MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ba4bb9f0990697fa0c3b12ddf2d1f31ef385e14556c081f3f5e30dcbbf50f1a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GhostBat


Vendor detections: 8


Intelligence 8 IOCs YARA 4 File information Comments

SHA256 hash: 1ba4bb9f0990697fa0c3b12ddf2d1f31ef385e14556c081f3f5e30dcbbf50f1a
SHA3-384 hash: cf293f8f87d15fd3bed856790abf65982b9316e97761e786beba38d2d331cec90275e6d5988f0f156b6583757184c5a1
SHA1 hash: d81a1fe640b844031f94dfcc55768dabce48910b
MD5 hash: e98ac10945ac4ee27c0397677f5e5ec0
humanhash: berlin-cat-princess-summer
File name:temp_info.apk
Download: download sample
Signature GhostBat
File size:7'519'688 bytes
First seen:2026-07-04 01:24:04 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 196608:LedyVcRD2AZvVVNgl1XaD+ebY5pHKhNvMqg:LedXRbZvl2KbOoNvpg
TLSH T16776014BF7C59B2BC53980BA4827323652575D0A8A93821BED2CB71C78735F45F88BD8
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter BastianHein
Tags:apk Arsink GhostBat HDFC

Intelligence


File Origin
# of uploads :
1
# of downloads :
164
Origin country :
CL CL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
bankingtrojan expand invalid-signature lolbin mirai obfuscated signed
Result
Application Permissions
read SMS or MMS (READ_SMS)
receive SMS (RECEIVE_SMS)
send SMS messages (SEND_SMS)
send SMS messages (SEND_SMS_NO_CONFIRMATION)
edit SMS or MMS (WRITE_SMS)
directly call phone numbers (CALL_PHONE)
intercept outgoing calls (PROCESS_OUTGOING_CALLS)
read phone state and identity (READ_PHONE_STATE)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
read external storage contents (READ_EXTERNAL_STORAGE)
Allows an application a broad access to external storage in scoped storage (MANAGE_EXTERNAL_STORAGE)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
prevent phone from sleeping (WAKE_LOCK)
change network connectivity (CHANGE_NETWORK_STATE)
view Wi-Fi status (ACCESS_WIFI_STATE)
change Wi-Fi status (CHANGE_WIFI_STATE)
send SMS-received broadcast (BROADCAST_SMS)
Verdict:
Malicious
File Type:
apk
First seen:
2026-07-03T23:59:00Z UTC
Last seen:
2026-07-05T19:30:00Z UTC
Hits:
~100
Threat name:
Android.Trojan.AVerseFalc
Status:
Malicious
First seen:
2026-07-04 02:24:22 UTC
AV detection:
9 of 38 (23.68%)
Threat level:
  5/5
Result
Malware family:
ghostbat
Score:
  10/10
Tags:
family:arsink family:ghostbat android collection credential_access defense_evasion discovery impact infostealer persistence rat trojan
Behaviour
Checks CPU information
Checks memory information
Uses Crypto APIs (Might try to encrypt user data)
Looks up external IP address via web service
Makes use of the framework's foreground persistence service
Requests disabling of battery optimizations (often used to enable hiding in the background).
Obtains sensitive information copied to the device clipboard
Queries the phone number (MSISDN for GSM devices)
Reads the content of the SMS messages.
Checks if the Android device is rooted.
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Android_ElectricityBill_Miner_APK
Author:ShriyaTiger
Description:Detects Electricity Bill themed Android malware and Miner.apk payload
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:Jeevan_Malware_Rewards
Author:ShriTiger
Description:Detects JeevanReward variants using Technical, Anti-Analysis, and Indian SE keywords
Rule name:ldpreload
Author:xorseed
Reference:https://stuff.rop.io/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments