🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9047ded41187be3c15d0d183e4fdd3d38c8f2fe16dcc495a68d12e5c7ff0f8c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Kimwolf


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: b9047ded41187be3c15d0d183e4fdd3d38c8f2fe16dcc495a68d12e5c7ff0f8c
SHA3-384 hash: a445b6bc9d723417165530addf3d500ba2d5b9f184975a724739c4ff691ce88ac86465523618da4e354b282ed3fc62b6
SHA1 hash: 11fbf18109f93ca5be1af03c0dbc4e0dcc583d55
MD5 hash: 1945b073019603d97a4296c6f6e1cd55
humanhash: vermont-blue-island-island
File name:b9047ded41187be3c15d0d183e4fdd3d38c8f2fe16dcc495a68d12e5c7ff0f8c
Download: download sample
Signature Kimwolf
File size:1'439'738 bytes
First seen:2026-03-23 16:25:00 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 24576:fCyVQYCSjm3RufyltnHlMatcXvzl3ynkuq39KeXaQos3PZbS7Dgz/J4:fjQYWuarFMaW/zlmkuiKcjtuDgz/J4
TLSH T116651292B318792FC8BB45314C6AC3761715AE11CB9A270BA624373C6D7B3C94F99BC4
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter jpgmeyer
Tags:apk botnet ddos Kimwolf proxy signed

Code Signing Certificate

Organisation:nigger
Issuer:nigger
Algorithm:sha256WithRSAEncryption
Valid from:2025-12-08T16:49:22Z
Valid to:2050-12-02T16:49:22Z
Serial number: 01
Intelligence: 481 malware samples on MalwareBazaar are signed with this code signing certificate
Cert Graveyard Blocklist:This certificate is on the Cert Graveyard blocklist
Thumbprint Algorithm:SHA256
Thumbprint: f17723a75f43aee3e69e92e9143cfaff7c09b262b65793e33ff878260f15b20c
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
jpgmeyer
kimwolf DDoS botnet sample

Intelligence


File Origin
# of uploads :
1
# of downloads :
137
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Result
Application Permissions
full Internet access (INTERNET)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:kimwolf_dropper_apk
Author:Nokia Deepfield ERT
Description:Kimwolf residential proxy botnet - Android APK dropper

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Kimwolf

apk b9047ded41187be3c15d0d183e4fdd3d38c8f2fe16dcc495a68d12e5c7ff0f8c

(this sample)

  
Delivery method
Distributed via web download

Comments