SUSPICIOUS — 80e848189890f38d803bf51df123f901148d12fbc65bd6be9080c4f5e8b745d9
SUSPICIOUS — 80e848189890f38d803bf51df123f901148d12fbc65bd6be9080c4f5e8b745d9 is a apk sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (51/100). 4 of 51 detection engines flagged it.
Identification
- SHA-256:
80e848189890f38d803bf51df123f901148d12fbc65bd6be9080c4f5e8b745d9 - SHA-1:
69a9c0776a2611a68a86d8c5eb5a54a16be788cb - MD5:
4f8b2f951745a42af17246904dbda27c - ssdeep:
98304:bCeHhCPZ8d2Ou12yurNhwQcqRT3KSpAHSDCWtn0rAS9CzhsovTKQuOjXOfv7FHFD:WvZ8IOu65tcS77Autn0rAS9udLKLGXOf - TLSH:
T11063235935BDF970F4F97362FABC229C49BD7520800534A6132E682214EE1377D6A33A - Submitted as: 80e848189890f38d803bf51df123f901148d12fbc65bd6be9080c4f5e8b745d9
- File type: apk · Size: 4804240 bytes
- Verdict: suspicious (51/100)
Detections (4 of 51 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- androguard (APK/DEX analysis): androguard:4 dangerous permissions
- Microsoft Defender: Trojan:Script/Wacatac.C!ml
- Kaspersky (KVRT): not-a-virus:HEUR:RiskTool.AndroidOS.SMSreg.mq
Why this verdict
The suspicious score of 51/100 is the fusion of 3 weighted signals:
- androguard (APK/DEX analysis) flagged androguard:4 dangerous permissions (rule
androguard:4 dangerous permissions) - engine signal, weight 0.35, confidence 0.70 - APK requests 5 dangerous permissions: android.permission.READ_PHONE_STATE, android.permission.SEND_SMS, android.permission.RECEIVE_SMS, android.permission.READ_SMS, android.permission.RECEIVE_BOOT_COMPLETED - static signal, weight 0.35, confidence 0.70
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (3 executables)
This apk carries 3 extracted members, each analyzed as its own sample:
- mraid.js -
1aecfba93ef7a6f34061483c6ef8b01a9b8311a7fc4807b5f178bb168e063f34 - ormma.js -
9d8aabf11f5060ed0a1a1f0e927a5cdc5db210b21cee1fec7b7457563b65dd7a - ormma_bridge.js -
0bd2c774105e75d0a7e428cad3a6e0141082aa4ae02f3dece60f6f181c224cae
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- ppq.fr
- www.inkscape.org
File paths
- p:\Qp:f
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report