MALICIOUS — 4b8a2fdaad0f3e6e6325d3deef163526e470c9a88a23f73e491bd228f3548641.apk
MALICIOUS — 4b8a2fdaad0f3e6e6325d3deef163526e470c9a88a23f73e491bd228f3548641.apk is a apk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (89/100), attributed to the AndroidOS family. 3 of 25 detection engines flagged it.
Identification
- SHA-256:
4b8a2fdaad0f3e6e6325d3deef163526e470c9a88a23f73e491bd228f3548641 - SHA-1:
1b5a32e61c9de6744a7472e3d4e7590b3d9974a4 - MD5:
4200322e65b8e871f859a11c3bc60600 - ssdeep:
393216:f7GCXr8pSEGvgfsaxgd52kU5Ux9aXYUx9aXfwVR:TGLHGvoOe6x9aHx9au - TLSH:
T1407433E82779EE64CCF5573268D2D10E229E842D203E96C9337076B571E98AF11331A7 - Submitted as: 4b8a2fdaad0f3e6e6325d3deef163526e470c9a88a23f73e491bd228f3548641.apk
- File type: apk · Size: 24067230 bytes
- Verdict: malicious (89/100) · Family: AndroidOS
Detections (3 of 25 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:Linux/CoinMiner.N!MTB
- Kaspersky (KVRT): not-a-virus:HEUR:RiskTool.AndroidOS.Miner.b
Why this verdict
The malicious score of 89/100 is the fusion of 6 weighted signals:
- Microsoft Defender flagged Trojan:Linux/CoinMiner.N!MTB (rule
Trojan:Linux/CoinMiner.N!MTB) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged not-a-virus:HEUR:RiskTool.AndroidOS.Miner.b (rule
not-a-virus:HEUR:RiskTool.AndroidOS.Miner.b) - engine signal, weight 0.55, confidence 0.85 - Contacted 0 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://upminer-up-default-rtdb.firebaseio.com - static signal, weight 0.35, confidence 0.60
- APK is not signed (v1 JAR signature absent) - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (7 executables)
This apk carries 7 extracted members, each analyzed as its own sample:
- DebugProbesKt.bin -
ae8a082dd609313835ba93c3ef479a3af9903977d7bdc81df45bbd209ec7d0da - xmrig_arm64 -
a847b257cc6b29cda5e7e485bccbe1ba8e1d573d22f74731f15497ba7b576c4a - xmrig_armv7 -
a847b257cc6b29cda5e7e485bccbe1ba8e1d573d22f74731f15497ba7b576c4a - libxmrig-mo.so -
dd14ad90c2e34e200e0c01e95702ebce3441f42e92347e30203bb54d0e19f283 - libxmrig.so -
dcb1fafec3748ee1d82605cc54c8c53ce6595b0413b7433dc781402da01080cb - libxmrig-mo.so -
aae306433e32315661d8aa78bb61f2f4192be9ad39683d4642c88185cd4270f0 - libxmrig.so -
01adba7c06026778e46910fd5f92fe8360e285bd765a904bb1c7fb16ce1e839a
Dynamic analysis (android)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- http://connectivitycheck.gstatic.com/generate_204
- https://android.googlesource.com/toolchain/llvm-project
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
Embedded URLs
- https://upminer-up-default-rtdb.firebaseio.com
- http://connectivitycheck.gstatic.com/generate_204
- https://android.googlesource.com/toolchain/llvm-project
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
Embedded domains
- z2.sg
- 8.es
- upminer-up-default-rtdb.firebaseio.com
- upminer-up.firebasestorage.app
File paths
- T:\$
- b:\^b
- o:\7Q
- B:\P(v
- s:\#H
- K:\ak
- c:\e9h
- i:\OD
- V:\{.V
More AndroidOS samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report