MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b62e73892d4d3f266a7f0c75cf3746fbaf92948ea8c4565595983ec6c5852feb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: b62e73892d4d3f266a7f0c75cf3746fbaf92948ea8c4565595983ec6c5852feb
SHA3-384 hash: 8e75448cc4a6f3da14891be86aef3291ee206a61563f3ea9bd15bf1b90d2435dca47c3ebe149bde95e563f951e0bde5e
SHA1 hash: 49ac76fdecff88ef37ae6f011e165a4306aa2c41
MD5 hash: 20d367286001e5e5e603fcc944b483ce
humanhash: bulldog-cold-fix-kilo
File name:app.apk
Download: download sample
File size:27'103'731 bytes
First seen:2026-02-24 08:24:34 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 393216:KxfIk5aBVHZV2R+sl7eJ8+DzGJXqDhxMIDfgkTeCmuKZKPIwgkzV:KaMaBDa+sJQTOqn1IaebujlJzV
TLSH T1B057F023F50529AADDD6A135F5E3579532301A540393A339271FE12AFDE25CECA33AC2
TrID 51.2% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
29.2% (.WMZ) Windows Media Player skin (6000/1/1)
19.5% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter juroots
Tags:apk

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
invalid-signature signed
Result
Application Permissions
display system-level alerts (SYSTEM_ALERT_WINDOW)
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
change your audio settings (MODIFY_AUDIO_SETTINGS)
kill background processes (KILL_BACKGROUND_PROCESSES)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
prevent phone from sleeping (WAKE_LOCK)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
C2DM permissions (RECEIVE)
Gathering data
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

apk b62e73892d4d3f266a7f0c75cf3746fbaf92948ea8c4565595983ec6c5852feb

(this sample)

  
Delivery method
Distributed via web download

Comments