🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 050537a47b5463e96a9f3e7ba79c607017faceeb668cef8aa1d5e11a19ff4990. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 050537a47b5463e96a9f3e7ba79c607017faceeb668cef8aa1d5e11a19ff4990
SHA3-384 hash: fa0f0ca635922eb011335652c5ce9e047eac52a57dac488d4c7dfcbb44ff00a9c72e28033a5bb8ba0bec5c12603056cf
SHA1 hash: 366b830464c0d609b94f8f2f460ac37474eabf67
MD5 hash: 4447efc903329f4916656a99161c7725
humanhash: early-nine-five-pizza
File name:050537a47b5463e96a9f3e7ba79c607017faceeb668cef8aa1d5e11a19ff4990.apk
Download: download sample
File size:87'819'084 bytes
First seen:2026-04-15 12:55:23 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 786432:Qx8hpRVAgfsVI0mke75jT0ZfR7LzfvfWyYEL9aoW56k1mApPfjO72Qm/fvpJc:jf9R5fyYLT1Y72QsJc
TLSH T19118E147F6428CA7CDE55470A55ED277B3223D6CC352A213AA44B7287EBB7D44F2A380
TrID 50.0% (.APK) Android Package (27000/1/5)
23.1% (.VYM) VYM Mind Map (12500/1/3)
19.4% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.4% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter JAMESWT_WT
Tags:45-74-4-179 apk

Intelligence


File Origin
# of uploads :
1
# of downloads :
225
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 crypto evasive fingerprint persistence signed
Result
Application Permissions
read phone state and identity (READ_PHONE_STATE)
Allows an application a broad access to external storage in scoped storage (MANAGE_EXTERNAL_STORAGE)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
read external storage contents (READ_EXTERNAL_STORAGE)
read contact data (READ_CONTACTS)
write contact data (WRITE_CONTACTS)
read SMS or MMS (READ_SMS)
send SMS messages (SEND_SMS)
display system-level alerts (SYSTEM_ALERT_WINDOW)
record audio (RECORD_AUDIO)
full Internet access (INTERNET)
view Wi-Fi status (ACCESS_WIFI_STATE)
view network status (ACCESS_NETWORK_STATE)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
prevent phone from sleeping (WAKE_LOCK)
control vibrator (VIBRATE)
C2DM permissions (RECEIVE)
Verdict:
Malicious
File Type:
apk
First seen:
2025-09-26T23:21:00Z UTC
Last seen:
2025-09-27T05:48:00Z UTC
Hits:
~10
Gathering data
Result
Malware family:
n/a
Score:
  6/10
Tags:
android defense_evasion discovery execution persistence
Behaviour
Schedules tasks to execute at a specified time
Acquires the wake lock
Makes use of the framework's foreground persistence service
Queries information about active data network
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments