🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 01227a8b5dca01ecac7177051e6d2a3cf5e12ce7ca9cbb06040d8bcb9cfcc6a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 01227a8b5dca01ecac7177051e6d2a3cf5e12ce7ca9cbb06040d8bcb9cfcc6a2
SHA3-384 hash: 7f7b301d329aa461e0d66b397d158cfcc0d776e9f2ae8e8a3cfcdbdc2bc7086fc3be6ff769e1d07e76dd77d4aea3a8d4
SHA1 hash: f25473c4f60a869eb1c63b46dcda1ba3d47aa4ee
MD5 hash: 3c53caa2fd562d12dcf22bd5b396a2ed
humanhash: oscar-skylark-don-fourteen
File name:Sexy_Chat_payload.apk
Download: download sample
File size:5'011'648 bytes
First seen:2026-09-05 11:30:23 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 98304:lq7J/hIkbwjsS54FKkcWQuoI5E36C0yk1eCQ0HeilmKs45dmlkz:lqdhhwjh4FKkFQuogE36CWIbKmV4jh
TLSH T1CF361282F7E8AE1FCC7781321F8A037151169E66CB83E707A454376D287BAE84E597C4
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter Xenofic
Tags:apk india payload RAT Sexy-Chat signed UPI zeroday

Code Signing Certificate

Organisation:Food Recipes
Issuer:Food Recipes
Algorithm:sha384WithRSAEncryption
Valid from:2026-09-04T13:11:42Z
Valid to:2054-01-20T13:11:42Z
Serial number: d2f34c307fa634bf
Thumbprint Algorithm:SHA256
Thumbprint: 458d59e0cf0406baaf7562e792b86d5605c835a117f425a9f1fde599aa61740e
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
Xenofic
RAT payload extracted from dropper. Package: com.batch.android.runtime, Internal label: Sexy Chat. Capabilities: SMS theft, contact exfil, call log theft, UPI PIN capture, card data theft, keylogging, bank balance scraping, call forwarding hijack. Supreme intercept feature holds victim banking sessions. C2: api.agenticera.club

Intelligence


File Origin
# of uploads :
1
# of downloads :
164
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug base64 crypto evasive fingerprint persistence signed
Result
Application Permissions
list accounts (GET_ACCOUNTS)
act as an account authenticator (AUTHENTICATE_ACCOUNTS)
receive SMS (RECEIVE_SMS)
read SMS or MMS (READ_SMS)
send SMS messages (SEND_SMS)
read phone state and identity (READ_PHONE_STATE)
directly call phone numbers (CALL_PHONE)
read contact data (READ_CONTACTS)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
view Wi-Fi status (ACCESS_WIFI_STATE)
change network connectivity (CHANGE_NETWORK_STATE)
change Wi-Fi status (CHANGE_WIFI_STATE)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
prevent phone from sleeping (WAKE_LOCK)
read sync settings (READ_SYNC_SETTINGS)
write sync settings (WRITE_SYNC_SETTINGS)
read sync statistics (READ_SYNC_STATS)
create Bluetooth connections (BLUETOOTH)
bluetooth administration (BLUETOOTH_ADMIN)
reorder applications running (REORDER_TASKS)
control vibrator (VIBRATE)
update component usage statistics (PACKAGE_USAGE_STATS)
Verdict:
Malicious
File Type:
apk
First seen:
2026-09-05T09:23:00Z UTC
Last seen:
2026-09-05T10:45:00Z UTC
Hits:
~10
Threat name:
Android.Trojan.AVerseFalc
Status:
Malicious
First seen:
2026-09-05 11:31:19 UTC
File Type:
Binary (Archive)
Extracted files:
576
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
android collection credential_access defense_evasion discovery evasion execution impact persistence
Behaviour
Registers a broadcast receiver at runtime (usually for listening for system events)
Schedules tasks to execute at a specified time
Uses Crypto APIs (Might try to encrypt user data)
Checks the presence of a debugger
Acquires the wake lock
Makes use of the framework's foreground persistence service
Queries information about active data network
Queries the mobile country code (MCC)
Queries the unique device ID (IMEI, MEID, IMSI)
Reads device software version
Reads information about phone network operator.
Requests disabling of battery optimizations (often used to enable hiding in the background).
Loads dropped Dex/Jar
Makes use of the framework's Accessibility service
Reads the content of SMS inbox messages.
Reads the content of outgoing SMS messages.
Reads the content of the call log.
Checks if the Android device is rooted.
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries

File information


The table below shows additional information about this malware sample such as delivery method and external references.

apk 01227a8b5dca01ecac7177051e6d2a3cf5e12ce7ca9cbb06040d8bcb9cfcc6a2

(this sample)

Comments