× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 7a9f8112a34bc34cb287c79ba7853b2d7c8822951be4ecb85970510949b752cb
File name: 9-62eebb7d338ad0c8252c7c29ef22b3e6-1434657691.apk
Detection ratio: 0 / 57
Analysis date: 2016-04-17 13:11:23 UTC ( 2 years, 11 months ago ) View latest
Antivirus Result Update
Ad-Aware 20160417
AegisLab 20160417
AhnLab-V3 20160416
Alibaba 20160415
ALYac 20160417
Antiy-AVL 20160416
Arcabit 20160417
Avast 20160417
AVG 20160417
Avira (no cloud) 20160416
AVware 20160417
Baidu 20160416
Baidu-International 20160416
BitDefender 20160417
Bkav 20160415
CAT-QuickHeal 20160416
ClamAV 20160417
CMC 20160415
Comodo 20160416
Cyren 20160417
DrWeb 20160417
Emsisoft 20160417
ESET-NOD32 20160416
F-Prot 20160417
F-Secure 20160417
Fortinet 20160417
GData 20160417
Ikarus 20160416
Jiangmin 20160417
K7AntiVirus 20160417
K7GW 20160417
Kaspersky 20160417
Kingsoft 20160417
Malwarebytes 20160417
McAfee 20160417
McAfee-GW-Edition 20160416
Microsoft 20160417
eScan 20160417
NANO-Antivirus 20160417
nProtect 20160415
Panda 20160416
Qihoo-360 20160417
Rising 20160417
Sophos AV 20160417
SUPERAntiSpyware 20160417
Symantec 20160417
Tencent 20160417
TheHacker 20160416
TotalDefense 20160417
TrendMicro 20160417
TrendMicro-HouseCall 20160417
VBA32 20160415
VIPRE 20160417
ViRobot 20160417
Yandex 20160416
Zillya 20160416
Zoner 20160417
The file being studied is Android related! APK Android file more specifically. The application's main package name is com.gameloft.android.ANMP.GloftGZHM. The internal version number of the application is 10120. The displayed version string of the application is 1.0.1a. The minimum Android API level for the application to run (MinSDKVersion) is 14. The target Android API level for the application to run (TargetSDKVersion) is 21.
Required permissions
android.permission.VIBRATE (control vibrator)
android.permission.READ_EXTERNAL_STORAGE (read from external storage)
android.permission.RECEIVE_BOOT_COMPLETED (automatically start at boot)
com.gameloft.android.ANMP.GloftGZHM.permission.C2D_MESSAGE (C2DM permission.)
glshare.permission.ACCESS_SHARED_DATA (Unknown permission from android reference)
com.google.android.c2dm.permission.RECEIVE (Unknown permission from android reference)
android.permission.ACCESS_WIFI_STATE (view Wi-Fi status)
android.permission.WAKE_LOCK (prevent phone from sleeping)
android.permission.ACCESS_NETWORK_STATE (view network status)
android.permission.INTERNET (full Internet access)
com.android.vending.CHECK_LICENSE (Unknown permission from android reference)
android.permission.WRITE_EXTERNAL_STORAGE (modify/delete SD card contents)
com.android.vending.BILLING (Unknown permission from android reference)
android.permission.GET_ACCOUNTS (discover known accounts)
Activities
com.gameloft.android.ANMP.GloftGZHM.MainActivity
com.gameloft.android.ANMP.GloftGZHM.installer.GameInstaller
com.gameloft.android.ANMP.GloftGZHM.iab.GMPActivity
com.gameloft.android.ANMP.GloftGZHM.IGPFreemiumActivity
com.gameloft.android.ANMP.GloftGZHM.InGameBrowser
com.gameloft.android.ANMP.GloftGZHM.ParseDeepLinkActivity
com.facebook.LoginActivity
com.renren.mobile.rmsdk.oauth.auth.OAuthActivity
com.renren.mobile.rmsdk.oauth.auth.ChooseAccountActivity
com.renren.mobile.rmsdk.component.share.ShareActivity
com.renren.mobile.rmsdk.component.share.ChooseFriendActivity
com.gameloft.GLSocialLib.VK.VKLoginActivity
com.gameloft.GLSocialLib.kakao.KakaoGamePostStoryActivity
Services
com.google.android.gms.analytics.CampaignTrackingService
com.gameloft.android.ANMP.GloftGZHM.GCMIntentService
Receivers
com.google.android.gcm.GCMBroadcastReceiver
com.gameloft.android.ANMP.GloftGZHM.PushNotification.LocalPushReceiver
com.gameloft.android.ANMP.GloftGZHM.PushNotification.PushIntentReceiver
com.gameloft.android.ANMP.GloftGZHM.PushNotification.PushDeleteReceiver
com.gameloft.android.ANMP.GloftGZHM.GLUtils.NetworkStateReceiver
com.gameloft.android.ANMP.GloftGZHM.BootCompletedReceiver
com.gameloft.android.ANMP.GloftGZHM.installer.IReferrerReceiver
com.gameloft.android.ANMP.GloftGZHM.ApplicationSetUp
Providers
com.gameloft.android.ANMP.GloftGZHM.KeyProvider
Activity-related intent filters
com.gameloft.android.ANMP.GloftGZHM.ParseDeepLinkActivity
actions: com.google.android.apps.plus.VIEW_DEEP_LINK
categories: android.intent.category.DEFAULT, android.intent.category.BROWSABLE
com.gameloft.android.ANMP.GloftGZHM.MainActivity
actions: android.intent.action.MAIN
categories: android.intent.category.LAUNCHER
com.gameloft.android.ANMP.GloftGZHM.IGPFreemiumActivity
actions: android.intent.action.MAIN
Receiver-related intent filters
com.google.android.gcm.GCMBroadcastReceiver
actions: com.google.android.c2dm.intent.RECEIVE, com.google.android.c2dm.intent.REGISTRATION
categories: com.gameloft.android.ANMP.GloftGZHM
com.gameloft.android.ANMP.GloftGZHM.BootCompletedReceiver
actions: android.intent.action.BOOT_COMPLETED
categories: android.intent.category.DEFAULT
com.gameloft.android.ANMP.GloftGZHM.ApplicationSetUp
actions: com.gameloft.android.ApplicationSetUp
com.gameloft.android.ANMP.GloftGZHM.installer.IReferrerReceiver
actions: com.android.vending.INSTALL_REFERRER
com.gameloft.android.ANMP.GloftGZHM.PushNotification.PushIntentReceiver
actions: com.gameloft.android.ANMP.GloftGZHM.PNBroadcast
com.gameloft.android.ANMP.GloftGZHM.PushNotification.LocalPushReceiver
actions: android.intent.action.BOOT_COMPLETED
com.gameloft.android.ANMP.GloftGZHM.PushNotification.PushDeleteReceiver
actions: com.gameloft.android.ANMP.GloftGZHM.PNDeleteBroadcast
com.gameloft.android.ANMP.GloftGZHM.GLUtils.NetworkStateReceiver
actions: android.net.conn.CONNECTIVITY_CHANGE
Application certificate information
Interesting strings
The file being studied is a compressed stream! Details about the compressed contents follow.
Interesting properties
The file under inspection contains at least one ELF file.
Contained files
Compression metadata
Contained files
400
Uncompressed size
57632389
Highest datetime
2015-03-06 20:03:26
Lowest datetime
2015-02-09 13:05:36
Contained files by extension
png
296
xml
88
so
4
txt
4
bin
1
MF
1
RSA
1
dex
1
wav
1
SF
1
Contained files by type
PNG
296
XML
86
unknown
13
ELF
4
DEX
1
File identification
MD5 62eebb7d338ad0c8252c7c29ef22b3e6
SHA1 b7fa18f1ee19342d79a69c1e8671240bbe993b6e
SHA256 7a9f8112a34bc34cb287c79ba7853b2d7c8822951be4ecb85970510949b752cb
ssdeep
393216:LSrOTNN0+P3v642T7m6hdERXZ7kB+/B6rQEsyGqoEJXa5vIRoRij0N:LkOTNN0+P3jkKYd3mghDtoEJXa5vI6h

