🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc111dbe181ecf60242886d28c8360d630913919feee4d37d0bc7b675c2f6566. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: dc111dbe181ecf60242886d28c8360d630913919feee4d37d0bc7b675c2f6566
SHA3-384 hash: 0051b4e5c703930e287d4e8868e32e462a7c430940c8f9f4b97275d2a02361310a8a1152212a20fe3e884094b5ece9fc
SHA1 hash: 0c8d4f151fbbaaf5bbf52f5c308979e33d74f1ff
MD5 hash: 9e189f4cc131035418b10ecc98b8db26
humanhash: sink-triple-venus-ack
File name:PlutoniumPREMIUM_0.37.1.apk
Download: download sample
File size:3'326'989 bytes
First seen:2026-04-05 12:53:43 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 98304:A1aWlm1s4h7EJWs61Vida9ZQHWDhVRrmdBe:Yah1s8EJWs61Vi0w2dVpWU
TLSH T110F51252E7A8A45EECFF96354B770A6841038E6B8713D3838D75723C2D7B9C09A61EC4
TrID 65.0% (.APK) Android Package (27000/1/5)
25.3% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
9.6% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter BastianHein
Tags:apk

Intelligence


File Origin
# of uploads :
1
# of downloads :
171
Origin country :
CL CL
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
invalid-signature signed soft-404
Result
Application Permissions
receive SMS (RECEIVE_SMS)
read SMS or MMS (READ_SMS)
send SMS messages (SEND_SMS)
read phone state and identity (READ_PHONE_STATE)
full Internet access (INTERNET)
automatically start at boot (RECEIVE_BOOT_COMPLETED)
view network status (ACCESS_NETWORK_STATE)
prevent phone from sleeping (WAKE_LOCK)
Verdict:
Clean
File Type:
apk
First seen:
2026-04-05T11:48:00Z UTC
Last seen:
2026-04-05T11:52:00Z UTC
Hits:
~10
Threat name:
Android.PUA.Generic
Status:
Suspicious
First seen:
2026-04-04 23:19:48 UTC
File Type:
Binary (Archive)
Extracted files:
354
AV detection:
5 of 24 (20.83%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
android collection credential_access defense_evasion discovery evasion impact persistence
Behaviour
Checks CPU information
Checks memory information
Registers a broadcast receiver at runtime (usually for listening for system events)
Uses Crypto APIs (Might try to encrypt user data)
Acquires the wake lock
Makes use of the framework's foreground persistence service
Queries the mobile country code (MCC)
Requests changing the default SMS application.
Loads dropped Dex/Jar
Obtains sensitive information copied to the device clipboard
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments