CLEAN — b3b5086f4f67270197f35d68133d821f5dc8ed040bb4471291e7a782af991086
CLEAN — b3b5086f4f67270197f35d68133d821f5dc8ed040bb4471291e7a782af991086 is a apk sample analyzed by MalwareAnalyzer by Cyble with a clean verdict (32/100). 1 of 54 detection engines flagged it.
Identification
- SHA-256:
b3b5086f4f67270197f35d68133d821f5dc8ed040bb4471291e7a782af991086 - SHA-1:
47e2a4d6a3713fabdf581d542889d6903a9fa9ad - MD5:
b5c42dc2992978cf5da77f706f0993bd - ssdeep:
786432:c1Dx8u73qakNIdb03R6pLHIbKFr234Noa1GrQFyUtNUSbbsIDgW1H:uF8gvky566lobkr2INoYGrQ0Obs3W1H - TLSH:
T1007633EC1BB5FAA2CAF4A5305D50495E1E91600C203C65BDD399847A32BB637E1331AF - Submitted as: b3b5086f4f67270197f35d68133d821f5dc8ed040bb4471291e7a782af991086
- File type: apk · Size: 28591137 bytes
- Verdict: clean (32/100)
Detections (1 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
Why this verdict
The clean score of 32/100 is the fusion of 2 weighted signals:
- Embedded network infrastructure: https://mr-stick-ad.firebaseio.com - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (6 executables)
This apk carries 6 extracted members, each analyzed as its own sample:
- libFirebaseCppAnalytics.so -
6975585b25edd6f8f54a9a4c4ab3bb106c7ee3c30e3a17567985bbf7d2071ee2 - libFirebaseCppApp-6_4_0.so -
a343d4cca1a12a7ff4996c7a45ec692086c695c2cbf1071a07218243ff742699 - libgpg.so -
209f0f0681ac695bf301f9548893a773a0921260244701b7c91ee70755f3385b - libil2cpp.so -
17a887b35db42927622baf0c166bd8b4f7fda1aa6c7aac0f17e3b77291a44c99 - libmain.so -
f47b8af98373cda7b4b547354dc90ae986763e17e4bfeb90758e0ea09e01bc5c - libunity.so -
74f254f06ac67f875cbb41ab0462ec289318a8b092b20b175eff3b1d39dd5db1
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://mr-stick-ad.firebaseio.com
Embedded domains
- t.no
- ct.ch
- 9.pw
- c.cf
- l.in
- 27.cf
- vu.to
- 4s.se
- di.it
- 464.tw
- facebook.com
- mr-stick-ad.appspot.com
- mr-stick-ad.firebaseio.com
- 7.ai
- ym.pw
- xs.ca
- mo.eu
- vb.nl
- of.to
File paths
- i:\f:
- C:\^,U
- y:\K
- B:\:
- U:\Ia
- Z:\/G
- Y:\W
- b:\o
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report