MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0c13889d0f9c8aac6880838de43150547d8bce4fb8921af47b56db9d4dc65ddd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 0c13889d0f9c8aac6880838de43150547d8bce4fb8921af47b56db9d4dc65ddd
SHA3-384 hash: 2c3125012c6c67efa164758dc7d55659e0f7caea72fb884e23ccfd1cac2a5836971d9a6c0591440fbaabdcccedc1dc0d
SHA1 hash: e8109b64239217eee3de70d9e7d9f5c0fc8e2a14
MD5 hash: 66229aa14390e4246c44d8f77d25cb8d
humanhash: salami-earth-princess-hydrogen
File name:pithus_sample_0c13889d0f9c8aac6880838de43150547d8bce4fb8921af47b56db9d4dc65ddd.apk
Download: download sample
File size:16'626'964 bytes
First seen:2026-06-21 20:36:52 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 393216:0X6WvdSWdJlLogUMzJ+dWyvhsDzSQZ4QkeK+sAP:0KWvdFdJlL9DF+dv6vSQBkp+RP
TLSH T118F62346FF58A92FC87780374B660336365A8D568E42C747385C730CA9B79E84F99BC8
TrID 60.6% (.APK) Android Package (27000/1/5)
30.3% (.JAR) Java Archive (13500/1/2)
8.9% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter trpyn
Tags:apk signed

Code Signing Certificate

Organisation:lskj
Issuer:lskj
Algorithm:sha256WithRSAEncryption
Valid from:2024-01-04T06:41:55Z
Valid to:2048-12-28T06:41:55Z
Serial number: 01
Intelligence: 467 malware samples on MalwareBazaar are signed with this code signing certificate
Cert Graveyard Blocklist:This certificate is on the Cert Graveyard blocklist
Thumbprint Algorithm:SHA256
Thumbprint: 2dcce5c56479deb819f29a3006898ef5fa8fb7c4bd5594d4085a867438f047e7
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 crypto evasive expand fingerprint lolbin persistence signed
Result
Application Permissions
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
fine (GPS) location (ACCESS_FINE_LOCATION)
act as an account authenticator (AUTHENTICATE_ACCOUNTS)
list accounts (GET_ACCOUNTS)
read phone state and identity (READ_PHONE_STATE)
read contact data (READ_CONTACTS)
read external storage contents (READ_EXTERNAL_STORAGE)
write contact data (WRITE_CONTACTS)
take pictures and videos (CAMERA)
coarse (network-based) location (ACCESS_COARSE_LOCATION)
read SMS or MMS (READ_SMS)
send SMS messages (SEND_SMS)
edit SMS or MMS (WRITE_SMS)
read Browser's history and bookmarks (READ_HISTORY_BOOKMARKS)
read calendar events (READ_CALENDAR)
add or modify calendar events and send emails to guests (WRITE_CALENDAR)
retrieve running applications (GET_TASKS)
modify global system settings (WRITE_SETTINGS)
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
directly call phone numbers (CALL_PHONE)
access location in background (ACCESS_BACKGROUND_LOCATION)
record audio (RECORD_AUDIO)
receive SMS (RECEIVE_SMS)
display system-level alerts (SYSTEM_ALERT_WINDOW)
read sensitive log data (READ_LOGS)
prevent phone from sleeping (WAKE_LOCK)
full Internet access (INTERNET)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
view Wi-Fi status (ACCESS_WIFI_STATE)
access extra location provider commands (ACCESS_LOCATION_EXTRA_COMMANDS)
create Bluetooth connections (BLUETOOTH)
kill background processes (KILL_BACKGROUND_PROCESSES)
change Wi-Fi status (CHANGE_WIFI_STATE)
view network status (ACCESS_NETWORK_STATE)
change network connectivity (CHANGE_NETWORK_STATE)
update component usage statistics (PACKAGE_USAGE_STATS)
modify battery statistics (BATTERY_STATS)
retrieve system internal status (DUMP)
directly install applications (INSTALL_PACKAGES)
modify secure system settings (WRITE_SECURE_SETTINGS)
Verdict:
Adware
File Type:
apk
First seen:
2026-05-02T11:15:00Z UTC
Last seen:
2026-06-22T23:48:00Z UTC
Hits:
~10
Gathering data
Threat name:
Android.Trojan.Generic
Status:
Suspicious
First seen:
2025-06-10 21:52:12 UTC
File Type:
Binary (Archive)
Extracted files:
820
AV detection:
11 of 36 (30.56%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments