MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ab3cc3c0df02d723c850e712fa5f4a0de29f2addf2c50beffe222112c2baa38. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 3ab3cc3c0df02d723c850e712fa5f4a0de29f2addf2c50beffe222112c2baa38
SHA3-384 hash: 9cc2e37a38f26b0ed0f3dcef9bdb5b0f3063f5eb6e19b0fadb41c6b7cf4810c4f64d6d76eb52f8eda436d388f8004ab4
SHA1 hash: f1a882d145272e998463596e3203a8269404ea01
MD5 hash: 644321ca9abd32c5d8a6f5cafde61deb
humanhash: tennessee-blue-quebec-robin
File name:TikTok18.apk
Download: download sample
File size:7'640'329 bytes
First seen:2025-12-06 16:11:35 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 196608:whNXnA47j9kixuhA57I9iKyBaX7p43Sxexl:whrn9kix4A57AiKyIXWiYxl
TLSH T10A761203F74E492ECDD2BA781953137166156CAC192092CB4A02F318BEB77E9AF16FC5
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter juroots
Tags:apk signed

Code Signing Certificate

Organisation:App
Issuer:App
Algorithm:sha384WithRSAEncryption
Valid from:2025-12-06T09:44:31Z
Valid to:2080-09-08T09:44:31Z
Serial number: decaab083defdecf
Thumbprint Algorithm:SHA256
Thumbprint: 601bfa52ea445ac2fbd73a96b56351b113e7399aa280586eae689de503db2384
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
45
Origin country :
IL IL
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
android signed
Result
Application Permissions
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
prevent phone from sleeping (WAKE_LOCK)
Verdict:
Malicious
File Type:
apk
First seen:
2025-12-06T06:56:00Z UTC
Last seen:
2025-12-07T01:41:00Z UTC
Hits:
~10
Threat name:
Android.Trojan.Generic
Status:
Suspicious
First seen:
2025-12-06 16:12:14 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

apk 3ab3cc3c0df02d723c850e712fa5f4a0de29f2addf2c50beffe222112c2baa38

(this sample)

  
Delivery method
Distributed via web download

Comments