🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 37aea8c8ed8ea55d23da37d997e82e6cc34bf80bce891378be7543adf6678ea1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 37aea8c8ed8ea55d23da37d997e82e6cc34bf80bce891378be7543adf6678ea1
SHA3-384 hash: dd53537b1ad61e4c4485836c8d31761434be2798beda30ea4e01a17686826059496fe1893c512783ee7cbb6cd36f4a23
SHA1 hash: 1b365a88eaccd28fa3fbac8db471bab39a98868a
MD5 hash: 30bc7a40d4de34277275963feb2d4311
humanhash: illinois-colorado-grey-nine
File name:SecureGuard.apk
Download: download sample
File size:2'282'059 bytes
First seen:2026-03-12 08:09:34 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 49152:n5n4lXbabTJnPO3ENVXdBUJ7RoiFg2wLgvObQA5Nzw:nV4lrcTJnPmsHeJ9c2wJbXLzw
TLSH T112B50241F3E9AC2FCDB785324BBA4B7A42428D46C647C71349A8B22C5DBB9C45E85FC4
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter jitesh
Tags:android apk signed SpyAgent

Code Signing Certificate

Organisation:Android Security
Issuer:Android Security
Algorithm:sha256WithRSAEncryption
Valid from:2026-03-07T05:45:42Z
Valid to:2053-07-23T05:45:42Z
Serial number: 9c0060a3b0d3ad3e
Thumbprint Algorithm:SHA256
Thumbprint: 205b97016051bb5b26af6ccc997f1e55cc5902edded218a8c64eafc512a7373c
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
226
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
android crypto evasive fingerprint infostealer persistence signed
Result
Application Permissions
display system-level alerts (SYSTEM_ALERT_WINDOW)
read SMS or MMS (READ_SMS)
send SMS messages (SEND_SMS)
receive SMS (RECEIVE_SMS)
directly call phone numbers (CALL_PHONE)
read phone state and identity (READ_PHONE_STATE)
take pictures and videos (CAMERA)
record audio (RECORD_AUDIO)
read contact data (READ_CONTACTS)
fine (GPS) location (ACCESS_FINE_LOCATION)
coarse (network-based) location (ACCESS_COARSE_LOCATION)
access location in background (ACCESS_BACKGROUND_LOCATION)
read external storage contents (READ_EXTERNAL_STORAGE)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
view Wi-Fi status (ACCESS_WIFI_STATE)
prevent phone from sleeping (WAKE_LOCK)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
control vibrator (VIBRATE)
Threat name:
Android.Trojan.AVerseFalc
Status:
Malicious
First seen:
2026-03-12 08:10:33 UTC
File Type:
Binary (Archive)
Extracted files:
450
AV detection:
12 of 38 (31.58%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
android collection credential_access defense_evasion discovery persistence
Behaviour
Registers a broadcast receiver at runtime (usually for listening for system events)
Acquires the wake lock
Makes use of the framework's foreground persistence service
Reads information about phone network operator.
Requests disabling of battery optimizations (often used to enable hiding in the background).
Requests enabling of the accessibility settings.
Makes use of the framework's Accessibility service
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments