🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 afbe6751d339fbc5b7bddd29429a11740e82fef935a61acaf2fe5487444dbed4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: afbe6751d339fbc5b7bddd29429a11740e82fef935a61acaf2fe5487444dbed4
SHA3-384 hash: 1bf98ca9a74cde8bbdfd2bbcbbae5828c51a0a9520162bf4de495e41abbc205a88eb4ab598916fc42ca5e66734632ef6
SHA1 hash: faf180d3c26db7b724a6f6c307282417dbed16a6
MD5 hash: 8559091709db25c061b856921f55e0eb
humanhash: whiskey-fifteen-six-romeo
File name:afbe6751d339fbc5b7bddd29429a11740e82fef935a61acaf2fe5487444dbed4
Download: download sample
File size:2'703'466 bytes
First seen:2026-01-28 21:02:39 UTC
Last seen:2026-01-29 15:25:42 UTC
File type: apk
MIME type:application/zip
ssdeep 49152:BR7C830FOWZB7oeMzsO/moi477H0mgW2y3KfzCg2MQ5o6C7C4VSyYlyYs:BEe0F5B7oeosO/moi47j2y3KLCg2MQ5q
TLSH T116C5CF89BB48662FC87B11370DEA923212578D478E8397437848376C79B76E80F59BCD
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter johnk3r
Tags:38-47-213-197 apk banker NFC NFCShare signed

Code Signing Certificate

Organisation:Supportazzouz
Issuer:Supportazzouz
Algorithm:sha512WithRSAEncryption
Valid from:2026-01-23T05:30:32Z
Valid to:2050-01-17T05:30:32Z
Serial number: 259c3656
Thumbprint Algorithm:SHA256
Thumbprint: f540cecce74c4ab47344912210bceb243b92a3cfe5f4ad9e6d4229944e5038b7
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
103
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Result
Application Permissions
control Near-Field Communication (NFC)
prevent phone from sleeping (WAKE_LOCK)
view network status (ACCESS_NETWORK_STATE)
full Internet access (INTERNET)
control vibrator (VIBRATE)
Verdict:
Malicious
File Type:
apk
First seen:
2026-01-28T14:13:00Z UTC
Last seen:
2026-01-30T17:09:00Z UTC
Hits:
~10
Gathering data
Threat name:
Android.Infostealer.Bank
Status:
Malicious
First seen:
2026-01-28 20:42:30 UTC
File Type:
Binary (Archive)
Extracted files:
750
AV detection:
5 of 38 (13.16%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments