Suicidal Instant Loan Apps — Repository for Mobile Malware Researchers

Rushi Mehta
2 min readAug 28, 2022

--

Internet is flooded these days with instant loan apps, most of them which are unregulated entities. RBI has recently come up with a notification on regulating illegal digital lending after issue become too grave that large number of suicides have taken place. (https://www.businessinsider.in/india/news/rbi-tightens-norms-for-chinese-lending-apps/articleshow/93629917.cms)

Recent Suicide by a Family owing to harrasment

I have collated list of many such apps (will keep updating) with their virustotal link based on common detection parameters mentioned.

Malware analysts can refer the same to suggest any recommendation in dealing with the.

Interesting Observations in App:

  1. Liveness Detection Service
  2. Use of Alibaba & AWS Cloud
  3. ESET-Nod32 — One of best AV to flag them (Thansk to https://twitter.com/LukasStefanko)
  4. Payment Gateway Integrations
  5. International Domains (.cn, .qq, baidu etc)
  6. Uses all android permissions (location, storage, contacts etc) for collateral.
  7. Uses Cloudflare to original hosting
  8. Mandatory OTP based authentication (dynamic analysis). SMS comes from random SMS header registered on DLT.
  9. Fake reviews and extreme negative reviews in App Store
  10. Boosted by Advertisement in App and Search
  11. Sent over SMS directly

Indicative List of Instant Loan Apps:

https://www.virustotal.com/gui/file/30ec2db56b5df3f37ddf79d0cc4cfbb3e71fd89eb5e8caa0b79ee94d7e44dd03?nocache=1

https://www.virustotal.com/gui/file/4e5214da0e205fa0151de2689e37c610160c602113b2b63fb6af67f3747b196e?nocache=1

https://www.virustotal.com/gui/file/091dfebbdf8cebc0631208f56b348441b2a21eb660dde8c2d625d542b2d3dca9

https://www.virustotal.com/gui/file-analysis/NDAzOTI4ZTg5MmZlYWZkZDQyYTUwOTFjMDEzNjY0ODE6MTY2MTI0OTUxNg==

https://www.virustotal.com/gui/file/e9e837de8db096f1cd60cefdfed836f0e74b63e01d45fb41f892a5ff6219fc0d?nocache=1

https://www.virustotal.com/gui/file/0e68fa586f18872c79a224f4ec9aaba7321e7f3cefe2d4a1c09f5194c11d4781?nocache=1

https://www.virustotal.com/gui/file/ccc656c43e680bf66f0495ef739c180eac3596fccde7806377cc53cfe1e11d8b?nocache=1

https://www.virustotal.com/gui/file/bbca987ce3dace54728b2b6908efab895bf582fc14609b1a1f7f1a5f7e127b0e?nocache=1

https://www.virustotal.com/gui/file/8505ba0708e9aab8bc5837c4830a49daf5a958a4935ac97e13fe051bde028825/detection

https://www.virustotal.com/gui/file/b712ba7e8e257b330bd7f2d5dfdab0e79522fb1fee82bfbf6f21cbff8e3cd470?nocache=1

https://www.virustotal.com/gui/file/21ae6aa778217bb156ed104971c1a8ec2efb0b8a52704a3bd07791bc63d80d43?nocache=1

https://www.virustotal.com/gui/file/0b776ef94ab8b430249ceca2bb21d76b4d91d837995d94705d86d8f3356e7b59

https://www.virustotal.com/gui/file/674c8f2a99f123aad17930772dd6f8c6715963d50511424c8d902dbc9571c625/details

https://www.virustotal.com/gui/file/67617ff834874a27a3409e800266f3e205fe19350a106b452c1902924e45cb57?nocache=1

https://www.virustotal.com/gui/file/0e68fa586f18872c79a224f4ec9aaba7321e7f3cefe2d4a1c09f5194c11d4781

https://www.virustotal.com/gui/file/e4da0ae6137ce5219b1bd4af15ccb016e7bcfdc2f1737a19fc9cc32794bf7d36/detection

https://www.virustotal.com/gui/file/7370454ed42c9d2e0da12c6327d85b0b0d6ab833e216d4d69e5cc9fb986cb48e?nocache=1

https://www.virustotal.com/gui/file/6b3a8603f862914aef58b9180e72fbadf886151d47c8d08beed4eb4107f6401b?nocache=1

https://www.virustotal.com/gui/file/805520c12893db68791140e63def7d58034565362f9cee4a96dadc3043f430ef

https://www.virustotal.com/gui/file/34ac980ba05c3f6fc5a3a34953331a83f48ad4b76cef9be07cfc3949d3f197eb?nocache=1

https://www.virustotal.com/gui/file/a5e1bedffb41bdce73e1be9ca95d9ef3ceac2f5ef87e487e4400bf9206c7dc67?nocache=1

https://www.virustotal.com/gui/file-analysis/MGY3NTRjZmMwZTJhN2YyOTVhYmUxZjYxZjQyOTM5MzE6MTY2MTI1MDEyMw==/detection

https://www.virustotal.com/gui/file/3a1195c45c21845db4943e13e95234ee3a63cf185c83f88a6022cfbbcf202d97

