🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2b7e044edadb6932c251f2169da0a777bf553a549a263c5c8a0cf9d888cee704. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Wroba


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 2b7e044edadb6932c251f2169da0a777bf553a549a263c5c8a0cf9d888cee704
SHA3-384 hash: 053e19c7c0bc9af6907224d922b4a47d0024341c0a7546c03286730db0a92c17357c0bfc3368e09afb027fd9bc407711
SHA1 hash: 26b13151a6097a32af22da9fe2ac30b39cfb1353
MD5 hash: 42e842d51844b7b9f8e095201c14534f
humanhash: finch-nevada-hamper-alanine
File name:sagawa.apk
Download: download sample
Signature Wroba
File size:3'016'260 bytes
First seen:2026-04-17 20:02:03 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 49152:hBlSbQn3j1ZEemqlutKNXef2GKX0+wLpCw9lcjJbgYzJrksfW5gipFKV5p:hBwQJZbmGNOOkf/vcjhgexLfW+i+VT
TLSH T17AD50145FB989F5EC8F393760C396635547AD827C703C283C9792679248BAF40F862E9
TrID 60.6% (.APK) Android Package (27000/1/5)
30.3% (.JAR) Java Archive (13500/1/2)
8.9% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter BastianHein
Tags:apk signed Wroba

Code Signing Certificate

Organisation:
Issuer:
Algorithm:sha384WithRSAEncryption
Valid from:2026-06-07T12:06:17Z
Valid to:2094-11-17T12:06:17Z
Serial number: 521da3d6e6254632
Thumbprint Algorithm:SHA256
Thumbprint: 6d22bfe841afe5a520784818dd79f7dc1dd4e82e0a590e9194ea0904078b12e0
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
147
Origin country :
CL CL
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 evasive expand fingerprint lolbin persistence signed
Result
Application Permissions
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
read external storage contents (READ_EXTERNAL_STORAGE)
receive SMS (RECEIVE_SMS)
read SMS or MMS (READ_SMS)
send SMS messages (SEND_SMS)
read phone state and identity (READ_PHONE_STATE)
view Wi-Fi status (ACCESS_WIFI_STATE)
change network connectivity (CHANGE_NETWORK_STATE)
view network status (ACCESS_NETWORK_STATE)
change your audio settings (MODIFY_AUDIO_SETTINGS)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
prevent phone from sleeping (WAKE_LOCK)
full Internet access (INTERNET)
Verdict:
Malicious
File Type:
apk
First seen:
2026-04-16T16:34:00Z UTC
Last seen:
2026-04-19T03:08:00Z UTC
Hits:
~100
Threat name:
Android.Trojan.Wroba
Status:
Malicious
First seen:
2026-04-17 03:11:22 UTC
File Type:
Binary (Archive)
Extracted files:
122
AV detection:
15 of 38 (39.47%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments