MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 48b2095d9f746bb60ddf126365a9bb9ebaeae36f21dc1b5fa2213eafbdc9f18b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 48b2095d9f746bb60ddf126365a9bb9ebaeae36f21dc1b5fa2213eafbdc9f18b
SHA3-384 hash: 544f5fb754a1c5403ab0199d4e70f0d62768e743f10e5060745c8306e469b0626e42c98beb19a4c463aab6df4e2f0f8c
SHA1 hash: 7d6c9fe4a7516d40768991e9c905d7ab85a1a25b
MD5 hash: c43a542d6bd92cad03639c5aa37ea221
humanhash: neptune-florida-ink-burger
File name:c43a542d6bd92cad03639c5aa37ea221.apk
Download: download sample
File size:2'356'332 bytes
First seen:2026-08-27 06:36:42 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 49152:prh6x1tfvDvtD9GkF4sX9iunc/sLdyLbR0029l6cMKqyLvyMU4:prh6x1lvDFD9GkFfouzx6utyy
TLSH T1DAB5338DA782CC1AD61FB7B0C687741B77852336673AAB39F1D5CA40AB1373E948418C
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter myonium1
Tags:apk Brokewell dropper signed

Code Signing Certificate

Organisation:Android Debug
Issuer:Android Debug
Algorithm:sha256WithRSAEncryption
Valid from:2016-10-23T20:10:05Z
Valid to:2044-03-10T20:10:05Z
Serial number: 056c1a15
Intelligence: 90 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 1e08a903aef9c3a721510b64ec764d01d3d094eb954161b62544ea8f187b5953
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
myonium1
The dropper contains the Brokewell malware.

Intelligence


File Origin
# of uploads :
1
# of downloads :
98
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
signed
Verdict:
Malicious
File Type:
apk
First seen:
2026-07-30T22:48:00Z UTC
Last seen:
2026-07-30T23:31:00Z UTC
Hits:
~10
Threat name:
Android.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-01 02:54:00 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
5 of 38 (13.16%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
android defense_evasion impact
Behaviour
Uses Crypto APIs (Might try to encrypt user data)
Checks the application is allowed to request package installs through the package installer
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

apk 48b2095d9f746bb60ddf126365a9bb9ebaeae36f21dc1b5fa2213eafbdc9f18b

(this sample)

105f165556b5c7fc73c10cdd0aa6e6ca

  
Dropping
MD5 105f165556b5c7fc73c10cdd0aa6e6ca
  
Delivery method
Multiple

Comments