🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3c86606b1410cc558acef06d55c2a03d41ad85cb2b04e904640f58b23185db3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: b3c86606b1410cc558acef06d55c2a03d41ad85cb2b04e904640f58b23185db3
SHA3-384 hash: 1549cc162c06f5d9ba134e15870c1ba0c7cd298be223ca135bcaeccca017bf7ad8d8d15fada7cc63adbf896aacfc9be7
SHA1 hash: b38378d4c8082eded156a6814d564b6d04747a8f
MD5 hash: b8c6a538b69811c37af929b31ce0b07d
humanhash: carpet-rugby-music-pasta
File name:app.apk
Download: download sample
File size:2'723'829 bytes
First seen:2026-02-05 13:07:24 UTC
Last seen:Never
File type: apk
MIME type:application/java-archive
ssdeep 49152:+59Btc9ZCWXCmDJiUnFwRGu11CX0AJ7kdSEjEos:aBtqZ7Ca0UneRGth7kYEjEos
TLSH T1E6C5CF8AF705D8ABC0E7C636827646A65517DC258B53D2874A69F23C0CB7DC08B87EDC
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter jitesh
Tags:android apk Fake app RiskWare signed Spy-Agent

Code Signing Certificate

Organisation:(���������������)
Issuer:(���������������)
Algorithm:sha256WithRSAEncryption
Valid from:2026-01-25T11:26:46Z
Valid to:2027-01-25T11:26:46Z
Serial number: 5bc3c13d
Thumbprint Algorithm:SHA256
Thumbprint: 927e695e00445a31dff51005aabce117794850e0586b25d079c6dc70af1dbcc5
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
301
Origin country :
IN IN
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
android base64 crypto evasive fingerprint signed spyagent
Result
Application Permissions
fine (GPS) location (ACCESS_FINE_LOCATION)
coarse (network-based) location (ACCESS_COARSE_LOCATION)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
take pictures and videos (CAMERA)
read external storage contents (READ_EXTERNAL_STORAGE)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
view Wi-Fi status (ACCESS_WIFI_STATE)
prevent phone from sleeping (WAKE_LOCK)
control flashlight (FLASHLIGHT)
access SurfaceFlinger (ACCESS_SURFACE_FLINGER)
Verdict:
Adware
File Type:
apk
First seen:
2026-02-05T11:17:00Z UTC
Last seen:
2026-02-05T18:55:00Z UTC
Hits:
~10
Threat name:
Android.PUA.Multiverze
Status:
Malicious
First seen:
2026-02-05 13:08:20 UTC
File Type:
Binary (Archive)
Extracted files:
1008
AV detection:
10 of 24 (41.67%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
android collection credential_access discovery impact persistence
Behaviour
Checks CPU information
Checks memory information
Registers a broadcast receiver at runtime (usually for listening for system events)
Queries information about active data network
Queries the mobile country code (MCC)
Obtains sensitive information copied to the device clipboard
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments