MALICIOUS — 9ececbf103dfdfbc2b5b2490c5d49c2d636ff22650b390d058228a12a03e8762
MALICIOUS — 9ececbf103dfdfbc2b5b2490c5d49c2d636ff22650b390d058228a12a03e8762 is a apk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (73/100). 2 of 55 detection engines flagged it.
Identification
- SHA-256:
9ececbf103dfdfbc2b5b2490c5d49c2d636ff22650b390d058228a12a03e8762 - SHA-1:
1ae3705f513e92899aa646774a0ab49d67360348 - MD5:
f2c093375c5f0320104d59052678a82e - ssdeep:
98304:mnJcygrKHSeEq1cou2b/O11sdZHivJV6FTyl9Cdr34go/JO:mJctrKyeEY5gAH3sWd0g4Y - TLSH:
T1176033CF75E92CCFC5E85C00730A2A5DFD8BAAE94018DCF513855132D8ECAAB4D621A5 - Submitted as: 9ececbf103dfdfbc2b5b2490c5d49c2d636ff22650b390d058228a12a03e8762
- File type: apk · Size: 3620686 bytes
- Verdict: malicious (73/100)
Detections (2 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Kaspersky (KVRT): not-a-virus:HEUR:AdWare.AndroidOS.Kuguo.j
Why this verdict
The malicious score of 73/100 is the fusion of 4 weighted signals:
- Kaspersky (KVRT) flagged not-a-virus:HEUR:AdWare.AndroidOS.Kuguo.j (rule
not-a-virus:HEUR:AdWare.AndroidOS.Kuguo.j) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://purl.org/dc/elements/1.1/, http://www.iec.ch - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (3 executables)
This apk carries 3 extracted members, each analyzed as its own sample:
- libjiagu.so -
68ab2ab39cf23cc19fd1b4a4ecc8aaf1465885b3dbeba98bcb3b5110a1c95525 - libjiagu_x86.so -
6ee081753f582d98d552f6fa41c832fd668fb7634f5719c2bcfeea8d856d58f8 - libxlp.so -
b61675544b0492ac916984134eda67b6d2f5031d2d065674172ab238296a3679
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://ns.adobe.com/xap/1.0/
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/photoshop/1.0/
- http://www.iec.ch
Embedded domains
- www.diandian.com
- diandian.com
- ns.adobe.com
- www.w3.org
- purl.org
- www.meitu.com
- www.iec.ch
File paths
- q:\$
- a:\p
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report