MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 2dba129f35c5c0c5e858f39ddcb396fb5d0e64822dcb5e1b037b6e3558d1cf6a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 5
| SHA256 hash: | 2dba129f35c5c0c5e858f39ddcb396fb5d0e64822dcb5e1b037b6e3558d1cf6a |
|---|---|
| SHA3-384 hash: | 87ab055e8105e89222191db1d7bc702a859781f7ab6d8ce1574ecebda6105484be96cbf717959e6c1ef5a3a7a52416b3 |
| SHA1 hash: | e546d7d440267bc0f6717151fc97da6566c5e1c9 |
| MD5 hash: | cf9a42b6ab217490f8957ae819bd7d34 |
| humanhash: | violet-tennis-black-avocado |
| File name: | cici303_1.0.0.apk |
| Download: | download sample |
| File size: | 4'843'402 bytes |
| First seen: | 2025-11-13 06:51:15 UTC |
| Last seen: | 2025-11-13 12:42:29 UTC |
| File type: | apk |
| MIME type: | application/zip |
| ssdeep | 98304:4tHeMJ6p3Z4TBWz+eP4h8H7VOZ/sNXcE6pmbcP6Sa1q+LmsL+gLCr4op:kHeMJ6Nuz24CI0rbcPta1QQSp |
| TLSH | T19526F08BF758A92FC87B14F209AE523166574D168E839B436C48321C68776D83F9DFC8 |
| TrID | 65.0% (.APK) Android Package (27000/1/5) 25.3% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3) 9.6% (.ZIP) ZIP compressed archive (4000/1) |
| Magika | apk |
| Reporter | |
| Tags: | apk |
Intelligence
File Origin
# of uploads :
2
# of downloads :
60
Origin country :
CHVendor Threat Intelligence
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
base64 crypto evasive expand fingerprint lolbin signed
Result
Application Permissions
full Internet access (INTERNET)
Verdict:
Unknown
File Type:
apk
First seen:
2024-06-28T05:47:00Z UTC
Last seen:
2025-11-14T05:50:00Z UTC
Hits:
~10
Score:
98%
Verdict:
Malware
File Type:
APK
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
7/10
Tags:
android collection credential_access discovery impact persistence
Behaviour
Checks CPU information
Checks memory information
Registers a broadcast receiver at runtime (usually for listening for system events)
Queries the mobile country code (MCC)
Obtains sensitive information copied to the device clipboard
Verdict:
Unknown
Tags:
n/a
YARA:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.05
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
apk 2dba129f35c5c0c5e858f39ddcb396fb5d0e64822dcb5e1b037b6e3558d1cf6a
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.