🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ac2ccb3043f3c8e4519b4130b72048b971419d73b825ccba5ab51d9adf2d2db. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1ac2ccb3043f3c8e4519b4130b72048b971419d73b825ccba5ab51d9adf2d2db
SHA3-384 hash: abed2727b01f0fb0a7ee8095c19eb7bbf21d234d4542d8acd2605e6fb9d37602cc7c475d5536fb2c00d9d5f15ee0b54a
SHA1 hash: 33f341ab5e14771174d127461c495ffbaa89ba13
MD5 hash: 1f965bf1571d2c4c3768d3c75e3c0a75
humanhash: cup-august-india-spaghetti
File name:auap-mobile.apk
Download: download sample
File size:108'975'892 bytes
First seen:2026-09-25 15:33:41 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 1572864:+PKWj6stYwdat3vsjAsz0TZkdHC2iB54OUL:o/+stY1vsGXF4O4
TLSH T17938BE46B34988AAECD664B8D90B56B1AA307C444362A0DF7E06F7807D772E52F7D3C1
TrID 50.0% (.APK) Android Package (27000/1/5)
23.1% (.VYM) VYM Mind Map (12500/1/3)
19.4% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.4% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter jitesh
Tags:android apk Axis Bank malware trojan

Intelligence


File Origin
# of uploads :
1
# of downloads :
146
Origin country :
IR IR
Vendor Threat Intelligence
Result
Application Permissions
coarse (network-based) location (ACCESS_COARSE_LOCATION)
fine (GPS) location (ACCESS_FINE_LOCATION)
take pictures and videos (CAMERA)
read contact data (READ_CONTACTS)
read external storage contents (READ_EXTERNAL_STORAGE)
read phone state and identity (READ_PHONE_STATE)
record audio (RECORD_AUDIO)
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
display system-level alerts (SYSTEM_ALERT_WINDOW)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
modify global system settings (WRITE_SETTINGS)
view network status (ACCESS_NETWORK_STATE)
full Internet access (INTERNET)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
allow use of fingerprint (USE_FINGERPRINT)
control vibrator (VIBRATE)
prevent phone from sleeping (WAKE_LOCK)
show app notification (READ_APP_BADGE)
C2DM permissions (RECEIVE)
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
android collection discovery evasion
Behaviour
Checks memory information
Acquires the wake lock
Queries information about active data network
Loads dropped Dex/Jar
Reads the content of photos stored on the user's device.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments