🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7b68d452bf402df7e3a0f04bc59e36dfee84800bfc0595fbf602f3f621c883c1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Joker


Vendor detections: 3


Intelligence 3 IOCs YARA 4 File information Comments

SHA256 hash: 7b68d452bf402df7e3a0f04bc59e36dfee84800bfc0595fbf602f3f621c883c1
SHA3-384 hash: 60b0c002acd548f2b1f0403a6a6ec3985dc7522055417964149c3413d5e5c730a2215629cf9e0b0bb34034b4eda8b896
SHA1 hash: add6676970143f40635056e7889c3fed0c2cf734
MD5 hash: 5a2d95bd313bea27872d276c72a9cbff
humanhash: pizza-florida-lamp-harry
File name:Quick Cleaner_8.8.apk
Download: download sample
Signature Joker
File size:34'725'213 bytes
First seen:2026-03-25 03:01:52 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 786432:hLZ+pxAvbt30JhQ7v41XAKIIYZlTmwIblNsbo:9pvbxvuAKpYPtIvh
TLSH T13A77237A9318346AD43A91B75E1E3A79328D0D787B42A7E71401B2DD28F36E48709FC7
TrID 44.6% (.APK) Android Package (27000/1/5)
18.1% (.CATROBAT) Pocket Code/Catroid Catrobat Project (11000/1/2)
17.3% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
13.2% (.WIDGET) Konfabulator widget (8000/1/2)
6.6% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter Anonymous
Tags:apk joker malware

Intelligence


File Origin
# of uploads :
1
# of downloads :
189
Origin country :
HK HK
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
adware base64 crypto evasive fingerprint obfuscated soft-404
Result
Application Permissions
list accounts (GET_ACCOUNTS)
read external storage contents (READ_EXTERNAL_STORAGE)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
fine (GPS) location (ACCESS_FINE_LOCATION)
coarse (network-based) location (ACCESS_COARSE_LOCATION)
act as an account authenticator (AUTHENTICATE_ACCOUNTS)
Allows an application a broad access to external storage in scoped storage (MANAGE_EXTERNAL_STORAGE)
directly call phone numbers (CALL_PHONE)
display system-level alerts (SYSTEM_ALERT_WINDOW)
read contact data (READ_CONTACTS)
retrieve running applications (GET_TASKS)
read phone state and identity (READ_PHONE_STATE)
modify global system settings (WRITE_SETTINGS)
take pictures and videos (CAMERA)
control flashlight (FLASHLIGHT)
kill background processes (KILL_BACKGROUND_PROCESSES)
prevent phone from sleeping (WAKE_LOCK)
kill background processes (RESTART_PACKAGES)
expand/collapse status bar (EXPAND_STATUS_BAR)
measure application storage space (GET_PACKAGE_SIZE)
allow use of fingerprint (USE_FINGERPRINT)
control vibrator (VIBRATE)
read sync statistics (READ_SYNC_STATS)
write sync settings (WRITE_SYNC_SETTINGS)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
change Wi-Fi status (CHANGE_WIFI_STATE)
view network status (ACCESS_NETWORK_STATE)
full Internet access (INTERNET)
change network connectivity (CHANGE_NETWORK_STATE)
view Wi-Fi status (ACCESS_WIFI_STATE)
update component usage statistics (PACKAGE_USAGE_STATS)
C2DM permissions (RECEIVE)
delete other applications' caches (DELETE_CACHE_FILES)
delete all application cache data (CLEAR_APP_CACHE)
Gathering data
Result
Malware family:
n/a
Score:
  6/10
Tags:
android
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:dependsonpythonailib
Author:Tim Brown
Description:Hunts for dependencies on Python AI libraries
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments