🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 decf0f2e6d42f5da6ef5f77954115e5cbbb8d68edab7151cf34d28a6d49cb9f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BankBot


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: decf0f2e6d42f5da6ef5f77954115e5cbbb8d68edab7151cf34d28a6d49cb9f8
SHA3-384 hash: 7ec4bb3919675673e125a9e31a6abb5cc3ae553c7948c58fc2bd608a57481580cfb549a00b38da0688a9897332dee84d
SHA1 hash: 9041e09bd753ecd395ba25666097e61c27b98747
MD5 hash: db85a7d154e9967625c3e43d950b81f8
humanhash: december-gee-enemy-echo
File name:Mp3.indir.apk
Download: download sample
Signature BankBot
File size:5'053'600 bytes
First seen:2026-02-25 13:30:55 UTC
Last seen:Never
File type: apk
MIME type:application/zip
ssdeep 98304:t309Q1H+YGB8tuuvt0vvoslHBThJUeDbVV0R3ZRdwzfrEPIjSuyTDf4G:poTzuvqvv5FjJTD5V0RzXrPfR
TLSH T15436F046FB56AA7BC4F7433246769266613BCC668B83D6871C1C323C09B75D80F5AEC8
TrID 40.0% (.APK) Android Package (27000/1/5)
20.0% (.JAR) Java Archive (13500/1/2)
18.5% (.VYM) VYM Mind Map (12500/1/3)
15.5% (.SH3D) Sweet Home 3D Design (generic) (10500/1/3)
5.9% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter CyberMAN_noBODY
Tags:apk BankBot banker dropper signed

Code Signing Certificate

Organisation:Kasoft Technology
Issuer:Kasoft Technology
Algorithm:sha256WithRSAEncryption
Valid from:2022-07-12T19:06:37Z
Valid to:2047-07-06T19:06:37Z
Serial number: 0f0f0271
Intelligence: 2 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 1d8e0657e7f6386d516ad1c97479aebc4235c014d26c5f549bcdceabdc3b2374
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
311
Origin country :
TR TR
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
android bankbot base64 crypto evasive expand fingerprint lolbin signed
Result
Application Permissions
full Internet access (INTERNET)
prevent phone from sleeping (WAKE_LOCK)
Verdict:
Malicious
File Type:
apk
First seen:
2023-08-31T14:03:00Z UTC
Last seen:
2023-08-31T18:45:00Z UTC
Hits:
~10
Threat name:
Android.Infostealer.Anubis
Status:
Malicious
First seen:
2023-08-31 21:10:04 UTC
File Type:
Binary (Archive)
Extracted files:
617
AV detection:
10 of 36 (27.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
android collection credential_access defense_evasion impact persistence
Behaviour
Uses Crypto APIs (Might try to encrypt user data)
Acquires the wake lock
Makes use of the framework's foreground persistence service
Makes use of the framework's Accessibility service
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments