🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3dec12d27b8a187e4e67977fb64c38e0c830f1c6a6b630d702e2af7e769db6ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 3dec12d27b8a187e4e67977fb64c38e0c830f1c6a6b630d702e2af7e769db6ec
SHA3-384 hash: b22453a852793cd30cfb749c91c87b9c172aa65a6382f96c80d3397d16ad2baa6761abccd4b11795a1266ae3dd031a32
SHA1 hash: 85106c70ef93b88447d72b2fae5ea6abbb8c5d14
MD5 hash: 5c7786e8688794e67e11140a501d2694
humanhash: massachusetts-twenty-east-magnesium
File name:app.apk
Download: download sample
File size:5'317'133 bytes
First seen:2026-02-05 13:20:35 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 98304:qkEAtz6OIcxQZMdXfvghDn2U2GerFjpO7xJkaev+0EMgLCrFXLdB3:qkEAtdpQhD+GerpE7xJkaenDhB3
TLSH T15336E08BFB48A89BC4F753B24539532241474C268B83D7C36D58723C19BB6D06F9EAC9
TrID 40.0% (.APK) Android Package (27000/1/5)
20.0% (.JAR) Java Archive (13500/1/2)
18.5% (.VYM) VYM Mind Map (12500/1/3)
15.5% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
5.9% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter jitesh
Tags:android apk dropper FakeApp IBKR signed

Code Signing Certificate

Organisation:vumz
Issuer:vumz
Algorithm:sha512WithRSAEncryption
Valid from:2026-01-30T04:10:01Z
Valid to:2076-01-18T04:10:01Z
Serial number: 5d7e9a1f
Thumbprint Algorithm:SHA256
Thumbprint: 238a7698dd09613fe9684802a132efa24225886fe0104f21e5184ac64119bb4d
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
303
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
base64 crypto evasive expand fingerprint lolbin signed
Result
Application Permissions
read external storage contents (READ_EXTERNAL_STORAGE)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
view network status (ACCESS_NETWORK_STATE)
full Internet access (INTERNET)
Verdict:
Malicious
File Type:
apk
First seen:
2026-02-05T11:25:00Z UTC
Last seen:
2026-02-05T19:01:00Z UTC
Hits:
~10
Threat name:
Android.PUA.Multiverze
Status:
Malicious
First seen:
2026-02-05 13:21:19 UTC
File Type:
Binary (Archive)
Extracted files:
847
AV detection:
9 of 38 (23.68%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
android collection credential_access discovery impact persistence
Behaviour
Checks CPU information
Checks memory information
Registers a broadcast receiver at runtime (usually for listening for system events)
Queries information about active data network
Queries the mobile country code (MCC)
Obtains sensitive information copied to the device clipboard
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments