🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 464fee5a6d85370e8764f0e682ef01cf2d9cef3efb7e4bbdf0146a94cc83ff4a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Copybara


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 464fee5a6d85370e8764f0e682ef01cf2d9cef3efb7e4bbdf0146a94cc83ff4a
SHA3-384 hash: 47f18f9e7c2c32255d298dbdbda96aae49e8666e7ebfd584ec22468b7f94eab0faa997fe1b7ba0c510d2bb9cc1f74577
SHA1 hash: 91320edbb7598d36729ce90ad7f948592d192c53
MD5 hash: 298a6d3c18508b7ccab7fde444ddab1c
humanhash: juliet-green-beer-timing
File name:464fee5a6d85370e8764f0e682ef01cf2d9cef3efb7e4bbdf0146a94cc83ff4a.apk
Download: download sample
Signature Copybara
File size:12'653'931 bytes
First seen:2026-07-29 06:07:19 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 393216:G22Cv1A9+RJmJdOtyr+rKqe1Pt/QKwn5hu8:X2CvOFn+uPyh7P
TLSH T1EDD633061E07F9D5C2B14C73ECC294788CD12F4446CBE4549DAEE9DA28BEBB5D22CB58
TrID 69.2% (.APK) Android Package (27000/1/5)
20.5% (.XPI) Mozilla Firefox browser extension (8000/1/1)
10.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter JAMESWT_WT
Tags:37-148-161-44 apk Copybara

Intelligence


File Origin
# of uploads :
1
# of downloads :
256
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anubis dropper invalid-signature signed
Result
Application Permissions
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
full Internet access (INTERNET)
Verdict:
Malicious
File Type:
apk
First seen:
2026-07-23T15:34:00Z UTC
Last seen:
2026-07-30T19:43:00Z UTC
Hits:
~10
Result
Malware family:
copybara
Score:
  10/10
Tags:
family:copybara android banker collection credential_access defense_evasion discovery evasion impact infostealer persistence trojan
Behaviour
Checks CPU information
Checks memory information
Registers a broadcast receiver at runtime (usually for listening for system events)
Attempts to obfuscate APK file format
Declares broadcast receivers with permission to handle system events
Declares services with permission to bind to the system
Queries the mobile country code (MCC)
Requests dangerous framework permissions
Loads dropped Dex/Jar
Obtains sensitive information copied to the device clipboard
Copybara payload
Family: Copybara
Malware Config
C2 Extraction:
37.148.161.44
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments