MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 63a19cd37e5f23ba982d004e587472bdc30d64af04e1b321419d8173a16c60cc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 63a19cd37e5f23ba982d004e587472bdc30d64af04e1b321419d8173a16c60cc
SHA3-384 hash: f65218630c05139f8bc78c5bfcdf872d5ed0f52781c6e053e4968b230461bd352fbe8240b30bbf80a99b14198087f5d5
SHA1 hash: 491718ab8a3745376f7d76ff5696e373d3bd57e7
MD5 hash: 698d811173c6ea3e5ae5f37251a8855e
humanhash: double-blue-king-freddie
File name:TikTok18.apk
Download: download sample
File size:9'541'790 bytes
First seen:2026-03-11 18:34:37 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 196608:OsXyrMOArjv2K4Id5MpmRY3PDgvv1ktR7rGGlpgoLyStn0:fiQjrqKPpRY3WeRuGlpgoLyStn0
TLSH T122A633D2F716492ED8B604328DAE07752B555D928A92870B7168373CBC3BBD84F98FD0
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter jitesh
Tags:android apk dropper malware signed Tiktok trojan

Code Signing Certificate

Organisation:main_app
Issuer:main_app
Algorithm:sha384WithRSAEncryption
Valid from:2026-03-11T16:50:06Z
Valid to:2093-11-16T16:50:06Z
Serial number: 1122725204ac2f4d
Thumbprint Algorithm:SHA256
Thumbprint: 9ba9a156467a7d2ac31d9f53670d738398268ebe7a83af9d1c458085949b6d6a
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
232
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
signed
Result
Application Permissions
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
full Internet access (INTERNET)
expand/collapse status bar (EXPAND_STATUS_BAR)
view network status (ACCESS_NETWORK_STATE)
reorder applications running (REORDER_TASKS)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
prevent phone from sleeping (WAKE_LOCK)
read sync statistics (READ_SYNC_STATS)
Threat name:
Android.Trojan.AVerseFalc
Status:
Malicious
First seen:
2026-03-11 18:35:35 UTC
File Type:
Binary (Archive)
Extracted files:
412
AV detection:
8 of 38 (21.05%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments