🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 61f6ab5b07b1bef78e25da133d0a6df09a54f34d15c2b1dc2fdb6306ce567fce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Metasploit


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 61f6ab5b07b1bef78e25da133d0a6df09a54f34d15c2b1dc2fdb6306ce567fce
SHA3-384 hash: 602876842e3eb3119d0f601ef04c07b6f57d6eaa62acc85471c5389da135477e4a1da35ad7f8d12734d23c8e11217823
SHA1 hash: e83c36afafdfb7338546676885a37bc2ac7363b3
MD5 hash: f3c501f46b5a29378c7cfa2a46047de9
humanhash: neptune-six-skylark-red
File name:game.apk
Download: download sample
Signature Metasploit
File size:10'236 bytes
First seen:2026-03-24 18:45:35 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 192:eLt7+5NELVNzmA+I3wZ4zMCzDboVtM5u/otx5mvB0ROLNln1Mn:eLtvLLJi4nnbUtX/otxU0IHnin
TLSH T1C8229C3296B445B6C387C876872B3285692D741113EABB4FAE1C9CD7AD70446ADC6E30
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter BastianHein
Tags:apk Metasploit signed

Code Signing Certificate

Organisation:
Issuer:
Algorithm:sha1WithRSAEncryption
Valid from:2025-12-02T04:23:27Z
Valid to:2036-03-16T13:24:53Z
Serial number: 01
Intelligence: 484 malware samples on MalwareBazaar are signed with this code signing certificate
Cert Graveyard Blocklist:This certificate is on the Cert Graveyard blocklist
Thumbprint Algorithm:SHA256
Thumbprint: 03e91e6ae616b8a1e6066cd3c2047d60b24e02bb2f91d37e39e8ee5053cd24cf
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
210
Origin country :
CL CL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
android crypto evasive fingerprint invalid-signature persistence signed
Result
Application Permissions
coarse (network-based) location (ACCESS_COARSE_LOCATION)
fine (GPS) location (ACCESS_FINE_LOCATION)
read phone state and identity (READ_PHONE_STATE)
send SMS messages (SEND_SMS)
receive SMS (RECEIVE_SMS)
record audio (RECORD_AUDIO)
directly call phone numbers (CALL_PHONE)
read contact data (READ_CONTACTS)
write contact data (WRITE_CONTACTS)
modify global system settings (WRITE_SETTINGS)
take pictures and videos (CAMERA)
read SMS or MMS (READ_SMS)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
full Internet access (INTERNET)
view Wi-Fi status (ACCESS_WIFI_STATE)
change Wi-Fi status (CHANGE_WIFI_STATE)
view network status (ACCESS_NETWORK_STATE)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
set wallpaper (SET_WALLPAPER)
prevent phone from sleeping (WAKE_LOCK)
Threat name:
Android.Hacktool.MetaSploit
Status:
Malicious
First seen:
2026-03-21 03:10:09 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
18 of 38 (47.37%)
Threat level:
  1/5
Result
Malware family:
metasploit
Score:
  10/10
Tags:
family:metasploit android
Behaviour
Acquires the wake lock
Malware Config
C2 Extraction:
tcp://192.168.17.129:4444
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments