× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 49a8c4f55e89a70480f1cb629e82e3d81d23962a3826b8c1f360d2425cd0d249
File name: get_player.php
Detection ratio: 30 / 57
Analysis date: 2016-05-02 20:37:00 UTC ( 1 year, 2 months ago )
Antivirus Result Update
Ad-Aware Android.Trojan.SLocker.BC 20160502
AhnLab-V3 Android-Trojan/Slocker.d349 20160502
Alibaba A.H.Pri.Guady.D 20160429
Antiy-AVL Trojan[Ransom:HEUR]/AndroidOS.Fusob.4 20160502
Arcabit Android.Trojan.SLocker.BC 20160502
Avast Android:Locker-EW [Trj] 20160502
AVG Android/Deng.GOB 20160502
Avira (no cloud) ANDROID/Locker.BZ.Gen 20160502
Baidu-International Trojan.Win32.Agent.AaA 20160502
BitDefender Android.Trojan.SLocker.BC 20160502
CAT-QuickHeal Android.Fusob.D 20160502
Comodo UnclassifiedMalware 20160502
Cyren AndroidOS/GenBl.C77AD66A!Olympus 20160502
DrWeb Android.Locker.122.origin 20160502
Emsisoft Android.Trojan.SLocker.BC (B) 20160502
ESET-NOD32 a variant of Android/Locker.BV 20160502
F-Secure Trojan:Android/SLocker.BI 20160502
Fortinet Android/Locker.BV!tr 20160502
GData Android.Trojan.SLocker.BC 20160502
Ikarus Trojan.AndroidOS.Locker 20160502
K7GW Trojan ( 004c0f161 ) 20160502
Kaspersky HEUR:Trojan-Ransom.AndroidOS.Fusob.d 20160502
McAfee Artemis!C77AD66A4996 20160502
McAfee-GW-Edition Artemis 20160502
eScan Android.Trojan.SLocker.BC 20160502
NANO-Antivirus Trojan.Android.Ransom.drhbgw 20160502
Qihoo-360 Android mobile malware 20160502
Sophos AV Andr/PornLock-A 20160502
Tencent SH.!Android.GenA.10e3 20160502
Zoner Trojan.AndroidOS.Locker.A 20160502
AegisLab 20160502
ALYac 20160502
AVware 20160502
Baidu 20160429
Bkav 20160429
ClamAV 20160502
CMC 20160429
F-Prot 20160502
Jiangmin 20160502
K7AntiVirus 20160502
Kingsoft 20160502
Malwarebytes 20160502
Microsoft 20160502
nProtect 20160502
Panda 20160502
Rising 20160502
SUPERAntiSpyware 20160502
Symantec 20160502
TheHacker 20160502
TotalDefense 20160502
TrendMicro 20160502
TrendMicro-HouseCall 20160502
VBA32 20160502
VIPRE 20160502
ViRobot 20160502
Yandex 20160502
Zillya 20160502
The file being studied is Android related! APK Android file more specifically. The application's main package name is de.ramparts.fisheries. The internal version number of the application is 1. The displayed version string of the application is 1.0. The minimum Android API level for the application to run (MinSDKVersion) is 8. The target Android API level for the application to run (TargetSDKVersion) is 16.
Required permissions
android.permission.WRITE_CONTACTS (write contact data)
android.permission.ACCESS_FINE_LOCATION (fine (GPS) location)
android.permission.RECEIVE_BOOT_COMPLETED (automatically start at boot)
android.permission.READ_PHONE_STATE (read phone state and identity)
android.permission.SYSTEM_ALERT_WINDOW (display system-level alerts)
android.permission.PROCESS_OUTGOING_CALLS (intercept outgoing calls)
android.permission.ACCESS_NETWORK_STATE (view network status)
android.permission.ACCESS_COARSE_LOCATION (coarse (network-based) location)
android.permission.WAKE_LOCK (prevent phone from sleeping)
android.permission.GET_TASKS (retrieve running applications)
android.permission.READ_CALL_LOG (read the user's call log.)
android.permission.ACCESS_COARSE_UPDATES (Unknown permission from android reference)
android.permission.WRITE_SETTINGS (modify global system settings)
android.permission.CAMERA (take pictures and videos)
android.permission.INTERNET (full Internet access)
android.permission.READ_PROFILE (read the user's personal profile data)
android.permission.WRITE_EXTERNAL_STORAGE (modify/delete SD card contents)
android.permission.READ_CONTACTS (read contact data)
Activities
de.ramparts.fisheries.AdamActivity
de.ramparts.fisheries.TrilateralActivity
de.ramparts.fisheries.PsychosesActivity
de.ramparts.fisheries.AboriginesActivity
de.ramparts.fisheries.TwitteredActivity
Services
de.ramparts.fisheries.SwimwearService
de.ramparts.fisheries.PersonificationService
Receivers
de.ramparts.fisheries.Heels
de.ramparts.fisheries.Cocoons
Activity-related intent filters
de.ramparts.fisheries.AdamActivity
actions: android.intent.action.MAIN
categories: android.intent.category.LAUNCHER
Receiver-related intent filters
de.ramparts.fisheries.Cocoons
actions: android.app.action.DEVICE_ADMIN_ENABLED
de.ramparts.fisheries.Heels
actions: android.intent.action.BOOT_COMPLETED, android.intent.action.USER_PRESENT, android.intent.action.SCREEN_ON, android.intent.action.NEW_OUTGOING_CALL, android.intent.action.PHONE_STATE
Application certificate information
The file being studied is a compressed stream! Details about the compressed contents follow.
Contained files
Compression metadata
Contained files
10
Uncompressed size
70128
Highest datetime
2015-04-27 19:38:36
Lowest datetime
2015-04-27 19:38:32
Contained files by extension
xml
3
dex
1
MF
1
RSA
1
SF
1
png
1
Contained files by type
unknown
4
XML
3
DEX
1
HTML
1
PNG
1
File identification
MD5 c77ad66a499675c5794e32475ae7b989
SHA1 56b5427e10748d841e0e0c172b5da7f5dfc79a4b
SHA256 49a8c4f55e89a70480f1cb629e82e3d81d23962a3826b8c1f360d2425cd0d249
ssdeep
768:1ioxqgkqOKTXFRG+PLMu6Sm2BltUT6B7AUzJj8Wr9VNRya28lDwuHGFqE:1ugphWcltUeB7vN8e3RymlDwnFP

