MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 3103a55e5f39fe474143496e5ebdfb5a2b2be924ab4cc51517b59b930a927290. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | 3103a55e5f39fe474143496e5ebdfb5a2b2be924ab4cc51517b59b930a927290 |
|---|---|
| SHA3-384 hash: | 785aa8a216b506d6c1e1411173616b0d3b0156e47ac0ac6b5b9b1b1642ea15273d7b5fb011c21db6b30583fd8c8ed817 |
| SHA1 hash: | 0c37c10636f3822a6d616a2b08bb14b2762c056d |
| MD5 hash: | 1fc38a262097414e8edb7d7906f8170a |
| humanhash: | black-island-wyoming-spaghetti |
| File name: | xupr.hydra-modilimitado.apk |
| Download: | download sample |
| File size: | 37'465'567 bytes |
| First seen: | 2026-09-16 18:03:07 UTC |
| Last seen: | Never |
| File type: | apk |
| MIME type: | application/zip |
| ssdeep | 786432:sUi4Z04cRPGiItxyCc/0dl1ZEFeYz6mwW1l7s846A:s5e04OItsCK0DDEFhzrtA |
| TLSH | T17887239BF74CF456C1F3CA368B714257A5160C688B43E6E71A01B6288EF3AC0D75AEC5 |
| TrID | 39.1% (.APK) Android Package (27000/1/5) 20.2% (.GDTB) gretl Binary Data (14000/1/2) 19.5% (.JAR) Java Archive (13500/1/2) 15.2% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3) 5.7% (.ZIP) ZIP compressed archive (4000/1) |
| Magika | apk |
| Reporter | |
| Tags: | apk BrasilTV BrazilTV Hydra Xuper TV HydraTV signed XuperTV |
Code Signing Certificate
| Organisation: | MSR Xuper TV 657 |
|---|---|
| Issuer: | MSR Xuper TV 657 |
| Algorithm: | sha384WithRSAEncryption |
| Valid from: | 2026-06-17T17:40:29Z |
| Valid to: | 2053-11-02T17:40:29Z |
| Serial number: | e005309efc2a6e33 |
| Thumbprint Algorithm: | SHA256 |
| Thumbprint: | c626cc618c1f711f831f44c55b5bfd9f2c6b41b73c6ef134a1c3d10396db75aa |
| Source: | This information was brought to you by ReversingLabs A1000 Malware Analysis Platform |
Rainb0wJagu4r
Static reverse-engineering analysis of Android APK associated with Brasil TV / Zuper Hydra TV / XuperTV.Package: com.msandroid.mobile
Version: 6.5.7 (versionCode 60507)
SHA-256: 3103A55E5F39FE474143496E5EBDFB5A2B2BE924AB4CC51517B59B930A927290
The sample contains the native library libranger-jni.so and titan.ranger-related components exposing multi-protocol proxy functionality, including HTTP/H1/H2/HA proxy handlers. Decompiled code references P2P relay telemetry fields such as sendPeerBytes, recvPeerBytes, p2pMode, p2pErr and cdnType.
Intelligence
File Origin
MXVendor Threat Intelligence
Result
Application Permissions
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | telebot_framework |
|---|---|
| Author: | vietdx.mb |
| Rule name: | test_Malaysia |
|---|---|
| Author: | rectifyq |
| Description: | Detects file containing malaysia string |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
apk 3103a55e5f39fe474143496e5ebdfb5a2b2be924ab4cc51517b59b930a927290
(this sample)
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.