File size 21.2 MB ( 22183856 bytes )
File type Android
Magic literal
Zip archive data, at least v2.0 to extract

TrID Android Package (73.9%)
Java Archive (20.4%)
ZIP compressed archive (5.6%)
Tags
apk android contains-elf software-collection

VirusTotal metadata
First submission 2015-03-10 13:07:24 UTC ( 4 years ago )
Last submission 2016-10-30 02:11:48 UTC ( 2 years, 4 months ago )
File names sibadazhanjimyzb.apk
b4fd315ac23d6a1e5831abb840ca4aeeb6d37eed9a6e80e873946c77eefb7397244029f338b43d8e076868e2e2a4123abf3c5156e177917968e1bda390049798
9-62eebb7d338ad0c8252c7c29ef22b3e6-1434634818.apk
9-62eebb7d338ad0c8252c7c29ef22b3e6-1434657691.apk
Age-of-Sparta.apk
9-62eebb7d338ad0c8252c7c29ef22b3e6-1434655636.apk
age-of-sparta.apk
9-62eebb7d338ad0c8252c7c29ef22b3e6-1434657691.apk
age-of-sparta-1.0.1a.apk
62eebb7d338ad0c8252c7c29ef22b3e6.tmp.5683
age-of-sparta-1-0-1a-multi-android.apk
com.gameloft.android.ANMP.GloftGZHM.apk
7a9f8112a34bc34cb287c79ba7853b2d7c8822951be4ecb85970510949b752cb
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Permissions checked
glshare.permission.ACCESS_SHARED_DATA:com.gameloft.android.ANMP.GloftGZHM
Started receivers
com.gameloft.android.ANMP.GloftGZHM_pushbroadcast
Opened files
/data/data/com.gameloft.android.ANMP.GloftGZHM/files/gaClientId
/sdcard/Android/data/com.gameloft.android.ANMP.GloftGZHM/files
/mnt/sdcard/Android/data/com.gameloft.android.ANMP.GloftGZHM/files
/mnt/sdcard
/mnt/sdcard/Android/obb/com.gameloft.android.ANMP.GloftGZHM
/data/data/com.gameloft.android.ANMP.GloftGZHM/files
/data/data/com.gameloft.android.ANMP.GloftGZHM/cache
Accessed files
/data/data/com.gameloft.android.ANMP.GloftGZHM/files
/sdcard/Android/data/com.gameloft.android.ANMP.GloftGZHM/files
/data/data/com.gameloft.android.ANMP.GloftGZHM/databases/PN.db
/mnt/sdcard/Android/data/com.gameloft.android.ANMP.GloftGZHM/files/qaTestingConfigs.txt
/data/data/com.gameloft.android.ANMP.GloftGZHM/app_renrenerror/error.xml
/proc/cpuinfo
Interesting calls
Calls APIs that provide access to information about the telephony services on the device. Applications can use such methods to determine telephony services and states, as well as to access some types of subscriber information.
Contacted URLs
http://confirmation.gameloft.com/freemium/content/
Accessed URIs
content://com.gameloft.android.ANMP.GloftGZHM.KeyProvider/key
content://com.gameloft.android.ANMP.GloftGZHM.KeyProvider/key/