SUSPICIOUS — 2bffaf6d0e1be71d15cde5f81beb4c44c5b95f0b89f0730f8b89c6845c111dcd
SUSPICIOUS — 2bffaf6d0e1be71d15cde5f81beb4c44c5b95f0b89f0730f8b89c6845c111dcd is a apk sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (67/100). 1 of 54 detection engines flagged it.
Identification
- SHA-256:
2bffaf6d0e1be71d15cde5f81beb4c44c5b95f0b89f0730f8b89c6845c111dcd - SHA-1:
42367cd811c894298203a19d6f1ddfb844b39d71 - MD5:
cd648faea880a789752b4b550c812646 - ssdeep:
786432:RHFuJ2olMvfYCyE7QvwjYEkOVCsgthz63W:5FcliAE8P/OZgtp - TLSH:
T1D97533DC389DF09ACCD13724B164605D6DBD70A4C8B8A7A2D2442BB6B0F86373975932 - Submitted as: 2bffaf6d0e1be71d15cde5f81beb4c44c5b95f0b89f0730f8b89c6845c111dcd
- File type: apk · Size: 26460047 bytes
- Verdict: suspicious (67/100)
Detections (1 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
Why this verdict
The suspicious score of 67/100 is the fusion of 4 weighted signals:
- APK requests 8 dangerous permissions: android.permission.ACCESS_COARSE_LOCATION, android.permission.ACCESS_FINE_LOCATION, android.permission.CAMERA, android.permission.READ_CONTACTS, android.permission.READ_PHONE_STATE - static signal, weight 0.50, confidence 0.70
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.iec.ch, http://purl.org/dc/elements/1.1/ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (15 executables)
This apk carries 15 extracted members, each analyzed as its own sample (listing truncated):
- WebViewJavascriptBridge.js -
e2dce4bd72f820f5a00c1903f19709998b5807f80f7304591f487733a8e404d8 - gdtadv2.jar -
abbda9c3353d88c4de9df8880b962fe7958c610cbf54e3e57568af80cd504711 - compose1.js -
70e555ad275425be9daa38c9bf2a99d85d03415b0d57f262e4ab343ef6e9b7e6 - inline.js -
e75d57f0eb227eb49ee477f5a348eced1cb19a03a2ace4f5679a0950be45bc83 - jquery.caret.min.js -
38e0dddb3aec82f2607c8b39d196e51586bf7fc16cb7abe5f88c153169ff4b14 - jquery.min.js -
20638e363fcc5152155f24b281303e17da62da62d24ef5dcf863b184d9a25734 - resize.js -
9a8a09e46577f8415ecf884a5b879c233d3bb284bf07eb9a471455439e544e9c - libBugly.so -
e364119ce770351a23877cca141cc12cfa353bdeaac30febd1205d7628ec299f - libJNIEncrypt.so -
2e52c8b427c8136c481fb4425f104028aa01b8ce0d4eb54b367cefd2353c3bff - libjcore125.so -
e4ebdead067959f6d7891bf8010b50252ee38ab261e874f8c5215629da77e04f - libshella-2.9.1.2.so -
0d286a328d7bfeb8263852ed591958b3824393c07b445e2a9016e557969511fe - libsqlcipher.so -
7fb1c2e1205b7b923bb8e8edfc9792416a3dbda306bc9238df56389d57f5007b - libBugly.so -
b12b86b352d771fa19cc95e71472549aefe73867eba73a82e60b992dc0cb86d8 - libJNIEncrypt.so -
80acc13f6626c104cabbd92f376a2cf423e7ef9aee6a8d1434bcb16a225ebfb9 - libjcore125.so -
113806b93cff75ecddd59316149b70b8a907a33d841aa5982dd0d537ef517187
Dynamic analysis
This apk is a container, so it was not detonated itself. Its extracted members were re-submitted and analyzed as their own samples, and the runtime behaviour lives on those reports.
Embedded URLs
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/sType/ResourceRef#
- http://ns.adobe.com/xap/1.0/
- http://www.iec.ch
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
- http://ns.adobe.com/illustrator/1.0/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/photoshop/1.0/
Embedded domains
- www.w3.org
- ns.adobe.com
- c.tv
- t.gq
- 72.gq
- 5.cc
- ml.de
- 7n.ga
- www.iec.ch
- purl.org
- 6.ga
- k.hk
- 5f.uk
File paths
- l:\e/
- H:\c\
- o:\[7
- c:\m(~
- z:\yb
- P:\HP
- D:\4c
- t:\SY
- z:\rV
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report