28c11bb998bf8c023a212c6518b4f8219c8583c2e79fc87d76be6fcad51b522f.apk
Classification: Malicious
28c11bb998bf8c023a212c6518b4f8219c8583c2e79fc87d76be6fcad51b522f.apk is a malicious file sample. Linked to Anubis malware. Detected by 30 antivirus engines.
Detection summary
- 30 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: ANUBIS (S0422)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Flubot | Triage | 2026-08-13 01:08:01 | 2026-08-13 01:08:01 | malicious-activity | |
| Generic.Malware | Abuse.ch | 2021-05-05 10:24:17 | 2021-05-05 10:24:17 | malicious-activity | |
| Anubis | Abuse.ch | 2021-05-05 10:24:17 | 2021-05-05 10:24:17 | malicious-activity | S0422 Anubis |
Tags
flubot android banker c2 collection credential_access defense_evasion discovery dropper evasion exfiltration impact infostealer loader obfuscated otp overlay persistence rat sms spyware stealer suspicious trojanSample information
- Filenames
- 28c11bb998bf8c023a212c6518b4f8219c8583c2e79fc87d76be6fcad51b522f.apk, UPS943.apk
- File type
- application/java-archive
- MD5
92891906b5842b1daac01661731116b9- SHA-1
53ff2b0a928fda3439d188c9b7d2f989f7e93eec- SHA-256
28c11bb998bf8c023a212c6518b4f8219c8583c2e79fc87d76be6fcad51b522f- First indexed
- 2021-05-05 12:15:04
- Last updated
- 2026-08-13 02:00:12
Antivirus detections
| Engine | Detection |
|---|---|
| AhnLab-V3 | Trojan/Android.Banker.1177328 |
| Alibaba | Backdoor:Android/Polph.47e5ea25 |
| Antiy-AVL | Trojan/Generic.ASMalwAD.37 |
| Avast-Mobile | Android:Evo-gen [Trj] |
| Avira | ANDROID/Hqwar.FJTU.Gen |
| BitDefenderFalx | Android.Trojan.Banker.WA |
| CAT-QuickHeal | Android.ScytheSCF.BZ |
| Cynet | Malicious (score: 99) |
| DrWeb | Android.BankBot.9434 |
| ESET-NOD32 | a variant of Android/TrojanDropper.Agent.HZA |
| F-Secure | Malware.ANDROID/Hqwar.FJTU.Gen |
| Fortinet | Android/Bankbot.6439!tr |
| Detected | |
| Gridinsoft | Trojan.U.Banker.oa |
| Ikarus | Trojan-Banker.AndroidOS.Hydra |
| Jiangmin | AdWare.Script.ia |
| K7GW | Trojan ( 0057c0dd1 ) |
| Kaspersky | HEUR:Backdoor.AndroidOS.Polph.c |
| Lionic | Trojan.AndroidOS.Polph.m!c |
| McAfee | Artemis!6B86E3701D41 |
| Microsoft | TrojanDropper:AndroidOS/Banker.D!MTB |
| NANO-Antivirus | Trojan.Android.Polph.jepwsf |
| Sophos | Andr/Banker-GZW |
| Symantec | Trojan.Gen.2 |
| SymantecMobileInsight | AppRisk:Generisk |
| Tencent | a.privacy.BankAnubisTrojan |
| Trustlook | Android.Malware.Trojan |
| Varist | AndroidOS/Banker.BA.gen!Eldorado |
| Xcitium | Malware@#1ucpksnv464gx |
| ZoneAlarm | HEUR:Backdoor.AndroidOS.Polph.c |