🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c5cc20ef48e8c9cd6cf76d8a9d8cc6a04ad4985bd2c86d461beeece88e4fccc9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Joker


Vendor detections: 3


Intelligence 3 IOCs YARA 3 File information Comments

SHA256 hash: c5cc20ef48e8c9cd6cf76d8a9d8cc6a04ad4985bd2c86d461beeece88e4fccc9
SHA3-384 hash: 90558cc38a6169a41db7fe4a9d1715f920673b9440277b7f9b7d2e20c7afec07a825763d93549045840314b4c0f644f5
SHA1 hash: 8101539ca9303eb7e760285f88fa839cf3c282fe
MD5 hash: a96d89295527b90c93e406135b6dd00c
humanhash: illinois-asparagus-juliet-double
File name:Phone Cleaner_1.16.apk
Download: download sample
Signature Joker
File size:27'634'201 bytes
First seen:2026-03-25 03:10:16 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 786432:ELOszWYCPCLlw+WuFLU0Evtjn+Av2GctPG8lE:EOszWYCPnluFLUXxz0G
TLSH T1D657126BB35CAD2FD4365072C9593236D18E0F25AF4297D3682C768C39B39E08B25BD4
TrID 65.0% (.APK) Android Package (27000/1/5)
25.3% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
9.6% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter Anonymous
Tags:apk joker malware

Intelligence


File Origin
# of uploads :
1
# of downloads :
181
Origin country :
HK HK
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
adware base64 crypto evasive expand finger fingerprint lolbin tracker
Result
Application Permissions
read external storage contents (READ_EXTERNAL_STORAGE)
modify global system settings (WRITE_SETTINGS)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
Allows an application a broad access to external storage in scoped storage (MANAGE_EXTERNAL_STORAGE)
prevent phone from sleeping (WAKE_LOCK)
control vibrator (VIBRATE)
view network status (ACCESS_NETWORK_STATE)
allow use of fingerprint (USE_FINGERPRINT)
view Wi-Fi status (ACCESS_WIFI_STATE)
full Internet access (INTERNET)
bluetooth administration (BLUETOOTH_ADMIN)
change network connectivity (CHANGE_NETWORK_STATE)
create Bluetooth connections (BLUETOOTH)
C2DM permissions (RECEIVE)
update component usage statistics (PACKAGE_USAGE_STATS)
Gathering data
Result
Malware family:
n/a
Score:
  6/10
Tags:
android
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:telebot_framework
Author:vietdx.mb
Rule name:test_Malaysia
Author:rectifyq
Description:Detects file containing malaysia string

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments