MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5ebd725d3b158d56d9629a6226b8d7cd3dae030cfbb7c4b506308f6d4c6b6eca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 5ebd725d3b158d56d9629a6226b8d7cd3dae030cfbb7c4b506308f6d4c6b6eca
SHA3-384 hash: d6712629355f9e4cb733b64d8f1458c6a82685377b54931fa87e1a143ad475e6e8f79875b25c737f210bfaa0d6167ef6
SHA1 hash: 50e0a36c7dff6d2af3fb9f16b780c1cec07e791e
MD5 hash: 15d9ca5d41eb51aae97610b86dbeb5fa
humanhash: echo-sink-october-grey
File name:TikTok18.apk
Download: download sample
File size:8'864'964 bytes
First seen:2025-11-23 12:09:24 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 196608:8r7tnA+E/4j1XZWnm/5qeBAOZWgvg7LZRoGlYK:8r7c/4janm/uO4
TLSH T10C961203F74F492ECDE2B97C4A6313716615ACEC182092CB4A12F218BEB76E95F15BC5
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter juroots
Tags:apk signed

Code Signing Certificate

Organisation:App
Issuer:App
Algorithm:sha384WithRSAEncryption
Valid from:2025-11-22T12:24:01Z
Valid to:2080-08-25T12:24:01Z
Serial number: 7d9242fefb605e1a
Thumbprint Algorithm:SHA256
Thumbprint: 1f05baf1773c039508426fdf10ebccbf5df18d8a36ef906105687ed19f3ca930
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
RO RO
Vendor Threat Intelligence
Gathering data
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
android signed
Result
Application Permissions
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
prevent phone from sleeping (WAKE_LOCK)
Threat name:
Android.Trojan.Generic
Status:
Suspicious
First seen:
2025-11-23 12:10:59 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
6 of 36 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Any_SU_Domain
Author:you
Description:Detect any reference to .su domains or subdomains

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

apk 5ebd725d3b158d56d9629a6226b8d7cd3dae030cfbb7c4b506308f6d4c6b6eca

(this sample)

  
Delivery method
Distributed via web download

Comments