🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 595355daaa6aad284090210cd55c4a2e276c5263c83d2b202e1486d347af3701. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Arsink


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 595355daaa6aad284090210cd55c4a2e276c5263c83d2b202e1486d347af3701
SHA3-384 hash: fa3eb0a98caddc9e0800652fb32efc0756e0643f64043e30ac2e2785bb923cb1522d2ba32069dfebbbfa6447e28486a7
SHA1 hash: 25504f0bab3d46ccbfc425bfba92cfde63f06577
MD5 hash: 85825bad50ab1228514962733584c041
humanhash: saturn-bacon-mars-pluto
File name:painel cheetos.apk
Download: download sample
Signature Arsink
File size:4'631'421 bytes
First seen:2026-03-27 19:38:53 UTC
Last seen:Never
File type: apk
MIME type:application/java-archive
ssdeep 98304:eKgMGsJ39M1Ur/+MdCzyxk4i11g+9JhX6+P1BWjI3C4ImK4u1a7Y:DvS1IL21/5RRCEKxa7Y
TLSH T166262343EA98D837D2A3923281F98507B9D4020156D4F7772EA4E44D8FE3E215B2AFDD
TrID 60.6% (.APK) Android Package (27000/1/5)
30.3% (.JAR) Java Archive (13500/1/2)
8.9% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter BastianHein
Tags:apk Arsink signed

Code Signing Certificate

Organisation:Android
Issuer:Android
Algorithm:sha1WithRSAEncryption
Valid from:2008-02-29T01:33:46Z
Valid to:2035-07-17T01:33:46Z
Serial number: 936eacbe07f201df
Intelligence: 1869 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
179
Origin country :
CL CL
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
signed
Result
Application Permissions
display system-level alerts (SYSTEM_ALERT_WINDOW)
control vibrator (VIBRATE)
Prevent non-system-overlay windows (HIDE_OVERLAY_WINDOWS)
display unauthorised windows (INTERNAL_SYSTEM_WINDOW)
Result
Malware family:
Score:
  10/10
Tags:
family:arsink android collection credential_access
Behaviour
Requests overlaying windows on top of other apps.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments