🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3e6edebc2da9a4a80507eeb7abf529c9c3a70201927f1ae864f9f257ca64bc2e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Arsink


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 3e6edebc2da9a4a80507eeb7abf529c9c3a70201927f1ae864f9f257ca64bc2e
SHA3-384 hash: 36857fb86ee2c1cf4ba8dd0ca285de3a1f9712a16c056ad1d9cafdcdcd77acbbca4c8b57dfc1f8e5b6cb8ac4573cfc0e
SHA1 hash: 34dacea9525c261b9948bdca9a3f63a525f32c40
MD5 hash: 0b1f1f573a7d947f468aafc29f6d97fd
humanhash: robert-uncle-leopard-alpha
File name:FL TOUR BD.apk
Download: download sample
Signature Arsink
File size:17'423'890 bytes
First seen:2026-03-27 20:20:02 UTC
Last seen:Never
File type: apk
MIME type:application/java-archive
ssdeep 393216:NJuJwaADuRW5Uq2Rt0eLuZBtxvj0qJDursiWcf:N+zWtat0eLuZBtxvBDViWcf
TLSH T1DC072285FB44E52BC17B8036C5BA5627918B4C128F83D7936D45764C68BBAD8CF0AFC8
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter BastianHein
Tags:apk Arsink

Intelligence


File Origin
# of uploads :
1
# of downloads :
178
Origin country :
CL CL
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated signed
Result
Application Permissions
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
prevent phone from sleeping (WAKE_LOCK)
C2DM permissions (RECEIVE)
Result
Malware family:
Score:
  10/10
Tags:
family:arsink android discovery
Behaviour
Acquires the wake lock
Queries information about active data network
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments