed.bowling

3741237d907cafa9e00fccfedd77fa84dc017c15 com.devaswaopa.gta3

edc3d88ef1b27d28f5b0b47dd4c82c7438fb3cbb com.white.browser

ffc8c5a55e06ba240f942010697f2b7b4665f847 gokuloiuj.droidstudio.game.devil2

a79809cddc6ce3f4e4c91c09f07d2028d5937d6d com.fortunerobc.shooting.star

aca85f21973c6eead88ccda7c603ff709ac97fb3 karleone.twitter.android

95d1f502c67eba97732fa2954d2fed16c9874fc7 com.ahuwy.dropboxandroid

9650ed9204da1e12ce3eea1b5ef973eadad715ac rtyujgfgcds.kairosoft.android.soccer2_en

1a9408b6ce8628f185dd7cef47cf061e3b0fba05 gfdcvbhujk.jrummy.root.browser

a045260d76257cddc7f4f1ee9039d451ce2d8858 com.togplndra.x3m.tx3

8557be6c694a85be762354c1476307c05aca480d com.niepena.socialpoint.DragonCity

81645986cdcbe39828fdb9947af24069070fa63b com.example.homeof11182beauty

02404f8bea2048123c3e5612e647b385c20043dd com.kovinjova.whatsapp

b66ecdf756e2d5ebad9607c95b8e5986ee3fbc14 foilpkmjn.bfg.steam.train.simulator

668ad3421bbbeff2913316981841d65dbde1e64b com.j9b.insaneEmoji

08be2d018ee59688badb9c9ff86422ed8790ac7d com.gaucergo.launcherex

1dbebfa9e67c995bb68ec9e0c96c04df2ea26678 com.sexsne.mat

7dacce563a5e1adb6ca0ad2e5f8655332e28db0a com.tobykurien.batteryfu

Page 35: User Beware: Rooting Malware Found in Third Party App Stores

Trend Micro Incorporated, a global leader in security software, strives to make the

world safe for exchanging digital information. Our innovative solutions for consumers,

businesses and governments provide layered content security to protect information

on mobile devices, endpoints, gateways, servers and the cloud. All of our solutions

are powered by cloud-based global threat intelligence, the Trend Micro™ Smart

Protection Network™, and are supported by over 1,200 threat experts around the

globe. For more information, visit www.trendmicro.com.

©2015 by Trend Micro, Incorporated. All rights reserved. Trend Micro and the Trend

Micro t-ball logo are trademarks or registered trademarks of Trend Micro,

Incorporated. All other product or company names may be trademarks or registered

trademarks of their owners.

10101 N. De Anza Blvd.

Cupertino, CA 95014

U.S. toll free: 1 +800.228.5651

Phone: 1 +408.257.1500

Fax: 1 +408.257.2003