What I Found During My Analysis
- I received and investigated a suspicious APK distributed through a fake traffic-challan SMS/link.
- The downloaded file was named
NextGen_mParivahan._apk.apkand was presented as a legitimate NextGen mParivahan application. - The sample I analysed was flagged by 8 of 64 security vendors on VirusTotal as malicious.
- The investigation identified the sample as Android / APK, approximately 6.89 MB, with a community score of -12.
- SHA-256:
ad8b3644fb48c312932454a378c1ece19811b7c8891785fed51e6547db4451d5. - This is a malware indicator, not the official mParivahan application.
The Attack Chain
- Traffic Challan SMS → Urgency / Fear → Fake Government-looking Link → Fake mParivahan Page → APK Download → Victim Installs Application → Potential Device Compromise.
- The attacker does not initially ask for a bank password. Instead, the message asks the victim to install an application to check the challan, making the attack more believable.
Why the Scam Works
- Cybercriminals exploit the expectation that traffic fines can be real.
- A message containing a vehicle number, fine amount, challan details and a verification link can immediately create urgency.
- The attack relies on a short moment of curiosity: “Maybe I really received a challan. Let me check it quickly.”
The Fake Website
- During the investigation, the SMS redirected to
mparivahan-gov.dedyn.io. - The supplied post identifies
echallan.parivahan.gov.inas the official eChallan service and explains that the fake site was designed to visually resemble an official application listing using government/NIC-style branding. - The attack is a combination of Brand Impersonation + Phishing + Malware Delivery.
Technical Analysis — APK
- Filename: NextGen_mParivahan._apk.apk
- Type: Android APK
- Size: ~6.89 MB / 7,224,764 bytes
- MD5:
fdad41a9659f151f2bf4c1df80b20454 - SHA-1:
ecdc5f6eec08ee1d8a1dd1bca67612e1feb30ba7 - SHA-256:
ad8b3644fb48c312932454a378c1ece19811b7c8891785fed51e6547db4451d5 - VirusTotal observation: 8 / 64 security vendors flagged the sample as malicious.
- The APK contains three DEX files:
classes.dex,classes2.dexandclasses3.dex. - Approximately 938 ZIP/APK entries were observed during static inspection.
- The package also contains an asset associated with
ApkControlFlowConfusion_8.0, consistent with code-obfuscation/protection tooling. - Static inspection alone does not establish every runtime capability. The safest conclusion from the available evidence is that the sample is suspicious/malicious and should not be installed.
This Is Not Just a “Fake Challan” Scam
- The danger is the APK installation.
- A phishing website can steal credentials. A malicious Android application can potentially obtain access to sensitive device functionality depending on the permissions granted and the implementation of the malware.
- Potential targets may include banking credentials, SMS/OTP, calls, contacts, notifications, payment information, authentication data and personal files.
- The exact capabilities depend on the malware’s permissions and runtime behaviour.
Red Flags in This Incident
- Unknown SMS sender
- Urgent financial penalty
- Suspicious external domain
- Government / mParivahan impersonation
- APK download
- Application installation outside the trusted app distribution channel
- Fake government-style interface
How to Protect Yourself
- 1. Never install APKs from SMS links. Government challan ≠ APK download from an SMS link.
- 2. Check your challan yourself. Do not use the link provided in the SMS. Open the official eChallan service independently and enter your vehicle/challan details there.
- 3. Don’t trust the app logo. A malicious APK can copy the logo, name, screenshots, description and government branding. Verify the source, not the appearance.
- 4. Keep “Install unknown apps” disabled. Review which applications have permission to install unknown applications and keep the setting disabled when you do not need it.
If You Already Installed the APK
- Treat the device as potentially compromised.
- Disconnect from the internet if active compromise is suspected.
- Remove the malicious application.
- Change important passwords from a clean device.
- Contact your bank if financial information may have been exposed.
- Review SMS, call and notification activity.
- Check installed applications and special permissions.
- Monitor bank and UPI transactions.
- Preserve the SMS, URL and APK as evidence.
- If financial fraud has already occurred in India, report it immediately through 1930 and the National Cyber Crime Reporting Portal.
The Biggest Lesson
- This attack does not begin with sophisticated hacking.
- It begins with: “You have a ₹1,000 challan.”
- The attacker creates Fear → Urgency → Curiosity → Fake Government Identity → APK Installation → Potential Malware Infection.
- Cybersecurity awareness is the first line of defence.
IOC — Indicators of Compromise
- Malicious APK:
NextGen_mParivahan._apk.apk - SHA-256:
ad8b3644fb48c312932454a378c1ece19811b7c8891785fed51e6547db4451d5 - SHA-1:
ecdc5f6eec08ee1d8a1dd1bca67612e1feb30ba7 - MD5:
fdad41a9659f151f2bf4c1df80b20454 - Suspicious domain:
mparivahan-gov.dedyn.io - Observed URL:
https://mparivahan-gov.dedyn.io/558489/ - Delivery Vector: SMS → Fake eChallan page → Malicious APK
🛡️ CyberRakshakLabs Security Message
A REAL CHALLAN DOES NOT REQUIRE YOU TO TRUST A RANDOM APK.
STOP → DON'T CLICK → DON'T INSTALL APK → OPEN THE OFFICIAL eChallan PORTAL YOURSELF → VERIFY