https://www.virustotal.com/gui/file/4c495a20d1a251544f32e2f7ff41e505d915a00dea7ac781ca7d405af3d291e5?nocache=1

https://www.virustotal.com/gui/file/75e929d67bed4c941b9cd31e442da39f84eb53708b0513d10c1abf6b004a1c12

https://www.virustotal.com/gui/file/9c9283f43e2473ad6cd1b2abe56353b0ab34db4106dd5da2f76802f0ec4026b7?nocache=1

https://www.virustotal.com/gui/file/0204bd9d4c5a748bec9c5d333b16466eae6f84ba42e8a834b9ba73f38e51f8a8

https://www.virustotal.com/gui/file/46c948500aed0dbd47e009127872a35723c998d017579a4845a72795d68ac5bf?nocache=1

https://www.virustotal.com/gui/file-analysis/NDhiMTc1MWQ5ZGM3Mjk2NTAxZDQzNmU1Yzc5ZmY0YzE6MTY2MTQxNzEyMQ==/detection

https://www.virustotal.com/gui/file/e1946a44338c6b0d81e8182787e28f0dae823ff5ef41b29cb2dd1c548bc6f243/summary

https://www.virustotal.com/gui/file-analysis/MDczODkyOGUzNTI0YzVlOWU2ZWI3NzE0MGFkNjk5MzM6MTY2MTQxNzM1NQ==

https://www.virustotal.com/gui/file-analysis/NGE2ZjM0YTZmODk0MTYxNjMxMTA0MzFjNjI5N2I3Zjg6MTY2MTQxNzQ4MQ==

https://www.virustotal.com/gui/file-analysis/YTJlZDRmM2I1NTk4ZGI3YzQ3ZGU3MTlkZGVkODhhNDc6MTY2MTQxNzgxNA==

https://www.virustotal.com/gui/file/21ae6aa778217bb156ed104971c1a8ec2efb0b8a52704a3bd07791bc63d80d43/detection

https://www.virustotal.com/gui/file/29b7f45e3b0b9cac61959f529437b2910d60061c635eee048904498f675df804

https://www.virustotal.com/gui/file-analysis/OTVkY2RlM2MzMDY5YTYzOTA2YWVmOWM2NDAwNDM5YmE6MTY2MTQxOTAzMw==

https://www.virustotal.com/gui/file/c7e33cdf72a23aee238722f3ebb86c403e69dce72063f51a3621c79a2f3203a0?nocache=1

Older Ones (Banned by RBI)

https://www.virustotal.com/gui/file/42e2c2bf4107fa3f07b2c2e8ac9c737683a33a449b611243ae932b31f238e757?nocache=1

https://www.virustotal.com/gui/file/eb1432dc2fdf7ea537635e80c672e9d9708e0d19604154bf6ecd3e5441cae68d?nocache=1

https://www.virustotal.com/gui/file/ea827c84a4076eebe2944b47f12e43a18ac2206880a9022e19b21efc0d29050d

https://www.virustotal.com/gui/file/db3e29124a9b868ad67727e3542309e53da793d317a786640ee3053c110db962?nocache=1

https://www.virustotal.com/gui/file/a6f930e1d3978e685a4426d93ebf20e0c6ff42c4c5c79206e1f362a9eec1e85a/details

https://www.virustotal.com/gui/file/849edf300ff37ccb53fe58a18b7aa17e5720c9dbea1960d71b1aace126abb6b4/details

https://www.virustotal.com/gui/file/a0292fe83b669def19dd8690e9ce6f4563fd807ccf3dac946447aca02c8e07ad

https://www.virustotal.com/gui/file/0f054727f7e8cc5dce3511692f003f65a6347b3eca49068c29014f488d542b2b?nocache=1

https://www.virustotal.com/gui/file/8578c4056882adc9ee0817858bdb47893033b3b0c0c3504499b8a71d5530b180?nocache=1

https://www.virustotal.com/gui/file/637c91a6345c49cc58910a8eea704a329895e69ff89dc6a9539e7a9220e3c97b?nocache=1

https://www.virustotal.com/gui/file/51acaa4a8c2bdc2c4dc74f392b80281af1c3f3ea1c720471193ac1aca263d277

https://www.virustotal.com/gui/file/9062de717f562ee966791b0fa21be572e017c816d4e4f9acebd3218db2f5aa18?nocache=1

https://www.virustotal.com/gui/file/6d05ade9a78c57daabb66e4ed1833fe96d5bc4f5f6a6d44141958f5f35a5d0f9?nocache=1

https://www.virustotal.com/gui/file/7c6f128d93b74b17d2a2988e6528b833f9a2f190a7f4a587d440e9b2554c9146

https://www.virustotal.com/gui/file/62aa5986dbcbf56d628e0442d39b6b8cc4cf1629858af82ab8ac69a2e5d3cac2

Flagging issue is easier. Getting to the solution keeping in mind Laws, manpower, implementation feasibility, scale, not impacting genuine ones is most difficult task

Do provide some unique suggestions..

************

--

--

Rushi Mehta
Rushi Mehta

Written by Rushi Mehta

Cyber Security & Fintech Risk Enthusiast, Trekker, Meditator and Contributor!

Responses (1)