MALICIOUS — 081_AndroRat_6Dec2013.bin
MALICIOUS — 081_AndroRat_6Dec2013.bin is a apk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Androrat family. 4 of 50 detection engines flagged it.
Identification
- SHA-256:
1af93c9fafdd21a33d647a79d1c36f5591432cb005edb3070768ddb1f333345a - SHA-1:
5a5f60a560ec52228224fd255e337f4a0fdead2f - MD5:
7329eb13bf323b40a354df1c0b2b43b2 - ssdeep:
1536:JMJ3HajfKWKIug/ynS2MVPfbpx80vJ3lbXqIlyDAS:JMp6jfXKxCynw9xfhVzf0DAS - TLSH:
T1FB36F1D6E9E5F5ECCCC88F945A26B9AC6E3224F51073049727346B904CD89BBD83025A - Submitted as: 081_AndroRat_6Dec2013.bin
- File type: apk · Size: 66739 bytes
- Verdict: malicious (98/100) · Family: Androrat
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Andr.Trojan.Androrat-1
- androguard (APK/DEX analysis): androguard:9 dangerous permissions
- Microsoft Defender: MonitoringTool:AndroidOS/AndroRat
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Andr.Trojan.Androrat-1 (rule
Andr.Trojan.Androrat-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged MonitoringTool:AndroidOS/AndroRat (rule
MonitoringTool:AndroidOS/AndroRat) - engine signal, weight 0.55, confidence 0.85 - APK requests 9 dangerous permissions: android.permission.RECEIVE_SMS, android.permission.READ_SMS, android.permission.SEND_SMS, android.permission.READ_PHONE_STATE, android.permission.ACCESS_FINE_LOCATION - static signal, weight 0.50, confidence 0.70
- Contacted 0 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- androguard (APK/DEX analysis) flagged androguard:9 dangerous permissions (rule
androguard:9 dangerous permissions) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (android)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- http://connectivitycheck.gstatic.com/generate_204
- https://android.googlesource.com/toolchain/llvm-project
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
Embedded URLs
- http://connectivitycheck.gstatic.com/generate_204
- https://android.googlesource.com/toolchain/llvm-project
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
More Androrat samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report