MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ddeb13abf09d096f821ee657c3479f799f2a236b49f46c80a0afb2676a8f55ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



FantasyHub


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ddeb13abf09d096f821ee657c3479f799f2a236b49f46c80a0afb2676a8f55ab
SHA3-384 hash: 2364d5ef1dae8c2d0ef59800c2b96bdfc5bd027513732a9ec171bab96fb46f7bb43fddfb0f608963ec7db41df86cb052
SHA1 hash: ab08fb72da9ffdb8a95de0fbf4320a9216bfd266
MD5 hash: 5541daf958a603061908b3431b0b8f1b
humanhash: maryland-freddie-paris-september
File name:TikTok18.apk
Download: download sample
Signature FantasyHub
File size:8'956'681 bytes
First seen:2026-01-16 12:30:55 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 196608:v6FWN5VgwBJpL9HX4TG/3tqedmMZkblRFblI0GJVvzge:vBMaJTH1qedrZkbldI0GJVL
TLSH T18F963381F711581EC9B792370E9B973647269E2A8EA697036490373DBCB76C18F18FC4
TrID 49.0% (.APK) Android Package (27000/1/5)
24.5% (.JAR) Java Archive (13500/1/2)
19.0% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
7.2% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter juroots
Tags:apk FantasyHub signed

Code Signing Certificate

Organisation:main_app
Issuer:main_app
Algorithm:sha384WithRSAEncryption
Valid from:2026-01-16T06:48:55Z
Valid to:2080-10-19T06:48:55Z
Serial number: 8eb9aff7d8a75df7
Thumbprint Algorithm:SHA256
Thumbprint: f2a1368687473fa36b2967b282f15a56b3089f4be33f74f702c448db0137f75b
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
signed
Result
Application Permissions
Allows an application to request installing packages. (REQUEST_INSTALL_PACKAGES)
full Internet access (INTERNET)
view network status (ACCESS_NETWORK_STATE)
prevent phone from sleeping (WAKE_LOCK)
Result
Malware family:
fantasyhub
Score:
  10/10
Tags:
family:fantasyhub
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

FantasyHub

apk ddeb13abf09d096f821ee657c3479f799f2a236b49f46c80a0afb2676a8f55ab

(this sample)

  
Delivery method
Distributed via web download

Comments