🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2d25cb4e862cc6cac19999798f044211ed99239dd15779be6271b680c028782a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2d25cb4e862cc6cac19999798f044211ed99239dd15779be6271b680c028782a
SHA3-384 hash: 1aef57ddc0108dbe92ac692b6197b9f8da8b0109f76d29a972a46e1b6c20fdcb85e10cb6a93164ac6ca00417b81876b7
SHA1 hash: 2edb06787250b07f40071d4186289f8f34900d10
MD5 hash: ec4b07bebe975e10334b3fb330219810
humanhash: comet-hydrogen-minnesota-november
File name:Dmart (12).apk
Download: download sample
File size:2'392'999 bytes
First seen:2026-05-06 09:45:00 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 49152:gcY+Dd+SLheidpdkBZ7Kb8aklEfSMrefeCU4Jj:geDdRdGy8maMVCdj
TLSH T189B5E0D27B86563EC83D45364CA613712B46AC25CDB6A707E814732C7CB72C84F9AED8
Magika apk
Reporter mohit
Tags:android apk DMart malware

Intelligence


File Origin
# of uploads :
1
# of downloads :
161
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
android expand invalid-signature lolbin signed
Result
Application Permissions
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
view network status (ACCESS_NETWORK_STATE)
change network connectivity (CHANGE_NETWORK_STATE)
full Internet access (INTERNET)
view Wi-Fi status (ACCESS_WIFI_STATE)
change Wi-Fi status (CHANGE_WIFI_STATE)
Verdict:
Malicious
File Type:
apk
First seen:
2025-12-01T08:44:00Z UTC
Last seen:
2026-05-08T00:00:00Z UTC
Hits:
~10
Result
Malware family:
n/a
Score:
  7/10
Tags:
android banker discovery impact
Behaviour
Uses Crypto APIs (Might try to encrypt user data)
Queries a list of all the installed applications on the device (Might be used in an attempt to overlay legitimate apps)
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments