MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 95e88ec3ceb56c7f3679c45b837f931d0b38269a2e275628f2bc1a9f5c77a19f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 95e88ec3ceb56c7f3679c45b837f931d0b38269a2e275628f2bc1a9f5c77a19f
SHA3-384 hash: 38c00015cb76629721e23361de468da429b1733912b260e5f88e3d403fd7c3fe385ef645fcd37e672eff07fb025e97be
SHA1 hash: 6b21dffc6b1086e9d5ac6ea2e7b0c1b9f4e913de
MD5 hash: 9d5614feb0514b304dc107f9db367522
humanhash: hamper-ohio-wisconsin-thirteen
File name:TikTok18.apk
Download: download sample
File size:9'598'738 bytes
First seen:2026-02-27 11:20:46 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 196608:+I5ktrR78Rdhj/t/dItuSP6VqDTyDVoc4bpx/kFJib7A6wzlpgoLyStn2I:+I5Id78vRt/dCCV4eyckxYJIsVlpgoLX
TLSH T11FA633C2F3296C2FD4770A3219A607712B22AD16CE96974B2549332D7CBBAC90F54FC5
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter juroots
Tags:apk signed

Code Signing Certificate

Organisation:main_app
Issuer:main_app
Algorithm:sha384WithRSAEncryption
Valid from:2026-02-27T07:19:47Z
Valid to:2076-09-19T07:19:47Z
Serial number: de9cdc7b75d9a600
Thumbprint Algorithm:SHA256
Thumbprint: 541b40ed440d3777d94fa3281c4ec5b09165fc5786fd9bfcb72b38ac18fe9298
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
RO RO
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
signed
Result
Application Permissions
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
view network status (ACCESS_NETWORK_STATE)
expand/collapse status bar (EXPAND_STATUS_BAR)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
measure application storage space (GET_PACKAGE_SIZE)
prevent phone from sleeping (WAKE_LOCK)
full Internet access (INTERNET)
change your audio settings (MODIFY_AUDIO_SETTINGS)
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

apk 95e88ec3ceb56c7f3679c45b837f931d0b38269a2e275628f2bc1a9f5c77a19f

(this sample)

  
Delivery method
Distributed via web download

Comments