MALICIOUS — 3f75869023be1a13a8ffd8d823a6986880d826fac37bea969bb89cbe1dd17856
MALICIOUS — 3f75869023be1a13a8ffd8d823a6986880d826fac37bea969bb89cbe1dd17856 is a apk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100). 4 of 55 detection engines flagged it.
Identification
- SHA-256:
3f75869023be1a13a8ffd8d823a6986880d826fac37bea969bb89cbe1dd17856 - SHA-1:
11660acd792f20fda6c1952e70eb4c8c086ea9ff - MD5:
2120863ad1604ccadd0ca1b9ef181a7b - ssdeep:
98304:HFFaQvpxjr2OuRDgWPSsjKNxST3sSpplpyCQtw0rAS9CzhsovTKQuOjXOfhyj4yH:l7xj6OuzKJNkbBpYtw0rAS9udLKLGXOw - TLSH:
T13E6313D935BCF1E2F4FD7362B2EE628C49BA752084052465132D682814ECB377D6732A - Submitted as: 3f75869023be1a13a8ffd8d823a6986880d826fac37bea969bb89cbe1dd17856
- File type: apk · Size: 4804234 bytes
- Verdict: malicious (89/100)
Detections (4 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- androguard (APK/DEX analysis): androguard:4 dangerous permissions
- Microsoft Defender: Trojan:Script/Wacatac.C!ml
- Kaspersky (KVRT): not-a-virus:HEUR:RiskTool.AndroidOS.SMSreg.mq
Why this verdict
The malicious score of 89/100 is the fusion of 6 weighted signals:
- Microsoft Defender flagged Trojan:Script/Wacatac.C!ml (rule
Trojan:Script/Wacatac.C!ml) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged not-a-virus:HEUR:RiskTool.AndroidOS.SMSreg.mq (rule
not-a-virus:HEUR:RiskTool.AndroidOS.SMSreg.mq) - engine signal, weight 0.55, confidence 0.85 - androguard (APK/DEX analysis) flagged androguard:4 dangerous permissions (rule
androguard:4 dangerous permissions) - engine signal, weight 0.35, confidence 0.70 - APK requests 5 dangerous permissions: android.permission.READ_PHONE_STATE, android.permission.SEND_SMS, android.permission.RECEIVE_SMS, android.permission.READ_SMS, android.permission.RECEIVE_BOOT_COMPLETED - static signal, weight 0.35, confidence 0.70
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (3 executables)
This apk carries 3 extracted members, each analyzed as its own sample:
- mraid.js -
1aecfba93ef7a6f34061483c6ef8b01a9b8311a7fc4807b5f178bb168e063f34 - ormma.js -
9d8aabf11f5060ed0a1a1f0e927a5cdc5db210b21cee1fec7b7457563b65dd7a - ormma_bridge.js -
0bd2c774105e75d0a7e428cad3a6e0141082aa4ae02f3dece60f6f181c224cae
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- ppq.fr
- www.inkscape.org
File paths
- p:\Qp:f
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report