IOC Radar
SHA256MediumSignal 51/100

48590b786b95a58669d11df6bf1bd3618c41c626b664998a398b5fbca4f47cb7

First Seen
Apr 16, 2026
Last Seen
Apr 23, 2026
Apr 16
First Seen
59d ago
Apr 23
Last Seen
52d ago
3
Reports
source reports
51%
Confidence
medium
Found in 3 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
SHA-256 Hash
SHA-256 file hash — primary identifier for malware samples.
MISP Category
Artifacts Dropped
Hash Algorithm
SHA256
Confidence
51%
Signal Score
51 / 100
IDS Rule
No
Threat Context
Tags

Feed Intelligence Summary

3 reports51% confidence
3
Source reports
51%
Confidence score
Category tags
access networkandroidapkapk packageaxmlclear filtersdetail infoexecutable fileexecute systemfile-hashhabo analysisindicatorload websiteminimum systemmobilemobile threatresearchedsystem sha256wifiwindows sandbox

Activity Timeline

1 total obs
Apr 23Apr 23

Threat Activity Heatmap

· Peak: 2026-04-23
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

This SHA-256 hash (48590b786b95a58669d11df6bf1bd3618c41c626b664998a398b5fbca4f47cb7) represents a critical Indicator of Compromise, signaling potential malicious executable code within an organization's environment. Its elevated threat score of 51.36, coupled with its appearance across multiple reputable threat intelligence feeds such as AlienVault OTX, SOCRadar Threat Exchange, and ThreatHose, underscores its widely recognized malicious nature. The presence of this IOC suggests a high probabili…

Threat ScoreMedium Risk
51
SIGNAL
Signal Score
51%
Confidence
3
Reports
First seenApr 16, 2026
Last seenApr 23, 2026

VirusTotal

Not checked

WHOIS

description
DBase 3 data file (624 records)
references
https://vtbehaviour.commondatastorage.googleapis.com/001379b9df220b47424d8fdcfe0d5acd95552378e725c6ead215582f765d71e6_VirusTotal%20R2DBox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776311623&Signature=yg%2FmHy%2FlyPZky1AHIylcq6mVVBvujhakbICkE8BC9i1BxyxeKqyEWFLlGGDlLrmKJxsJWw0dLpYAqWXwvokHnRH6iS4xC5tPVG4KYc%2BVqRMM%2B3WTOvaortPnFETHYrjC61BMkx%2FhSbYBQJ6brOvBOBa6vRGN9iaO7bWRt5vwZ%2BhsnJ5BDQWrx1n2HWMpN91UhoRVbO6NEpO0czcQYot5cxAsKkyffOqC3nctzOX%2F91b, https://vtbehaviour.commondatastorage.googleapis.com/001379b9df220b47424d8fdcfe0d5acd95552378e725c6ead215582f765d71e6_VirusTotal%20R2DBox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776311668&Signature=cLxTWVLzu7CvOhrT2ISmeOKnLgCM6aDuVFIMND%2BHcXAp7UhVungTAjGV7NyYoWGljSA1NiRha0qnttegiSlOTpsJwdEm9gWNDHWiaqqYI7kbD72i23y2cWfl69vYUek4bVhnBqHK77YoG9SFS%2FELSSK74dtD%2FtHSbr9zr5WjA510LevBkHucK%2BcSOxWg4xwWQ6D69xbnVuxIV1stJQXQGKd32lvHzdO75GnNpg7JTnyRcWnTq, https://vtbehaviour.commondatastorage.googleapis.com/001379b9df220b47424d8fdcfe0d5acd95552378e725c6ead215582f765d71e6_Tencent%20HABO.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776311690&Signature=RuBOWgvmJeJm%2FbeeX%2B0jMezX3Pd5kcWMMOmXtvWmzsLOkzdVFbECMQtVjWA44GGXfdE2wts%2BOVWeG%2BXZTCQYNiyWlkg%2FRtB4hLbiGwezAuxuFVlRidButnuxL1bIE3ub%2F1eIoudrt2Nl0kYXsOsaoTpnQNDJ%2FlcKiUByZ88VaoW4JLrwCqAQkBTqpjnJTq8IxgApNbvLNRWIq5WWtqiEu89M849sULPqV1tNDMcFu9LjqitK

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 month ago · Last seen 1 month ago
Appeared in 3 threat reports