🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cf869324cbadaa2bc186f2d1d1bda3718329c1000e60e22a29a3a1f207c465ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: cf869324cbadaa2bc186f2d1d1bda3718329c1000e60e22a29a3a1f207c465ae
SHA3-384 hash: f25bc7b6327afc951ff04c38e08c5c7d9b6bfde04d550f6ed7483d7c18ce842d5fdcd137cf8675e91838843ac8b50bbb
SHA1 hash: f296c5b197d2725b5d006f35484aa3a2a2767551
MD5 hash: faa7e4d034c37796ab9175dfb8f942ef
humanhash: bluebird-ten-sodium-speaker
File name:cf869324cbadaa2bc186f2d1d1bda3718329c1000e60e22a29a3a1f207c465ae.bin
Download: download sample
File size:1'165'966 bytes
First seen:2026-09-25 06:30:13 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 24576:oqJ+yxHvTvHvTTXHvT95ZyI6Z9IWez0pmsGEH7nABCQyz99:LJ+yxHvDHvXXHvnZyIwUwpJGo7ApU9
TLSH T154452367EB90A824CC6EC17642B74B877634C3209962979F562AD1F83CC96F387837C5
TrID 87.0% (.APK) Android Package (27000/1/5)
12.9% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter whack_sh
Tags:apk zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade signed
Threat name:
Android.Trojan.Locker
Status:
Suspicious
First seen:
2026-09-25 06:58:34 UTC
File Type:
Binary (Archive)
Extracted files:
61
AV detection:
9 of 35 (25.71%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
android defense_evasion evasion execution persistence
Behaviour
Schedules tasks to execute at a specified time
Acquires the wake lock
Makes use of the framework's foreground persistence service
Loads dropped Dex/Jar
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

apk cf869324cbadaa2bc186f2d1d1bda3718329c1000e60e22a29a3a1f207c465ae

(this sample)

  
Delivery method
Distributed via web download

Comments