× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 5dc39515d0455ab3f55ed0d02e2c9e4cb28826891cea2c767d656dfd9a0448bc
File name: ahsan78ahsan.apk
Detection ratio: 19 / 57
Analysis date: 2015-05-21 21:10:24 UTC ( 3 years, 6 months ago )
Antivirus Result Update
Ad-Aware Android.Trojan.AndroRAT.E 20150521
AhnLab-V3 Android-Trojan/Sandrorat.c542 20150521
Alibaba A.W.Rog.EvilCert.A24 20150521
Avast Android:Kasandra-E [Trj] 20150521
AVG Android/Deng.JSY 20150521
Avira (no cloud) ANDROID/Spy.Kasandra.A.Gen 20150521
BitDefender Android.Trojan.AndroRAT.E 20150521
CAT-QuickHeal Android.Sandr.A 20150520
Cyren AndroidOS/Sandr.A.gen!Eldorado 20150521
DrWeb Android.Spy.184.origin 20150521
Emsisoft Android.Trojan.AndroRAT.E (B) 20150521
ESET-NOD32 a variant of Android/Spy.Kasandra.C 20150521
F-Secure Android.Trojan.AndroRAT.E 20150521
GData Android.Trojan.AndroRAT.E 20150521
Ikarus Spyware.AndroidOS.Kasandra 20150521
Kaspersky HEUR:Trojan-Spy.AndroidOS.Sandr.a 20150521
eScan Android.Trojan.AndroRAT.E 20150521
NANO-Antivirus Trojan.Android.Zerat.dekxmy 20150521
Sophos AV Andr/SandRat-B 20150521
AegisLab 20150521
Yandex 20150521
ALYac 20150521
Antiy-AVL 20150521
AVware 20150521
Baidu-International 20150521
Bkav 20150521
ByteHero 20150521
ClamAV 20150521
CMC 20150520
Comodo 20150521
F-Prot 20150521
Fortinet 20150521
Jiangmin 20150519
K7AntiVirus 20150521
K7GW 20150521
Kingsoft 20150521
Malwarebytes 20150521
McAfee 20150521
McAfee-GW-Edition 20150521
Microsoft 20150521
Norman 20150521
nProtect 20150521
Panda 20150521
Qihoo-360 20150521
Rising 20150521
SUPERAntiSpyware 20150521
Symantec 20150521
Tencent 20150521
TheHacker 20150521
TotalDefense 20150521
TrendMicro 20150521
TrendMicro-HouseCall 20150521
VBA32 20150521
VIPRE 20150521
ViRobot 20150521
Zillya 20150521
Zoner 20150521
The file being studied is Android related! APK Android file more specifically. The application's main package name is net.droidjack.server. The internal version number of the application is 1. The displayed version string of the application is 1.0. The minimum Android API level for the application to run (MinSDKVersion) is 8. The target Android API level for the application to run (TargetSDKVersion) is 17.
Risk summary
The studied DEX file makes use of API reflection
The studied DEX file makes use of cryptographic functions
Permissions that allow the application to manipulate SMS
Permissions that allow the application to manipulate your location
Permissions that allow the application to perform payments
Permissions that allow the application to access Internet
Permissions that allow the application to access private information
Other permissions that could be considered as dangerous in certain scenarios
Required permissions
android.permission.CHANGE_NETWORK_STATE (change network connectivity)
android.permission.ACCESS_COARSE_LOCATION (coarse (network-based) location)
android.permission.ACCESS_WIFI_STATE (view Wi-Fi status)
android.permission.INTERNET (full Internet access)
android.permission.ACCESS_FINE_LOCATION (fine (GPS) location)
android.permission.SEND_SMS (send SMS messages)
android.permission.WRITE_SMS (edit SMS or MMS)
android.permission.ACCESS_NETWORK_STATE (view network status)
android.permission.WRITE_CALL_LOG (write (but not read) the user's contacts data.)
