MALICIOUS — app.apk
MALICIOUS — app.apk is a apk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100), attributed to the AndroidOS family. 2 of 25 detection engines flagged it.
Identification
- SHA-256:
104447278779517e2b397a18d501685ae61a9da84abe1c180ff9bb67a5a0f0fc - SHA-1:
591a2df183f3e377b81a50d5ef70224bb01fc0a5 - MD5:
6495be64978a1008d12e2cb6e2871f26 - ssdeep:
393216:hE+LTRu+ztXojVddxHkyo00/I+ZNG0aOkRsIE:hEugEojrdxHkMjdvCIE - TLSH:
T1C07012CA17396410CAF963E3B9A1D85EB6E31D1F103464DD12E0D233B5EC62B55322AE - Submitted as: app.apk
- File type: apk · Size: 16469857 bytes
- Verdict: malicious (75/100) · Family: AndroidOS
Detections (2 of 25 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): HEUR:Trojan-Dropper.AndroidOS.Banker.eg
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Trojan-Dropper.AndroidOS.Banker.eg (rule
HEUR:Trojan-Dropper.AndroidOS.Banker.eg) - engine signal, weight 0.55, confidence 0.85 - Contacted 0 external host(s) at runtime (17 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://schemas.android.com/apk/res-auto, http://schemas.android.com/apk/res/android - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (android)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- http://connectivitycheck.gstatic.com/generate_204
- https://amazon.com
- https://android.googleapis.com/checkin
- https://android.googlesource.com/toolchain/llvm-project
- https://cloudflare.f-droid.org
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://f-droid.org
- https://fdroid.link
- https://play.google.com
- https://staging.f-droid.org
- https://www.amazon.com
- https://www.f-droid.org
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
Embedded URLs
- http://schemas.android.com/apk/res-auto
- http://schemas.android.com/apk/res/android
- https://github.com/REAndroid/ARSCLib
- http://connectivitycheck.gstatic.com/generate_204
- https://amazon.com
- https://android.googleapis.com/checkin
- https://android.googlesource.com/toolchain/llvm-project
- https://cloudflare.f-droid.org
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://f-droid.org
- https://fdroid.link
- https://play.google.com
- https://staging.f-droid.org
- https://www.amazon.com
- https://www.f-droid.org
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
Embedded domains
- e.fi
- i.nl
- f.sh
- 60.su
- 6androidx.appcompat.app
- schemas.android.com
- github.com
File paths
- w:\h
- z:\Q8NC
- E:\xJ
- y:\VpN
- a:\^F
More AndroidOS samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report