MALICIOUS — 36ef3a11514f39f0143155711a4ca40ec546031a675a94c3b65dbae2c6d86e52.apk
MALICIOUS — 36ef3a11514f39f0143155711a4ca40ec546031a675a94c3b65dbae2c6d86e52.apk is a apk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (81/100), attributed to the AndroidOS family. 3 of 25 detection engines flagged it.
Identification
- SHA-256:
36ef3a11514f39f0143155711a4ca40ec546031a675a94c3b65dbae2c6d86e52 - SHA-1:
9520bc32a31773126ec776985e8ca9896a3a0478 - MD5:
f080a7e25bacfb2435cc9f5bdc4c12c3 - ssdeep:
196608:1u+Nlh8Eu1wWwPLCLH+QN4ut1eMSsiYmIJLmjOItCrsbyQmKoThwp9so0GHbp:eD1xwPmLH+luHeFWmIJSamCwy17Yp - TLSH:
T1946A33DD2775E164E7F88774BC44E89C1C11298E2A2D5AFA8309A42B71B309F113367B - Submitted as: 36ef3a11514f39f0143155711a4ca40ec546031a675a94c3b65dbae2c6d86e52.apk
- File type: apk · Size: 9673534 bytes
- Verdict: malicious (81/100) · Family: AndroidOS
Detections (3 of 25 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- androguard (APK/DEX analysis): androguard:5 dangerous permissions
- Kaspersky (KVRT): HEUR:Trojan-Banker.AndroidOS.Banbra.as
Why this verdict
The malicious score of 81/100 is the fusion of 5 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Trojan-Banker.AndroidOS.Banbra.as (rule
HEUR:Trojan-Banker.AndroidOS.Banbra.as) - engine signal, weight 0.55, confidence 0.85 - Contacted 0 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- androguard (APK/DEX analysis) flagged androguard:5 dangerous permissions (rule
androguard:5 dangerous permissions) - engine signal, weight 0.35, confidence 0.70 - APK is not signed (v1 JAR signature absent) - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (android)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- http://connectivitycheck.gstatic.com/generate_204
- https://android.googlesource.com/toolchain/llvm-project
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
Embedded URLs
- https://github.com/REAndroid/APKEditor
- https://github.com/REAndroid/ARSCLib
- http://connectivitycheck.gstatic.com/generate_204
- https://android.googlesource.com/toolchain/llvm-project
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
Embedded domains
- github.com
- c5ra.tv
- i.ly
File paths
- Z:\/q
- B:\)i
- L:\!G
- P:\/4g
- B:\&
- a:\y
- X:\sGx
More AndroidOS samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report