MALICIOUS — 080_AndroRat_6Dec2013.bin
MALICIOUS — 080_AndroRat_6Dec2013.bin is a unknown sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (72/100), attributed to the MonitoringTool family. 2 of 37 detection engines flagged it.
Identification
- SHA-256:
956a107a38ccde7f48494aa78888b50b7c79c0b3f4b107fbb513806d126e5618 - SHA-1:
975520e7acdf629dbd61036408ee1c5c60c6889a - MD5:
2efd2b76d0060c68719e71dd24a35504 - ssdeep:
1536:6cV5A5i1dhlM8x+pfPYwZH3MC1s4EMTLKJD:6co5i1dL0MC1s4B4D - TLSH:
T129393AD692217D5ADDF0C6A7E9615CAE4BC7A9DA24B688DC40C0E253F0B1733367022D - Submitted as: 080_AndroRat_6Dec2013.bin
- File type: unknown · Size: 84544 bytes
- Verdict: malicious (72/100) · Family: MonitoringTool
Detections (2 of 37 engines)
- Microsoft Defender: MonitoringTool:AndroidOS/AndroRat
- Emsisoft (Emergency Kit): Android.RemoteAdmin.A
Why this verdict
The malicious score of 72/100 is the fusion of 2 weighted signals:
- Microsoft Defender flagged MonitoringTool:AndroidOS/AndroRat (rule
MonitoringTool:AndroidOS/AndroRat) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Android.RemoteAdmin.A (rule
Android.RemoteAdmin.A) - engine signal, weight 0.55, confidence 0.85
Embedded IP addresses
- 192.168.0.12
More MonitoringTool samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report