MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 000f3363ebf6b2ad599dfb7022fae11dc157465aaefd9f35f3dadd1b5fabd111. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 4 File information Comments

SHA256 hash: 000f3363ebf6b2ad599dfb7022fae11dc157465aaefd9f35f3dadd1b5fabd111
SHA3-384 hash: 64b1229a162fa3dcd8311101336fbfc4e9ce7387c43ddd71dc9e0f855e78ef1f98dbe12861e89a008671a685c649381c
SHA1 hash: 33506ccee7a272dd3e553950e543a5556252002c
MD5 hash: 5f3128f04c4fb3d16ad9643d8d2b0c22
humanhash: high-johnny-kitten-tennessee
File name:base.apk
Download: download sample
File size:5'627'160 bytes
First seen:2026-08-27 16:10:10 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 98304:6dso9iFRPWY4LABZ1rtiXemyQFGC3VOZWj+SVfBS1XEfeTCJ2wimVK:qz9i7Pd4LAB3ti9o8OZspVfBwXhT6ji3
TLSH T13746F052B6B79A0EC436833FDF477222F1066D168E839247EE34335D68776A80F94AD4
TrID 87.0% (.APK) Android Package (27000/1/5)
12.9% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
CZ CZ
Vendor Threat Intelligence
No detections
Detection(s):
SecuriteInfo.com.PUA.IMG.PossibleMalware.63178934.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.11739745.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.88188649.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.29374763.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.31317319.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.86499543.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.45176272.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.33577514.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.58339521.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.98122742.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.77221194.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.87458113.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.44921377.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.19191779.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.93339559.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.16531126.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.55563394.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.73967571.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.92131248.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.58974858.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.66251846.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.46719184.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.35781814.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.72421349.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.35468512.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.18983143.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.12655914.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.62983538.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.22352365.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.77718541.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.52663669.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.73347363.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.99366643.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.13588294.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.73814785.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.66891484.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.18952184.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.23793139.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.39135916.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.91237578.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.63997331.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.14552463.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.88481566.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.36522292.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.65171978.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.95868557.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.71585162.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.74773487.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.88511148.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.55947287.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.72787827.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.27567169.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.68726435.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.19439915.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.48424656.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.42569534.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.64485617.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.73387993.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.32458798.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.21357251.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.98122879.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.86242949.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.99734152.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.28236485.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.42457512.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.91676288.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.81963714.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.18739414.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.91546845.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.51339225.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.62324476.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.29256412.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.36694772.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.93941398.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.72764496.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.44523226.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.39113456.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.52518687.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.17274272.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.81227886.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.37184667.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.43892587.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.67923948.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.67724782.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.67667443.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.79458887.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.65643794.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.75955834.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.78124325.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.65128497.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.16316625.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.67873511.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.53895348.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.18413146.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.71815919.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.67578785.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.14315436.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.24582712.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.42783266.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.64576182.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.63411741.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.86927181.UNOFFICIAL
SecuriteInfo.com.PUA.IMG.PossibleMalware.33417676.UNOFFICIAL
Result
Application Permissions
list accounts (GET_ACCOUNTS)
act as an account authenticator (AUTHENTICATE_ACCOUNTS)
receive SMS (RECEIVE_SMS)
read SMS or MMS (READ_SMS)
send SMS messages (SEND_SMS)
read phone state and identity (READ_PHONE_STATE)
directly call phone numbers (CALL_PHONE)
read contact data (READ_CONTACTS)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
view Wi-Fi status (ACCESS_WIFI_STATE)
change network connectivity (CHANGE_NETWORK_STATE)
change Wi-Fi status (CHANGE_WIFI_STATE)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
prevent phone from sleeping (WAKE_LOCK)
read sync settings (READ_SYNC_SETTINGS)
write sync settings (WRITE_SYNC_SETTINGS)
read sync statistics (READ_SYNC_STATS)
create Bluetooth connections (BLUETOOTH)
bluetooth administration (BLUETOOTH_ADMIN)
reorder applications running (REORDER_TASKS)
control vibrator (VIBRATE)
update component usage statistics (PACKAGE_USAGE_STATS)
Result
Malware family:
n/a
Score:
  8/10
Tags:
android collection credential_access defense_evasion discovery evasion execution impact persistence
Behaviour
Checks CPU information
Checks memory information
Registers a broadcast receiver at runtime (usually for listening for system events)
Schedules tasks to execute at a specified time
Uses Crypto APIs (Might try to encrypt user data)
Acquires the wake lock
Makes use of the framework's foreground persistence service
Queries information about active data network
Queries the mobile country code (MCC)
Queries the unique device ID (IMEI, MEID, IMSI)
Reads device software version
Loads dropped Dex/Jar
Obtains sensitive information copied to the device clipboard
Reads the content of SMS inbox messages.
Reads the content of outgoing SMS messages.
Reads the content of the call log.
Checks if the Android device is rooted.
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Android_Admin_And_Accessibility
Author:Buga :3
Description:This detects apps which request access to both device admin and the Android accessibility suite.
Rule name:Android_ElectricityBill_Miner_APK
Author:ShriyaTiger
Description:Detects Electricity Bill themed Android malware and Miner.apk payload
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:Jeevan_Malware_Rewards
Author:ShriTiger
Description:Detects JeevanReward variants using Technical, Anti-Analysis, and Indian SE keywords

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

apk 000f3363ebf6b2ad599dfb7022fae11dc157465aaefd9f35f3dadd1b5fabd111

(this sample)

  
Delivery method
Distributed via web download

Comments