MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc57e487bbddc0c26eccb758c92843e935a329cd706bbaa24537726f45a0de5d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cc57e487bbddc0c26eccb758c92843e935a329cd706bbaa24537726f45a0de5d
SHA3-384 hash: 6cc1e5476c497e05dffe1ed56ce88b5d67505b8e1fbcb9bbbeaa8250bc6325f2d6b747ee1d399d7b04d29078c61cc185
SHA1 hash: cdb5487f8b90269d9af8c2089a7cb6d6ff71fabd
MD5 hash: 2fff2e2a3f65c14acab1a0a977dca29e
humanhash: nineteen-apart-kilo-arkansas
File name:Norton Identity 1.86.apk.zip
Download: download sample
File size:91'306'537 bytes
First seen:2026-08-15 22:00:55 UTC
Last seen:2026-08-17 17:24:16 UTC
File type: zip
MIME type:application/zip
ssdeep 1572864:lnip9aCDktMFPiL11C4zrR6TMjncqOLKYPjJxKbSBmegMNb8H8ur4D:li19kx1XrAcncvLXxDwnMNwT8D
TLSH T126183326D1016E2FBDF69FE25C42848C1BF0D0B6B55992503AE800D75DC2B2FB6AE4D7
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika zip
Reporter Anonymous
Tags:zip


Avatar
Anonymous
https://otx.alienvault.com/pulse/6a7aa707929c9377594dd171

Part of https://otx.alienvault.com/group/2096/pulses
OTX 2096

cc57e487bbddc0c26eccb758c92843e935a329cd706bbaa24537726f45a0de5d
Norton Identity 1.86.apk.zip

Sample from Google Pixel on Telus ISP (Official Google Play Store) & Protected by Norton

Intelligence


File Origin
# of uploads :
2
# of downloads :
120
Origin country :
CA CA
Vendor Threat Intelligence
No detections
Result
Verdict:
Clean
File Type:
ZIP File - Malicious
Behaviour
SuspiciousEmbeddedObjects detected
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
crypto evasive fingerprint persistence signed
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments