MALICIOUS — com.baidu.appsearch.swanapp.jar
MALICIOUS — com.baidu.appsearch.swanapp.jar is a apk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100). 2 of 54 detection engines flagged it.
Identification
- SHA-256:
dd10c388b6d54e0be5e4fcf7ef5d5281040d2786a5810a46d1de9be641a07e00 - SHA-1:
44cd576d61c57247fb15c6e92c8a1c5a1f281fbf - MD5:
a381fb7045e527f7d5f11e6331648668 - ssdeep:
196608:7ED6tTogZC/Zd/I4TTsR1uaKc5hK/kM0AcadydWAj3VKHLxEDPEDv:7ED6xpe/RTTG1uIDO0ABDAj3EHOPEDv - TLSH:
T11F69239117FEB882D8F5B7207160F09C2AF9346D682411E903A89A3174E553F94B72BF - Submitted as: com.baidu.appsearch.swanapp.jar
- File type: apk · Size: 8776266 bytes
- Verdict: malicious (93/100)
Detections (2 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV feed: SaneSecurity foxhole_generic: Sanesecurity.Foxhole.JS_Zip_21.UNOFFICIAL
Why this verdict
The malicious score of 93/100 is the fusion of 4 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Sanesecurity.Foxhole.JS_Zip_21.UNOFFICIAL (rule
Sanesecurity.Foxhole.JS_Zip_21.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - APK requests 3 dangerous permissions: android.permission.ACCESS_COARSE_LOCATION, android.permission.ACCESS_FINE_LOCATION, android.permission.READ_PHONE_STATE - static signal, weight 0.35, confidence 0.70
- Embedded network infrastructure: http://purl.org/dc/elements/1.1/ - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (15 executables)
This apk carries 15 extracted members, each analyzed as its own sample (listing truncated):
- ._extension.js -
01eb8189a6fbaba16189473294daf816c97a69caf97861ff8c537fed54d59591 - extension.js -
fafa4a2121c7638aa42be5ff7298366f6aefcac4e4c10c57b9487108c763c304 - pickerRegion.js -
b56a0c352f5d64cc684e78a9f87aa3d36e868d78c2c7f80acd532a8ed0d2a2f4 - index.js -
0a4c6daf63c7457ac0d9e330202611a33382ab478ea0b6d973574ac37ee25032 - index.js -
5b52b5762a435c4a948b2c9d83150b05e60a690c3136ae2f8ee2bc8a02bfbbf3 - index.js -
8641075df5f6c042154d56c50784e6d07559166ed65db435c995f1b7984c9ad9 - custom-element-template.js -
fb3db0ebf5867a685ac255380bdecee28f524990cde2bfcfc12105228438c333 - index.js -
a34e42ca9e01e5f6366c8e5bbdd6e6edf50ccdfcd7d6b2e1112699492df93376 - swan-template.js -
3ed9a2a8c23d45e118550d04349a71a1d521403e18751893ee543e68a270945f - master.js -
fcda6fda337ee556c719af89f96be875c2156cb5e77c3c7359c0c56857f017ca - slave.js -
40256e3a62a0e09450269f61d11a81ffc5f61d3089233a8d0e0aee36ff4dc5d5 - swan-game-open-data.js -
8789cca189e9321fa579561462da682fa1b94e994e92b34a6d80993cb5234f28 - swan-game.js -
96c29ea82949aaa346fac5b03a548503fe7da1d0a980f0b32a7a66b51c1cbbce - libBaiduMapSDK_base_v5_2_1.so -
b861d03496f071f3d3f7def32d21375dfd728374c980222bbb252143a21bb51c - libBaiduMapSDK_map_v5_2_1.so -
cf85b26c5d87cda0011957aa06c8c56b1244335b869d2d8d995a960dc9d4697a
Dynamic analysis
This apk is a container, so it was not detonated itself. Its extracted members were re-submitted and analyzed as their own samples, and the runtime behaviour lives on those reports.
Embedded URLs
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://ns.adobe.com/tiff/1.0/
- http://ns.adobe.com/exif/1.0/
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/sType/ResourceEvent#
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/photoshop/1.0/
- http://ns.adobe.com/xap/1.0/sType/ResourceRef#
Embedded domains
- www.w3.org
- ns.adobe.com
- purl.org
- t.fr
- 9f.in
- 5.co
- 8.kr
- b.kr
File paths
- Y:\_w
- u:\z
- n:\LW
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report