MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 364983d2dbff85f4b9b2bac2beba40ad29ac85f2a16bdbc8fd65896ef03cddb2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 364983d2dbff85f4b9b2bac2beba40ad29ac85f2a16bdbc8fd65896ef03cddb2
SHA3-384 hash: fd29993f574f370700f27867e7778460c0ae2d75d3083be7ded9be41ac62b621153d5522bfa26b124e2c8074e30b8e6b
SHA1 hash: 83c39eedb91f01a627ab96eaba558c9352a18b03
MD5 hash: d3f801fe534fa70a5f37881ef6cf0c78
humanhash: lithium-nevada-comet-tennis
File name:ca8818e7_RT0-eChallan.apk
Download: download sample
File size:1'020'713 bytes
First seen:2026-06-24 11:12:34 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 12288:6UHy4Se6peGb3drg6xHWjeTBBmbP7juu8dHItG+Vh2D2QdGYUkMm8mYUX8kO:6UZKp9bN86feTjuJ1Jd0nlm8mYUX8N
TLSH T121252399B709C311D57B52728912A7826637EF848E12275B7842FBBCBAF37D40F05B81
TrID 87.0% (.APK) Android Package (27000/1/5)
12.9% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter realRudraP
Tags:android apk dropper


Avatar
realRudraP
Android Dropper Malware with Reflection based DEX classes loading. Potentially a VPN type app for stealing credentials

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
invalid-signature signed
Result
Application Permissions
read external storage contents (READ_EXTERNAL_STORAGE)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
set wallpaper (SET_WALLPAPER)
set wallpaper size hints (SET_WALLPAPER_HINTS)
prevent phone from sleeping (WAKE_LOCK)
Verdict:
Malicious
File Type:
apk
First seen:
2026-06-22T13:02:00Z UTC
Last seen:
2026-06-24T21:43:00Z UTC
Hits:
~10
Threat name:
Win32.Trojan.Kepavll
Status:
Malicious
First seen:
2026-06-22 18:17:26 UTC
File Type:
Binary (Archive)
Extracted files:
75
AV detection:
7 of 36 (19.44%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
android defense_evasion evasion impact
Behaviour
Uses Crypto APIs (Might try to encrypt user data)
Checks the presence of a debugger
Checks the application is allowed to request package installs through the package installer
Requests allowing to install additional applications from unknown sources.
Loads dropped Dex/Jar
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Android_ElectricityBill_Miner_APK
Author:ShriyaTiger
Description:Detects Electricity Bill themed Android malware and Miner.apk payload
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

apk 364983d2dbff85f4b9b2bac2beba40ad29ac85f2a16bdbc8fd65896ef03cddb2

(this sample)

  
Delivery method
Distributed via web download

Comments