MALICIOUS — e744a39cbfc82c6a937833025098ef0326b64316fbd04882e44dcef4413e8d9f
MALICIOUS — e744a39cbfc82c6a937833025098ef0326b64316fbd04882e44dcef4413e8d9f is a apk sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 2 of 55 detection engines flagged it.
Identification
- SHA-256:
e744a39cbfc82c6a937833025098ef0326b64316fbd04882e44dcef4413e8d9f - SHA-1:
6d2b248fb6cdf7e54ba60c3248962ae08782164e - MD5:
7f831ba45efea64e6c6402614ddc0750 - ssdeep:
393216:6f9kHuswUvnmmq4Zw/5cCVnYyXo/UgsPbmpF7HER:6f9HUvLH6yCmyY2bOER - TLSH:
T1BC6F1295237E7961E0FC2B12A165804C6AB6306E91195EE5B3586D3070F8E3FA4331FB - Submitted as: e744a39cbfc82c6a937833025098ef0326b64316fbd04882e44dcef4413e8d9f
- File type: apk · Size: 15314870 bytes
- Verdict: malicious (75/100)
Detections (2 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- androguard (APK/DEX analysis): androguard:7 dangerous permissions
Why this verdict
The malicious score of 75/100 is the fusion of 5 weighted signals:
- APK requests 12 dangerous permissions: android.permission.ACCESS_COARSE_LOCATION, android.permission.ACCESS_FINE_LOCATION, android.permission.BIND_ACCESSIBILITY_SERVICE, android.permission.BIND_DEVICE_ADMIN, android.permission.CALL_PHONE - static signal, weight 0.50, confidence 0.70
- androguard (APK/DEX analysis) flagged androguard:7 dangerous permissions (rule
androguard:7 dangerous permissions) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://www.freesfx.co.uk/assets/images/freesfxlogo.png, http://ajax.googleapis.com/ajax/libs/prototype/1.6.0.3/prototype.js, http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.2/effects.js - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Archive contents (14 executables)
This apk carries 14 extracted members, each analyzed as its own sample:
- libaecore.so -
2f38c6c92064c61ff0548b61d5a34ddbd06c9b94360aa9b039558f6a181d3ddd - libaedroid.so -
1202358f111ef93aec9254d89e15bb99d96716cfc467eeaa1ebf66be0ba9013b - libaeexp.so -
aa94d5f17d255438fd0c5d11b088826460f91bb61f2978692347bbcf9afe3660 - libaehelp.so -
03450fb3918d989e1f0062a0fd529cd5b70d685b9b17297a4596b7fc99eedbc6 - libaemobile.so -
db8469a9238c476795f8a2441b98b6e3d2419f84e9b49480c69786f3ff81a618 - libaepack.so -
5f829e8dc626c9f9f49a067519c4983b2a1a1915686d0baea09e9f4825519907 - libaescn.so -
986ae969b754a83d6d71a4a9fb9314d2a0fe79300e5f5c915214a5bedb0b3d17 - libaevdf.so -
c38ad3103cf133cee466c48262dae849da0f53ca98183f93d35e90387dab491b - libmavapi.so -
3ff0ee1fe84bf3fe96a034656059c2ee6e7dcc9046fd7244db453879a80b3219 - libmaven.so -
11315dd8c9207b547fb9cfd7a3fe5e2032c856d51b24c57a8401d42d70b4f827 - libmavpreload.so -
2a2f8b8f1c54d032a76bc2ce8cda04a93ba11219858a49dbce252f9c01d63ba0 - libmavupdate.so -
a5aceb57c5372195dfcbd0e8cd0a5277bf5e20def49fdbbc1ab722a717fc9ae3 - libscew.so -
7748c79525a2f9914c8f5994c7c04f6d604906bd4768ea0528984a0d4b2d8ea3 - libantivirus.so -
126a4cab17387fe1a80ea413ba9bb0a8469c70257b9fa3b77aa1b573cf31e1ab
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd
- http://www.w3.org/1999/xhtml
- http://www.freesfx.co.uk/assets/images/freesfxlogo.png
- http://ajax.googleapis.com/ajax/libs/prototype/1.6.0.3/prototype.js
- http://ajax.googleapis.com/ajax/libs/scriptaculous/1.8.2/effects.js
- https://www.paypal.com/cgi-bin/webscr
- https://www.paypalobjects.com/en_GB/i/btn/btn_donate_LG.gif
- https://www.paypalobjects.com/en_GB/i/scr/pixel.gif
- http://www.avira.com
- http://www.avira.com/en/android-upsell
- https://second-kite-739.firebaseio.com
- http://www.avira.com/ja/android-upsell
- http://www.avira.com/de/android-upsell
- http://www.avira.com/nl/android-upsell
- http://www.avira.com/pl/android-upsell
- http://www.avira.com/ko/android-upsell
- http://www.avira.com/fr/android-upsell
- http://www.avira.com/tr/android-upsell
- http://www.avira.com/es/android-upsell
- http://www.avira.com/it/android-upsell
- http://www.avira.com/pt-br/index
- http://www.avira.com/pt-br/android-upsell
- http://www.avira.com/ru/android-upsell
- http://www.apache.org/licenses/LICENSE-2.0
Embedded domains
- www.w3.org
- ajax.googleapis.com
- www.paypal.com
- www.paypalobjects.com
- r.za
- y1t.in
- 1.pw
- f.tw
- my.avira.com
- www.avira.com
- facebook.com
- second-kite-739.firebaseio.com
- second-kite-739.appspot.com
- verr.app
- myavira.com
- www.apache.org
File paths
- H:\o
- Z:\30F
- V:\M
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report