🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3103a55e5f39fe474143496e5ebdfb5a2b2be924ab4cc51517b59b930a927290. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: 3103a55e5f39fe474143496e5ebdfb5a2b2be924ab4cc51517b59b930a927290
SHA3-384 hash: 785aa8a216b506d6c1e1411173616b0d3b0156e47ac0ac6b5b9b1b1642ea15273d7b5fb011c21db6b30583fd8c8ed817
SHA1 hash: 0c37c10636f3822a6d616a2b08bb14b2762c056d
MD5 hash: 1fc38a262097414e8edb7d7906f8170a
humanhash: black-island-wyoming-spaghetti
File name:xupr.hydra-modilimitado.apk
Download: download sample
File size:37'465'567 bytes
First seen:2026-09-16 18:03:07 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 786432:sUi4Z04cRPGiItxyCc/0dl1ZEFeYz6mwW1l7s846A:s5e04OItsCK0DDEFhzrtA
TLSH T17887239BF74CF456C1F3CA368B714257A5160C688B43E6E71A01B6288EF3AC0D75AEC5
TrID 39.1% (.APK) Android Package (27000/1/5)
20.2% (.GDTB) gretl Binary Data (14000/1/2)
19.5% (.JAR) Java Archive (13500/1/2)
15.2% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
5.7% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter Rainb0wJagu4r
Tags:apk BrasilTV BrazilTV Hydra Xuper TV HydraTV signed XuperTV

Code Signing Certificate

Organisation:MSR Xuper TV 657
Issuer:MSR Xuper TV 657
Algorithm:sha384WithRSAEncryption
Valid from:2026-06-17T17:40:29Z
Valid to:2053-11-02T17:40:29Z
Serial number: e005309efc2a6e33
Thumbprint Algorithm:SHA256
Thumbprint: c626cc618c1f711f831f44c55b5bfd9f2c6b41b73c6ef134a1c3d10396db75aa
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
Rainb0wJagu4r
Static reverse-engineering analysis of Android APK associated with Brasil TV / Zuper Hydra TV / XuperTV.

Package: com.msandroid.mobile
Version: 6.5.7 (versionCode 60507)
SHA-256: 3103A55E5F39FE474143496E5EBDFB5A2B2BE924AB4CC51517B59B930A927290

The sample contains the native library libranger-jni.so and titan.ranger-related components exposing multi-protocol proxy functionality, including HTTP/H1/H2/HA proxy handlers. Decompiled code references P2P relay telemetry fields such as sendPeerBytes, recvPeerBytes, p2pMode, p2pErr and cdnType.

Intelligence


File Origin
# of uploads :
1
# of downloads :
125
Origin country :
MX MX
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
base64 captcha crypto evasive lolbin obfuscated obfuscated packed secneo signed tracker
Result
Application Permissions
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
retrieve running applications (GET_TASKS)
take pictures and videos (CAMERA)
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
Allows an application a broad access to external storage in scoped storage (MANAGE_EXTERNAL_STORAGE)
read external storage contents (READ_EXTERNAL_STORAGE)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
change network connectivity (CHANGE_NETWORK_STATE)
view Wi-Fi status (ACCESS_WIFI_STATE)
prevent phone from sleeping (WAKE_LOCK)
control vibrator (VIBRATE)
change Wi-Fi status (CHANGE_WIFI_STATE)
allow Wi-Fi Multicast reception (CHANGE_WIFI_MULTICAST_STATE)
create Bluetooth connections (BLUETOOTH)
C2DM permissions (RECEIVE)
Verdict:
Unknown
File Type:
apk
First seen:
2026-08-07T15:57:00Z UTC
Last seen:
2026-08-31T10:59:00Z UTC
Hits:
~10
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

apk 3103a55e5f39fe474143496e5ebdfb5a2b2be924ab4cc51517b59b930a927290

(this sample)

  
Dropping
Botnet
  
Delivery method
Distributed via web download

Comments