🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d04797a0ebd841da1f875a30ef19a9ae700c4d713ec6b57cc885601adee51b03. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: d04797a0ebd841da1f875a30ef19a9ae700c4d713ec6b57cc885601adee51b03
SHA3-384 hash: 25fc098a61116f4a353d50b6c351f6abc13a23fbc806a66c0e3af14fd5ab7385a2fe5c7326b29929025231a3243a879f
SHA1 hash: dd6458a3211bb202265ea1d33d9a787735061301
MD5 hash: 3274be89e0afefecaad9929765f0c56e
humanhash: arizona-alaska-kilo-berlin
File name:Telegram1.apk
Download: download sample
File size:77'537'538 bytes
First seen:2026-04-26 08:31:31 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 1572864:VowDl2UI0PSYD96txURn8gOX5KNkFVvci1jbCU0AUqa1dAt:VoJUI0P16txrPX5KNkFVx0tdC
TLSH T1460823EBB301FD38D1B3463297469561FD284E21DB12E10B6408F72DAEB36D045EA7E9
TrID 87.0% (.APK) Android Package (27000/1/5)
12.9% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter Bluebird
Tags:apk

Intelligence


File Origin
# of uploads :
1
# of downloads :
185
Origin country :
n/a
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive fingerprint invalid-signature persistence signed
Result
Application Permissions
read the user's personal profile data (READ_PROFILE)
coarse (network-based) location (ACCESS_COARSE_LOCATION)
fine (GPS) location (ACCESS_FINE_LOCATION)
access any geographic locations (ACCESS_MEDIA_LOCATION)
directly call phone numbers (CALL_PHONE)
read/modify/delete external storage contents (WRITE_EXTERNAL_STORAGE)
record audio (RECORD_AUDIO)
modify global system settings (WRITE_SETTINGS)
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
take pictures and videos (CAMERA)
read phone state and identity (READ_PHONE_STATE)
read external storage contents (READ_EXTERNAL_STORAGE)
list accounts (GET_ACCOUNTS)
read contact data (READ_CONTACTS)
write contact data (WRITE_CONTACTS)
manage the accounts list (MANAGE_ACCOUNTS)
access location in background (ACCESS_BACKGROUND_LOCATION)
display system-level alerts (SYSTEM_ALERT_WINDOW)
act as an account authenticator (AUTHENTICATE_ACCOUNTS)
read sync settings (READ_SYNC_SETTINGS)
control vibrator (VIBRATE)
write sync settings (WRITE_SYNC_SETTINGS)
prevent phone from sleeping (WAKE_LOCK)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
allow use of fingerprint (USE_FINGERPRINT)
view Wi-Fi status (ACCESS_WIFI_STATE)
create Bluetooth connections (BLUETOOTH)
view network status (ACCESS_NETWORK_STATE)
change your audio settings (MODIFY_AUDIO_SETTINGS)
show app notification (READ_APP_BADGE)
full Internet access (INTERNET)
C2DM permissions (RECEIVE)
Verdict:
Malicious
File Type:
apk
First seen:
2026-04-26T05:20:00Z UTC
Last seen:
2026-04-27T22:56:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Spy.AndroidOS.Agent.aeo
Gathering data
Verdict:
Malicious
Threat:
Trojan-Spy.AndroidOS.Agent
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments