MALICIOUS — b7f8c6b76b8b1a0f99fbec5eb467983e8fd18f3ef496957bd8fb9c5bfca5e50b.apk
MALICIOUS — b7f8c6b76b8b1a0f99fbec5eb467983e8fd18f3ef496957bd8fb9c5bfca5e50b.apk is a apk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the AndroidOS family. 4 of 25 detection engines flagged it.
Identification
- SHA-256:
b7f8c6b76b8b1a0f99fbec5eb467983e8fd18f3ef496957bd8fb9c5bfca5e50b - SHA-1:
4b9bfc8662a7539b25c0dc628560b0fb39e2c4e4 - MD5:
5f51cbb987e6fdb5c5ccb5a1a7ad3bde - ssdeep:
98304:GUDER3kg6q+7akTBZgV5z6WJQukgZBW6Di/5v4ERSzEYmmmYu9FTEwtluzX6w34p:GUY3R6qOtcVoupvW6G/VRclwtEzX7Y - TLSH:
T12A708DEA25B0354CD8FBE697B860CC1D99CB458F223615CD42E1D26790EA3B352F413A - Submitted as: b7f8c6b76b8b1a0f99fbec5eb467983e8fd18f3ef496957bd8fb9c5bfca5e50b.apk
- File type: apk · Size: 16562735 bytes
- Verdict: malicious (95/100) · Family: AndroidOS
Detections (4 of 25 engines)
- YARA: Trellix/McAfee ATR: ATR_LockBit_Ransomware
- YARA: ReversingLabs: RL_AsyncRAT
- androguard (APK/DEX analysis): androguard:6 dangerous permissions
- Kaspersky (KVRT): HEUR:Trojan-Banker.AndroidOS.Mamont.na
Why this verdict
The malicious score of 95/100 is the fusion of 10 weighted signals:
- Kaspersky (KVRT) flagged HEUR:Trojan-Banker.AndroidOS.Mamont.na (rule
HEUR:Trojan-Banker.AndroidOS.Mamont.na) - engine signal, weight 0.55, confidence 0.85 - APK requests 7 dangerous permissions: android.permission.CALL_PHONE, android.permission.READ_CONTACTS, android.permission.READ_PHONE_STATE, android.permission.READ_SMS, android.permission.RECEIVE_BOOT_COMPLETED - static signal, weight 0.50, confidence 0.70
- Contacted 0 external host(s) at runtime (16 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded executable payload carved at offset 10603246 - static signal, weight 0.40, confidence 0.70
- YARA: Trellix/McAfee ATR flagged ATR_LockBit_Ransomware (rule
ATR_LockBit_Ransomware) - engine signal, weight 0.35, confidence 0.70 - YARA: ReversingLabs flagged RL_AsyncRAT (rule
RL_AsyncRAT) - engine signal, weight 0.35, confidence 0.70 - androguard (APK/DEX analysis) flagged androguard:6 dangerous permissions (rule
androguard:6 dangerous permissions) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://bit.ly/3GfZoys, https://www.bouncycastle.org, https://bit.ly/2O3fHEX - static signal, weight 0.35, confidence 0.60
- APK is not signed (v1 JAR signature absent) - static signal, weight 0.30, confidence 0.60
- Extracted generic config (4 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Archive contents (7 executables)
This apk carries 7 extracted members, each analyzed as its own sample:
- DebugProbesKt.bin -
4d13bd92f86a0b1415062b8ed57655c0738ccfbdf0786c1d730d988b27fd4400 - libconscrypt_jni.so -
5e8c07ceb6cdda9aa1c31771e1e4ba49a5fb4692d625482e91a9ffbd6f66bff5 - libdatastore_shared_counter.so -
d3e48717c9aa147e0ab21063ba0e8e0211cabf8bf40b222640829519edbf58e1 - libsecurelogic.so -
ec106e708bd4c0f68cf26eaf4a54bf5001445a6fbf9b45599cca5455282753f1 - libconscrypt_jni.so -
bf855204f96020e213bd5a06c180a5d8d93f7c3ed3f537934c57c80c3e967325 - libdatastore_shared_counter.so -
716c5d8d2cac8ca0edf65da8f139c7886b726ac79d542a14edeb94994ba6d3dc - libsecurelogic.so -
0d7ac22978707160e62e376f50eb077554071dcefe712d723e797f78825364b4
Dynamic analysis (android)
1 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- http://connectivitycheck.gstatic.com/generate_204
- https://amazon.com
- https://android.googlesource.com/toolchain/llvm-project
- https://cloudflare.f-droid.org
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://f-droid.org
- https://fdroid.link
- https://play.google.com
- https://staging.f-droid.org
- https://www.amazon.com
- https://www.f-droid.org
- https://www.google.com/generate_204
- https://www.googleapis.com/auth/account.capabilities
- https://www.googleapis.com/auth/account.service_flags
- https://www.googleapis.com/auth/userinfo.email
- https://www.gstatic.com/android-search/hotword/x_google/975058821313279e27b2c3f04de0beef/hotword.data
Embedded URLs
- https://bit.ly/3GfZoys
- https://issuetracker.google.com/issues/241760537
- https://www.bouncycastle.org
- https://bit.ly/2O3fHEX
- https://youtrack.jetbrains.com/issue/KT-55980
- https://firebase.google.com/support/privacy/init-options
- https://issuetracker.google.com/issues/new?component=907884&template=1466542
- https://developer.android.com/training/articles/direct-boot
- http://schemas.android.com/apk/res-auto
- http://schemas.android.com/apk/res/android
- https://api.pushy.me
- https://issuetracker.google.com/issues/new?component=413107&template=1096568
- https://android.googlesource.com/toolchain/llvm-project
- http://www.apache.org/licenses/LICENSE-2.0
- https://youtrack.jetbrains.com/issue/KT-46465
- https://publicsuffix.org/list/public_suffix_list.dat
- https://mozilla.org/MPL/2.0/
- http://schemas.android.com/aapt
- http://connectivitycheck.gstatic.com/generate_204
- https://amazon.com
- https://cloudflare.f-droid.org
- https://dl.google.com/android/voice/soda/en-US/v3008/soda-en-US-v3008.zip
- https://f-droid.org
- https://fdroid.link
- https://play.google.com
Embedded domains
- n0.es
- n0.eu
- bit.ly
- issuetracker.google.com
- www.bouncycastle.org
- class.java.name
- youtrack.jetbrains.com
- pushy.me
- firebase.google.com
- developer.android.com
- 6androidx.appcompat.app
- builder.name
- charset.name
- clazz.name
- current.work
- firebaseinstallations.googleapis.com
- gcm.n.link
- schemas.android.com
- api.pushy.me
- pushy.io
- mqtt.pushy.io
- openssl.org
- handshake.cc
- o.gg
- www.apache.org
Embedded IP addresses
- 0.15.1.1
- 1.1.3.10
- 61.1.1.1
- 61.1.1.3
- 1.9.16.1
- 1.9.16.2
- 1.9.16.3
- 1.9.16.5
- 1.9.16.6
- 1.1.1.22
- 4.1.188.7
- 1.101.3.4
- 1.12.1.3
- 1.12.1.4
- 1.12.1.5
- 1.12.1.6
More AndroidOS samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report