🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd8d876a63c55a252a600f565c9ccc0f9d2375a0a341b84f5821b07d85f111de. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 3 File information Comments

SHA256 hash: bd8d876a63c55a252a600f565c9ccc0f9d2375a0a341b84f5821b07d85f111de
SHA3-384 hash: b12745198e77f053ae6ef34a42c163d59ddf3ab70fe570eed503d209315f6422cb152ee8f16cab981032a5d9411f87f3
SHA1 hash: ab7f49f42de87ae67e5eef01c7eceed3d80052e0
MD5 hash: ff24eae11453cca0687c832a9c8dbdef
humanhash: alpha-bacon-low-avocado
File name:TelegramFix.apk
Download: download sample
File size:3'119'597 bytes
First seen:2026-04-23 17:12:26 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 49152:EEikpIzcb3vNQrfoNuijwDF0okRjWKzk79/ikT01QsgyB191d3pKyoOu:E7kp3CrAwP4LzUdMB191d3pXoOu
TLSH T17AE5CE8BF749592FC8B705B249AE537066538C028E87AB437C48371C6D7B6D82F59BC8
TrID 40.0% (.APK) Android Package (27000/1/5)
20.0% (.JAR) Java Archive (13500/1/2)
18.5% (.VYM) VYM Mind Map (12500/1/3)
15.5% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
5.9% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter Alex_sev
Tags:android apk banker mamont signed

Code Signing Certificate

Organisation:Joe Coan
Issuer:Joe Coan
Algorithm:sha384WithRSAEncryption
Valid from:2026-03-02T16:28:11Z
Valid to:3025-07-03T16:28:11Z
Serial number: e8ff1a0c38b5c5c4
Thumbprint Algorithm:SHA256
Thumbprint: 25576b0e2fb3aa694a530884a24ce0345be965e051359a49602933319dfa6cc3
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
251
Origin country :
AU AU
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
android expand lolbin signed
Result
Application Permissions
read phone state and identity (READ_PHONE_STATE)
send SMS messages (SEND_SMS)
receive SMS (RECEIVE_SMS)
receive MMS (RECEIVE_MMS)
read SMS or MMS (READ_SMS)
full Internet access (INTERNET)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
prevent phone from sleeping (WAKE_LOCK)
view network status (ACCESS_NETWORK_STATE)
Verdict:
Malicious
File Type:
apk
First seen:
2026-04-23T14:23:00Z UTC
Last seen:
2026-04-25T00:48:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Banker.AndroidOS.Mamont.gf HEUR:Trojan-Banker.AndroidOS.Mamont.ga
Verdict:
Malicious
Threat:
Trojan-Banker.AndroidOS.Mamont
Threat name:
Android.Trojan.AVerseFalc
Status:
Malicious
First seen:
2026-04-23 17:07:08 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
7 of 38 (18.42%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:telebot_framework
Author:vietdx.mb
Rule name:Weedhack_Family_Generic
Author:jlab
Description:Generic Weedhack family detection

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments