🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e46d5e3237a7b339440dd7f005be4b77be4584749816bf64b0b3485e00862fd0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 14 File information Comments

SHA256 hash: e46d5e3237a7b339440dd7f005be4b77be4584749816bf64b0b3485e00862fd0
SHA3-384 hash: 70056dbd03a6cba1674f722f7f6ab3ee0de644f66c1d5c79a007054b0c63b7da4c7606cd05728af51c42aacbd320627e
SHA1 hash: 7773122eaba614465e4581de8867b8de36e4d751
MD5 hash: b68a1627a100bbfa82dc1fa53cda9874
humanhash: zulu-utah-hot-juliet
File name:e46d5e3237a7b339440dd7f005be4b77be4584749816bf64b0b3485e00862fd0.raw
Download: download sample
File size:460'653 bytes
First seen:2026-08-31 03:42:42 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:xI7NTOZ2/iqKpbsLG8YiPk+BeHsvdrvkRGOohjmjR4Rs6rnAbDpAwL7yKMZmIT:xUNLKpkG8dPkrIb4VjRwDA1TM4IT
TLSH T1E5A423A77A5C226BF37F973215DFDB39058D8D9B8A005A1F14A2CA29E9C713A0331DC5
TrID 77.1% (.JAR) Java Archive (13500/1/2)
22.8% (.ZIP) ZIP compressed archive (4000/1)
Magika apk
Reporter likeabosh
Tags:cowrie dionaea honeypot signed zip

Code Signing Certificate

Organisation:Android
Issuer:Android
Algorithm:sha1WithRSAEncryption
Valid from:2008-02-29T01:33:46Z
Valid to:2035-07-17T01:33:46Z
Serial number: 936eacbe07f201df
Intelligence: 1866 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
US US
File Archive Information

This file archive contains 17 file(s), sorted by their relevance:

File name:ANDROID.RSA
File size:1'714 bytes
SHA256 hash: 891f4cae3777571d1b5468f21fb25f6a47f2ffecb20504a2bf6b0139fda4a21b
MD5 hash: 6170e607c4269bb83a9ee0d719086403
MIME type:application/octet-stream
File name:classes2.dex
File size:45'624 bytes
SHA256 hash: da668cd4bc96b67d053e08137a0da24c944cca8f93caeba5ce021f1ed4fe6cea
MD5 hash: 7cd0fd30f38d3531a63ca101f7c26492
MIME type:application/octet-stream
File name:accessibility_service_config.xml
File size:552 bytes
SHA256 hash: ed82b5d0952bafdeeebb2d6d710e3e0a7965a7f965bd1af1ebb246c3042e5ff7
MD5 hash: 94f0607f495f2e7a4170d1c3b7aef22b
MIME type:application/octet-stream
File name:classes.dex
File size:41'596 bytes
SHA256 hash: ccc9dacfa8e9836230099580e60fe5108719f39aff45314d325e7946b60e9757
MD5 hash: 05c8f48af774f3b0fd182c67bca0337f
MIME type:application/octet-stream
File name:trust_agent.xml
File size:432 bytes
SHA256 hash: cb96e5a04f9485ac7940d4a8ed7c6efd863435c0fd491510d8884873ead2a76b
MD5 hash: 4fc53eef7d7035b2f35697aae17cb359
MIME type:application/octet-stream
File name:device_admin.xml
File size:1'048 bytes
SHA256 hash: 6e2337b9394d2c43b4c8736d389c00926f5b7e97cbe1e2cca59c073f0dbbf1e3
MD5 hash: c0676b13b493f9fad40795fc9312b096
MIME type:application/octet-stream
File name:resources.arsc
File size:2'704 bytes
SHA256 hash: 7cd2c8d80450f44693bf855cb24b2cd890de909eff2780b96741877822e92331
MD5 hash: 1a4fffd9611da80cfba772edddc9e2bd
MIME type:application/octet-stream
File name:method.xml
File size:356 bytes
SHA256 hash: ba69e67b9fa5c1db04352e12b2f0650bb38c0b010ab8fa061f3b5d766d1f93e2
MD5 hash: 5913a25de96dafe97687e9ef0b8b3962
MIME type:application/octet-stream
File name:libbot.so
File size:101'096 bytes
SHA256 hash: cf3a2657c94d50d00f96dd8d864690f68a027188e76207c263134f8e7460da00
MD5 hash: f68c765909302f64fceb74083c36c280
MIME type:application/x-executable
File name:AndroidManifest.xml
File size:13'960 bytes
SHA256 hash: ba6b76a80c258c150453bab934de076985e637f89016382bcb1df412b5ef3c8b
MD5 hash: d22fd78cef9aa19fe89592e17e97ce99
MIME type:application/octet-stream
File name:activity_main.xml
File size:3'432 bytes
SHA256 hash: 4fe8b33bdafd5ca82872e0c5fb9cc0f44f1edcb6beff71872bba89ee4508f2b9
MD5 hash: db4681064b14d862b6523ac07ffc59e3
MIME type:application/octet-stream
File name:network_security_config.xml
File size:468 bytes
SHA256 hash: e258d7a8981dfaf7e8e9a9dd21029c9e59dfe7132dce48339045f7237f6c0786
MD5 hash: 376a45683455207c14aa32119916ec9f
MIME type:application/octet-stream
File name:MANIFEST.MF
File size:1'818 bytes
SHA256 hash: 1358d5b2e0d6dec5cdaa6a13b72356dc78fa75e75903f437411b1b9634c13c4a
MD5 hash: 1bc5eef0b5b3d12a77537a625a5c632e
MIME type:text/plain
File name:app-metadata.properties
File size:56 bytes
SHA256 hash: 4cb06b8e3d74ab903adb1280e77a69a759dff50105be008adb82b67b0d408c1d
MD5 hash: 463fa1f444465a80d6ed1ad535219d0b
MIME type:text/plain
File name:androidx.localbroadcastmanager_localbroadcastmanager.version
File size:6 bytes
SHA256 hash: 1575e1af4a95f12f70b4ee6a6adce8160953d93ea17dc2611b90883ccc3ad3b8
MD5 hash: 30a04cf33ee91a3ecf4b75c71268f316
MIME type:text/plain
File name:ANDROID.SF
File size:1'875 bytes
SHA256 hash: 8b399f624b7070a80c5f458b9a8a2318f9a616e665834eb29587a02b634ecc6c
MD5 hash: 9c52b2b1dc612a7e6e9d880b7bc016c2
MIME type:text/plain
File name:androidsupportmultidexversion.txt
File size:53 bytes
SHA256 hash: 65d5f87198701970237117186049db45ae8e9151ed583f124e6bcb8ea5ba8a16
MD5 hash: dd74c55f4d6a07fbbb888ad194fa5613
MIME type:text/plain
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
apk
First seen:
2026-08-23T15:00:00Z UTC
Last seen:
2026-09-01T18:18:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Elf Executable Executable Zip Archive
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2026-08-23 19:54:32 UTC
File Type:
Binary (Archive)
Extracted files:
24
AV detection:
15 of 36 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
android defense_evasion persistence upx
Behaviour
Acquires the wake lock
Makes use of the framework's foreground persistence service
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:SUSP_ELF_LNX_UPX_Compressed_File
Author:Florian Roth (Nextron Systems)
Description:Detects a suspicious ELF binary with UPX compression
Reference:Internal Research
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments