MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b56c5ebe5b23984cb12135be981711c187bdc577be5bb5662963dd8ad894a5ad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: b56c5ebe5b23984cb12135be981711c187bdc577be5bb5662963dd8ad894a5ad
SHA3-384 hash: c25f77d4511c35fbf4eb73f0f95bce0decacd27293782481e101f7d614bb890da0e1fc28d2423d03d64a051be185b5a5
SHA1 hash: c921e743a2066c41be8e68e26302775ff9b2de8e
MD5 hash: 6cee5446ada1611bffb7e3472fd2f8b4
humanhash: muppet-fillet-sad-happy
File name:bar88.apk
Download: download sample
File size:1'869'576 bytes
First seen:2025-10-31 13:21:01 UTC
Last seen:2025-11-20 15:24:47 UTC
File type: apk
MIME type:application/zip
ssdeep 49152:nqKSaGEhfFFDuXg2AEec+aeb2dFyK7xlvJ0vxxbhuadYmpNu:nqKSaGEhH0kaebsPHNuu
TLSH T14F85F142F3E9BC2FDEB740314FBA0B7A45864D458646D3178569B12C9DBBAC48E82FC4
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter juroots
Tags:apk signed

Code Signing Certificate

Organisation:Android Debug
Issuer:Android Debug
Algorithm:sha1WithRSAEncryption
Valid from:2022-08-25T04:37:12Z
Valid to:2052-08-17T04:37:12Z
Serial number: 01
Intelligence: 370 malware samples on MalwareBazaar are signed with this code signing certificate
Cert Central Blocklist:This certificate is on the Cert Central blocklist
Thumbprint Algorithm:SHA256
Thumbprint: 18cc1699436060ed8b698be77c56276177b4ce1f3d6c97c79bce8eab03955c3f
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
3
# of downloads :
57
Origin country :
CH CH
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
base64 evasive signed
Result
Application Permissions
full Internet access (INTERNET)
Verdict:
Clean
File Type:
apk
First seen:
2023-03-17T02:25:00Z UTC
Last seen:
2025-10-31T17:30:00Z UTC
Hits:
~100
Result
Malware family:
n/a
Score:
  7/10
Tags:
android collection credential_access discovery impact persistence
Behaviour
Checks CPU information
Checks memory information
Registers a broadcast receiver at runtime (usually for listening for system events)
Queries the mobile country code (MCC)
Obtains sensitive information copied to the device clipboard
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

apk b56c5ebe5b23984cb12135be981711c187bdc577be5bb5662963dd8ad894a5ad

(this sample)

  
Delivery method
Distributed via web download

Comments