File size 37.8 KB ( 38656 bytes )
File type Android
Magic literal
Zip archive data, at least v2.0 to extract

TrID Java Archive (78.3%)
ZIP compressed archive (21.6%)
Tags
apk android

VirusTotal metadata
First submission 2015-05-03 21:14:13 UTC ( 2 years, 2 months ago )
Last submission 2015-05-03 21:14:13 UTC ( 2 years, 2 months ago )
File names get_player.php
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Started activities
#Intent;launchFlags=0x30000000;component=de.ramparts.fisheries/.PsychosesActivity;end
Started services
#Intent;component=de.ramparts.fisheries/.PersonificationService;end
#Intent;action=android.intent.action.BOOT_COMPLETED;component=de.ramparts.fisheries/.PersonificationService;end
Started receivers
android.intent.action.SCREEN_ON
android.intent.action.SCREEN_OFF
Opened files
/mnt/sdcard/Download
/data/data/de.ramparts.fisheries/files/phonograph.html
Accessed files
/data/data/de.ramparts.fisheries/files
/data/data/de.ramparts.fisheries/files/tilt.jpg
/data/data/de.ramparts.fisheries/files/thereon.apk
/data/data/de.ramparts.fisheries/files/phonograph.html
Interesting calls
Calls APIs that provide access to information about the telephony services on the device. Applications can use such methods to determine telephony services and states, as well as to access some types of subscriber information.
Contacted URLs
http://azureloop.in
646174613D6762447671454A38337054753343444E42463156664472714D4C6F6C41575967677A386D67306F5A504E51363552554E474E7455544559735A6D4D786C75616A56746D38654D61477646426E657A7A4A696F5F6445766C58505775504F5044653533774E534C7A417543385552417632504B4B5477627049394537636F696B74416B4D3051774E5947714B5347705441547A72486833557444617A425778756246324C4338327039316661526D396C4267724C38696977426C464D73554C50584D46654D333539526E6146396B586F5362514E7438415A706F3876546D6D63666C4E5846727242394B6E767731624A67586D4E6E45443953793447...
http://azureloop.in
646174613D5545784B763370327A6E46592D5A37624D7365396E7354726379395473557436595747303435466E36657A394F61437A7338546D6274535F45614D614C696552514D7446455063784A71426B4F394C7743562D715072486D446C77637476634754674F7655366F6E6E615659625335625942576F4A7251742D37365147646C766B56657064535973394B532D78533365576C4B6566357962354265726B6C53305A51754549697235462D743853725769335A4A6C663679376D48534E6434745A377544555533524674704142752D476C72416F45726A65484C74462D55564A5230344547454A66397846676A334B7155675447446C394D53707533...
http://azureloop.in
7265706F72743D657949784D434936496D3168615734694C4349784D794936496D466B5A434973496A5977496A7037496A457A496A6F784E5377694D5451694F6949304C6A41754E434973496A4578496A6F6961475679636D6C755A794973496A4579496A6F696332397164534973496A4D694F694A684E54686D4E545577595751334E5451354D44526B496977694D694936496A67304E4759794E474A6C4C575932593245744E475532595331694D6D55314C57466C4D5452694D446B775A474D784E534973496A4577496A6F6959334A6C63334276496977694D534936496A55754D534973496A41694F6949784D794973496A63694F694A7A5957317A64...