🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 019cd4ca5c50bf4e733bc0bee66b5a0c97cf8b0e297d396ccdeabd697ac8d566. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PixRevolution


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 019cd4ca5c50bf4e733bc0bee66b5a0c97cf8b0e297d396ccdeabd697ac8d566
SHA3-384 hash: 033d33c44e9f9b56abbc0b555fbf8ade8bbd0a4180f49bbdbee474bb60017cc7dd719f15572682dec548b4a69d93f859
SHA1 hash: 660439d398e71d91dbc8cfce2fdb271d18cde3cc
MD5 hash: 2178546a8d0aaa12bb3e63d7f012c0ce
humanhash: low-victor-tennis-west
File name:019cd4ca5c50bf4e733bc0bee66b5a0c97cf8b0e297d396ccdeabd697ac8d566.apk
Download: download sample
Signature PixRevolution
File size:13'456'463 bytes
First seen:2026-02-02 15:46:20 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 196608:fELhac4NWk2ZzZyzZ/MkQ8MxfdPDuIUJDzi7uYgH8PpYxF+Yleb9mRy9eknMhzE7:fENajNbwk6JPxZjUJXbQeYmRyE47
TLSH T162D62386BBC89E2ECC7340324F5AA7355609AD27C707C343C978365C78BB6E44E856E9
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter johnk3r
Tags:109-110-184-242 apk banker PixRevolution signed

Code Signing Certificate

Organisation:Lite Platform
Issuer:Lite Platform
Algorithm:sha256WithRSAEncryption
Valid from:2026-01-22T13:54:46Z
Valid to:2053-06-09T13:54:46Z
Serial number: d0d7494285ab53f5
Thumbprint Algorithm:SHA256
Thumbprint: f42aff2d11304b64a4534b926c14e957254141e92eda441f2b06a87bf8619a3b
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
175
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Result
Application Permissions
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
Verdict:
Malicious
File Type:
apk
First seen:
2026-01-23T19:12:00Z UTC
Last seen:
2026-01-26T18:45:00Z UTC
Hits:
~10
Threat name:
Android.PUA.Maltiverza
Status:
Malicious
First seen:
2026-01-24 11:11:28 UTC
File Type:
Binary (Archive)
Extracted files:
917
AV detection:
6 of 23 (26.09%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
android collection credential_access defense_evasion impact persistence
Behaviour
Checks CPU information
Checks memory information
Looks up external IP address via web service
Checks known Qemu files.
Checks known Qemu pipes.
Obtains sensitive information copied to the device clipboard
Checks if the Android device is rooted.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments