MALICIOUS — 2wvVwG9oCkNU.apk
MALICIOUS — 2wvVwG9oCkNU.apk is a apk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100), attributed to the AndroidOS family. 3 of 24 detection engines flagged it.
Identification
- SHA-256:
4b713c6fbe274e4ae95bc8f37567f925841f178fb9c4302c4a360c14fefbcc6f - SHA-1:
28dd64e478266009433169267fe8ba41c43163da - MD5:
2848782555461fcd6bf48109338a2863 - ssdeep:
196608:o4zi7RajBtat0yQojJEH98wiPmmbo2e79Be5ZRZS2KD+/swkUobtu67/C45y5cXN:Riut00ToNy98X9e79AR0Tzz7/xc8N - TLSH:
T1B86D22FA0731BD50CBFAEA205A14518F0F97565C01249AF5A3B8163270EB4EB663352F - Submitted as: 2wvVwG9oCkNU.apk
- File type: apk · Size: 12499518 bytes
- Verdict: malicious (72/100) · Family: AndroidOS
Detections (3 of 24 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- YARA: MalwareAnalyser community pack: TL_UPX_Packed
- Kaspersky (KVRT): HEUR:Trojan-Dropper.AndroidOS.Banker.eu
Why this verdict
The malicious score of 72/100 is the fusion of 4 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Trojan-Dropper.AndroidOS.Banker.eu (rule
HEUR:Trojan-Dropper.AndroidOS.Banker.eu) - engine signal, weight 0.55, confidence 0.85 - YARA: MalwareAnalyser community pack flagged TL_UPX_Packed (rule
TL_UPX_Packed) - engine signal, weight 0.35, confidence 0.70 - APK is not signed (v1 JAR signature absent) - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
This apk is a container, so it was not detonated itself. Its extracted members were re-submitted and analyzed as their own samples, and the runtime behaviour lives on those reports.
Embedded URLs
- https://github.com/REAndroid/ARSCLib
Embedded domains
- u.tv
- 2.cn
- 0k.uk
- 4l.hk
- github.com
File paths
- b:\Xc
- e:\R
More AndroidOS samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report