MALICIOUS — 082_AndroRat_6Dec2013.bin
MALICIOUS — 082_AndroRat_6Dec2013.bin is a apk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Androrat family. 4 of 50 detection engines flagged it.
Identification
- SHA-256:
9c8d02ff190f5929bc6745a541c326b2cd387d3145c759823d24972e65398a99 - SHA-1:
5c0f9caa159b416e2b784f483256048adb6a4025 - MD5:
badd51645b60f7168b5d9a0b441c924e - ssdeep:
1536:+MJ3HajfKWKIo/IAMi0NBMjjBdUW/t1g14Acn:+Mp6jfXKSTi0r6dn1Su - TLSH:
T13C36F1C4A5ADFCD0F0D10FF58A9CA5AC7A2A94E4882D0066954669346C9897FCC3339E - Submitted as: 082_AndroRat_6Dec2013.bin
- File type: apk · Size: 66918 bytes
- Verdict: malicious (98/100) · Family: Androrat
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Andr.Trojan.Androrat-1
- androguard (APK/DEX analysis): androguard:9 dangerous permissions
- Microsoft Defender: MonitoringTool:AndroidOS/AndroRat
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Andr.Trojan.Androrat-1 (rule
Andr.Trojan.Androrat-1) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged MonitoringTool:AndroidOS/AndroRat (rule
MonitoringTool:AndroidOS/AndroRat) - engine signal, weight 0.55, confidence 0.85 - APK requests 10 dangerous permissions: android.permission.RECEIVE_SMS, android.permission.READ_SMS, android.permission.SEND_SMS, android.permission.READ_PHONE_STATE, android.permission.ACCESS_FINE_LOCATION - static signal, weight 0.50, confidence 0.70
- Contacted 0 external host(s) at runtime (8 HTTP) - network signal, weight 0.40, confidence 0.80
- androguard (APK/DEX analysis) flagged androguard:9 dangerous permissions (rule
androguard:9 dangerous permissions) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (android)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- http://connectivitycheck.gstatic.com/generate_204
- https://android.googlesource.com/toolchain/llvm-project
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
Embedded URLs
- http://connectivitycheck.gstatic.com/generate_204
- https://android.googlesource.com/toolchain/llvm-project
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
More Androrat samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report