🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2e9007b0de5fbb7050ac84bbba29a883e8a142b8c64beffbe20a3910180cbfc1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PhantomCard


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 2e9007b0de5fbb7050ac84bbba29a883e8a142b8c64beffbe20a3910180cbfc1
SHA3-384 hash: cf3a9d6bd256820cb0a2eab05195bf38345c2233106cf05f30f22a10df6d083a592fa341309ce8be5494aca1f2fb7c32
SHA1 hash: ab4b7b844c0ad4c45ce87b22b2837c302290f12b
MD5 hash: 1d56e677e79674510937496aa74ae7a2
humanhash: fifteen-lithium-colorado-papa
File name:2e9007b0de5fbb7050ac84bbba29a883e8a142b8c64beffbe20a3910180cbfc1.apk
Download: download sample
Signature PhantomCard
File size:7'945'163 bytes
First seen:2026-01-29 15:27:41 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 196608:p/BuhqOf47PfkbMJK4eXcDM5P5A0mD3YOaCxyYzm:ahqOf47QM8XEMR5A0cIOaJYzm
TLSH T19B86018BF749AA6AC8F763364A7A4A2551474CA64F83D7C37844737C58BB5C01E0ABCC
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter JAMESWT_WT
Tags:38-47-213-197 apk NFCShare phantomcard signed

Code Signing Certificate

Organisation:eere
Issuer:eere
Algorithm:sha512WithRSAEncryption
Valid from:2025-11-14T05:31:06Z
Valid to:2049-11-08T05:31:06Z
Serial number: 4265bb80
Thumbprint Algorithm:SHA256
Thumbprint: 3af68b8862c7905b7abb02031f35455dd5d752d2454d83d231193ca6589043d7
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
224
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
android base64 crypto evasive expand lolbin signed
Result
Application Permissions
control Near-Field Communication (NFC)
prevent phone from sleeping (WAKE_LOCK)
view network status (ACCESS_NETWORK_STATE)
full Internet access (INTERNET)
control vibrator (VIBRATE)
Verdict:
Malicious
File Type:
apk
First seen:
2025-12-16T12:19:00Z UTC
Last seen:
2026-01-29T23:59:00Z UTC
Hits:
~10
Threat name:
Android.Spyware.Multiverze
Status:
Malicious
First seen:
2025-12-17 01:51:22 UTC
File Type:
Binary (Archive)
Extracted files:
765
AV detection:
8 of 36 (22.22%)
Threat level:
  2/5
Result
Malware family:
phantomcard
Score:
  10/10
Tags:
family:phantomcard android
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments