🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4e6c3f36a00638652d94b6a79722c7e40e11d73674fc49b4dbdadbe82acae581. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AntiDot


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments 2

SHA256 hash: 4e6c3f36a00638652d94b6a79722c7e40e11d73674fc49b4dbdadbe82acae581
SHA3-384 hash: 75e2f62a42cff0d4373f2aa8e3e57ad22d662f3a12e0c4651087f188ff931a1ddc2171a59a3e87e4066e0d18ab5fcc1b
SHA1 hash: 1a0a97e0bde2dd7098eb3ff813be953c4c2f48dd
MD5 hash: 1a24e3c38a91011367b7ac256ebf80cf
humanhash: spaghetti-emma-minnesota-queen
File name:Mise à jour du navigateur_a664ca.apk
Download: download sample
Signature AntiDot
File size:4'254'293 bytes
First seen:2026-05-25 10:48:51 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 49152:rbEnvZ2PEROz4UkG8vxv9Oj2n5j44PVYnnH13k6j+aFhptxNTDhYaBrHmkWlSX3:re28ROz4UV2rzu46FkS7hj3htBHmkqSn
TLSH T1B516120AF54DEC7ACE793439729A6775A32278685321C3C347201E256F9B6D5CF3AAC0
TrID 60.6% (.APK) Android Package (27000/1/5)
30.3% (.JAR) Java Archive (13500/1/2)
8.9% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter skywarp
Tags:Antidot apk dropper malvertising signed

Code Signing Certificate

Organisation:aoiV0iQ8yRzqZ72i
Issuer:aoiV0iQ8yRzqZ72i
Algorithm:dsa_with_SHA256
Valid from:2026-05-25T00:18:35Z
Valid to:2081-02-25T00:18:35Z
Serial number: fb41b879393c0d34
Thumbprint Algorithm:SHA256
Thumbprint: a1c6bb0f617d350e79228657e2aa8fb126e3e10f790ed444d780727fb68874cf
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
skywarp
Obtained via forced redirect from malvertising campaign (originating from hijacked sites).

Infection chain: global-pleymarket[.]com/fr/ -> playstoreapps[.]biz/downloads/go.php?project=9f0a9ac6156656ffcc1578481ffd4aea -> APK Payload download.

Note: Android AntiDot banking trojan variant. The distribution infrastructure employs advanced server-side cloaking/TDS (returns a fake "En Construction" maintenance page if accessed via desktop User-Agent).

This updated sample features aggressive anti-analysis capabilities, actively checking for root access, Cydia Substrate framework, and QEMU/emulator system properties. If a sandbox or analysis environment is detected, the sample executes a clean termination (System.exit) to prevent payload decryption.

Active C2 infrastructure caught during early execution:
- 62.60.226[.]184 (Spamhaus DROP listed)

Intelligence


File Origin
# of uploads :
1
# of downloads :
240
Origin country :
BE BE
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
signed
Result
Application Permissions
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
display system-level alerts (SYSTEM_ALERT_WINDOW)
view Wi-Fi status (ACCESS_WIFI_STATE)
change Wi-Fi status (CHANGE_WIFI_STATE)
full Internet access (INTERNET)
Verdict:
Malicious
File Type:
apk
First seen:
2026-05-25T08:50:00Z UTC
Last seen:
2026-05-27T00:42:00Z UTC
Hits:
~10
Threat name:
Android.Trojan.Ravartar
Status:
Malicious
First seen:
2026-05-25 10:49:40 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
9 of 38 (23.68%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
android banker defense_evasion discovery impact
Behaviour
Uses Crypto APIs (Might try to encrypt user data)
Checks Android system properties for emulator presence.
Checks known Qemu files.
Checks known Qemu pipes.
Queries a list of all the installed applications on the device (Might be used in an attempt to overlay legitimate apps)
Checks if the Android device is rooted.
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

AntiDot

apk 4e6c3f36a00638652d94b6a79722c7e40e11d73674fc49b4dbdadbe82acae581

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
commented on 2026-05-25 17:53:48 UTC

I was not entirely sure too. You can't be entirely sure

Avatar
commented on 2026-05-25 17:27:39 UTC

This is not AntiDot. While not entirely sure, it looks like Android Vultur