MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a709559e33100af7786ea3adb171afe2f1d0708ee5affe65d68b70a7a779671a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: a709559e33100af7786ea3adb171afe2f1d0708ee5affe65d68b70a7a779671a
SHA3-384 hash: de527610e8b760d3506057ec294f7d5b1df49085b6b60083c2f2fab4d4c06e15348836d1753d577329be725df7635bfe
SHA1 hash: c7dd39a2a47e6706f57fa137b162e9d6f89d8ef3
MD5 hash: 0f571c4d26ad7eabca615765ba29d67a
humanhash: robin-muppet-autumn-cold
File name:SUD CHAQIRUVI_105.pdf.apk
Download: download sample
File size:1'061'802 bytes
First seen:2026-08-22 12:07:44 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 24576:ZWHQzcKiXthop0fVSXGYzcdJEtsaD2yT2wgWgprViaC:owzcKathokMXGYzczEtsMJPg1rVi5
TLSH T196352307FB8F19BCCC6624BC18D691046D182AB1A2DA931348053E95F6B0E91FE57EDF
TrID 87.0% (.APK) Android Package (27000/1/5)
12.9% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter nrf322
Tags:apk dropper fake-pdf sms-stealer-suspected uzbekistan


Avatar
nrf322
Disguises as a PDF ("SUD CHAQIRUVI.pdf" = fake Uzbek court summons) via app label + icon spoofing. Package com.luzpvwir.xcyumjjmuf, launch activity in unrelated internal namespace nxqhtswvr.com.*. Requests REQUEST_INSTALL_PACKAGES (dropper) + persistent FOREGROUND_SERVICE_DATA_SYNC. Real payload appears to be encrypted/packed in assets/*.sps (largest: salxad.sps, 562KB) - no plaintext strings/URLs found via static analysis of classes.dex, likely loaded dynamically via DexClassLoader. Self-signed cert with fake DN (C=UZ, CN=jutec).

Intelligence


File Origin
# of uploads :
1
# of downloads :
107
Origin country :
GB GB
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
dropper masquerade signed
Result
Application Permissions
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
full Internet access (INTERNET)
prevent phone from sleeping (WAKE_LOCK)
Threat name:
Android.Trojan.Generic
Status:
Suspicious
First seen:
2026-08-22 12:08:15 UTC
File Type:
Binary (Archive)
Extracted files:
55
AV detection:
7 of 37 (18.92%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
android banker defense_evasion discovery
Behaviour
Checks the presence of a debugger
Queries a list of all the installed applications on the device (Might be used in an attempt to overlay legitimate apps)
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

apk a709559e33100af7786ea3adb171afe2f1d0708ee5affe65d68b70a7a779671a

(this sample)

  
Delivery method
Distributed via web download

Comments