MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cf905c53cf59462cb955095f57790f8f9d660286308a8055ce085d52742ca824. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: cf905c53cf59462cb955095f57790f8f9d660286308a8055ce085d52742ca824
SHA3-384 hash: 56619fedd4415bc36a551dcc444f3182fb5c7b333be9cdfa08fad386f747359bb5a7ee2d7dc2d5e323b67758194afa63
SHA1 hash: a584166a3b02a22bb71b964e3fb65350f70859ca
MD5 hash: c401099a9b033798c2cf160d51d29cb6
humanhash: paris-berlin-bacon-butter
File name:download.apk
Download: download sample
File size:1'820'775 bytes
First seen:2025-11-22 10:59:45 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 49152:RObPfFFDjdvfg2A2ec+aeb2dFyK7xlvJ0vxxbhuadYma4:RObPHJvjkaebsPHN+
TLSH T14A85F142F3E5AC2FCDB741360FBA4B7A05864D468686D3178565B12C9DBBEC48E82FC4
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter juroots
Tags:apk signed

Code Signing Certificate

Organisation:Android Debug
Issuer:Android Debug
Algorithm:sha1WithRSAEncryption
Valid from:2022-08-25T04:37:12Z
Valid to:2052-08-17T04:37:12Z
Serial number: 01
Intelligence: 371 malware samples on MalwareBazaar are signed with this code signing certificate
Cert Central Blocklist:This certificate is on the Cert Central blocklist
Thumbprint Algorithm:SHA256
Thumbprint: 18cc1699436060ed8b698be77c56276177b4ce1f3d6c97c79bce8eab03955c3f
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
RO RO
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
base64 evasive signed
Result
Application Permissions
full Internet access (INTERNET)
Verdict:
Unknown
File Type:
apk
First seen:
2024-04-01T14:19:00Z UTC
Last seen:
2025-11-23T01:40:00Z UTC
Hits:
~100
Result
Malware family:
n/a
Score:
  7/10
Tags:
android collection credential_access discovery impact persistence
Behaviour
Checks CPU information
Checks memory information
Registers a broadcast receiver at runtime (usually for listening for system events)
Queries the mobile country code (MCC)
Obtains sensitive information copied to the device clipboard
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

apk cf905c53cf59462cb955095f57790f8f9d660286308a8055ce085d52742ca824

(this sample)

  
Delivery method
Distributed via web download

Comments