android.permission.GET_TASKS (retrieve running applications)
android.permission.READ_CALL_LOG (read the user's call log.)
com.android.browser.permission.READ_HISTORY_BOOKMARKS (read Browser's history and bookmarks)
android.permission.WRITE_EXTERNAL_STORAGE (modify/delete SD card contents)
android.permission.RECORD_AUDIO (record audio)
android.permission.WRITE_CONTACTS (write contact data)
android.permission.READ_EXTERNAL_STORAGE (read from external storage)
android.permission.RECEIVE_BOOT_COMPLETED (automatically start at boot)
android.permission.CALL_PHONE (directly call phone numbers)
android.permission.READ_PHONE_STATE (read phone state and identity)
android.permission.READ_SMS (read SMS or MMS)
android.permission.CAMERA (take pictures and videos)
android.permission.WAKE_LOCK (prevent phone from sleeping)
android.permission.CHANGE_WIFI_STATE (change Wi-Fi status)
android.permission.RECEIVE_SMS (receive SMS)
android.permission.READ_CONTACTS (read contact data)
android.permission.GET_ACCOUNTS (discover known accounts)
Permission-related API calls
FACTORY_TEST
GET_TASKS
ACCESS_NETWORK_STATE
RECORD_AUDIO
READ_LOGS
SEND_SMS
ACCESS_WIFI_STATE
CAMERA
INTERNET
READ_CONTACTS
CHANGE_COMPONENT_ENABLED_STATE
READ_PHONE_STATE
WRITE_HISTORY_BOOKMARKS
ACCESS_FINE_LOCATION
WAKE_LOCK
Main Activity
net.droidjack.server.MainActivity
Activities
net.droidjack.server.MainActivity
net.droidjack.server.CamSnap
net.droidjack.server.VideoCap
Services
net.droidjack.server.Controller
net.droidjack.server.GPSLocation
net.droidjack.server.Toaster
Receivers
net.droidjack.server.Connector
net.droidjack.server.CallListener
Activity-related intent filters
net.droidjack.server.CamSnap
actions: android.intent.action.CAMSNAP
categories: android.intent.category.DEFAULT
net.droidjack.server.MainActivity
actions: android.intent.action.MAIN
categories: android.intent.category.LAUNCHER
net.droidjack.server.VideoCap
actions: android.intent.action.VIDEOCAP
categories: android.intent.category.DEFAULT
Receiver-related intent filters
net.droidjack.server.Connector
actions: android.net.conn.CONNECTIVITY_CHANGE, android.intent.action.BOOT_COMPLETED
net.droidjack.server.CallListener
actions: android.intent.action.PHONE_STATE
Application certificate information
Application bundle files
File identification
MD5 0445a9eb4b5926aa612a98a884dbeae5
SHA1 504f17dbf182c391d1e6207e3f0cedf82ad47b16
SHA256 5dc39515d0455ab3f55ed0d02e2c9e4cb28826891cea2c767d656dfd9a0448bc
ssdeep
6144:S48syD7pd/T8HyD8nV60nn7FxABx+/eUBk3QQpF55b:NOD7D/1Ozn7Fxux+/xWAmF55b

File size 211.0 KB ( 216031 bytes )
File type Android
Magic literal
Zip archive data, at least v2.0 to extract

TrID Android Package (92.9%)
ZIP compressed archive (7.0%)
Tags
apk android

VirusTotal metadata
First submission 2015-05-21 21:10:24 UTC ( 3 years, 6 months ago )
Last submission 2015-05-21 21:10:24 UTC ( 3 years, 6 months ago )
File names ahsan78ahsan.apk
ExifTool file metadata
MIMEType
application/zip

ZipRequiredVersion
20

ZipCRC
0x2cf8cd0b

FileType
ZIP

ZipCompression
Deflated

ZipUncompressedSize
758

ZipCompressedSize
409

FileTypeExtension
zip

ZipFileName
META-INF/MANIFEST.MF

ZipBitFlag
0x0808

ZipModifyDate
2015:05:21 08:44:21

No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Started services
#Intent;component=net.droidjack.server/.Controller;end