MALICIOUS — 25e6a6bac0859c785063eed88c04cfbb1c30613c9b549d846d43d1920db172e9.apk
MALICIOUS — 25e6a6bac0859c785063eed88c04cfbb1c30613c9b549d846d43d1920db172e9.apk is a apk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (85/100), attributed to the AndroidOS family. 3 of 25 detection engines flagged it.
Identification
- SHA-256:
25e6a6bac0859c785063eed88c04cfbb1c30613c9b549d846d43d1920db172e9 - SHA-1:
0001da6a2b92bef1607d7bdb6f471198a7c08e20 - MD5:
c2965b1f7a94860a2f982d202f7f6d58 - ssdeep:
196608:OjrSDM1sFO92upDjg1wWwPLCLH+QN4ut1eMSk9QObbmlfMHOchwnNVKQY9Wu3KB5:iD1592uy1xwPmLH+luHeFOQObiZIpwN9 - TLSH:
T1DE6B33EE1BB4D158D6F8CE75BC05A18D0E40258A412E29FDD31E1A3FA57718F847322A - Submitted as: 25e6a6bac0859c785063eed88c04cfbb1c30613c9b549d846d43d1920db172e9.apk
- File type: apk · Size: 10353470 bytes
- Verdict: malicious (85/100) · Family: AndroidOS
Detections (3 of 25 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- androguard (APK/DEX analysis): androguard:5 dangerous permissions
- Kaspersky (KVRT): HEUR:Trojan-Banker.AndroidOS.Banbra.as
Why this verdict
The malicious score of 85/100 is the fusion of 6 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Trojan-Banker.AndroidOS.Banbra.as (rule
HEUR:Trojan-Banker.AndroidOS.Banbra.as) - engine signal, weight 0.55, confidence 0.85 - Contacted 0 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- androguard (APK/DEX analysis) flagged androguard:5 dangerous permissions (rule
androguard:5 dangerous permissions) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://schemas.android.com/apk/res/android - static signal, weight 0.35, confidence 0.60
- APK is not signed (v1 JAR signature absent) - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (android)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- http://connectivitycheck.gstatic.com/generate_204
- https://android.googlesource.com/toolchain/llvm-project
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
Embedded URLs
- https://github.com/REAndroid/APKEditor
- http://schemas.android.com/apk/res/android
- https://github.com/REAndroid/ARSCLib
- http://connectivitycheck.gstatic.com/generate_204
- https://android.googlesource.com/toolchain/llvm-project
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
Embedded domains
- github.com
- 8i.gq
- c5ra.tv
- l.ly
- 8c.ru
- schemas.android.com
File paths
- Z:\/q
- A:\3$
- B:\)i
- L:\!G
- l:\gO
- K:\y
More AndroidOS samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report