× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 7d30ae696667bfc8a963f48a8359257148ca4e9d0ff83ece942d2b770def0143
File name: app-debug.apk
Detection ratio: 2 / 59
Analysis date: 2017-05-24 16:21:28 UTC ( 1 year, 10 months ago )
Antivirus Result Update
Avira (no cloud) ANDROID/Spy.Overlay.A.Gen 20170524
WhiteArmor PUP.HighConfidence 20170524
Ad-Aware 20170524
AegisLab 20170524
AhnLab-V3 20170524
Alibaba 20170524
ALYac 20170524
Antiy-AVL 20170524
Arcabit 20170524
Avast 20170524
AVG 20170524
AVware 20170524
BitDefender 20170524
Bkav 20170524
CAT-QuickHeal 20170524
ClamAV 20170524
CMC 20170523
Comodo 20170524
CrowdStrike Falcon (ML) 20170130
Cyren 20170524
DrWeb 20170524
Emsisoft 20170524
Endgame 20170515
ESET-NOD32 20170524
F-Prot 20170524
F-Secure 20170524
Fortinet 20170524
GData 20170524
Ikarus 20170524
Sophos ML 20170519
Jiangmin 20170524
K7AntiVirus 20170524
K7GW 20170524
Kaspersky 20170524
Kingsoft 20170524
Malwarebytes 20170524
McAfee 20170524
McAfee-GW-Edition 20170524
Microsoft 20170524
eScan 20170524
NANO-Antivirus 20170524
nProtect 20170524
Palo Alto Networks (Known Signatures) 20170524
Panda 20170524
Qihoo-360 20170524
Rising 20170524
SentinelOne (Static ML) 20170516
Sophos AV 20170524
SUPERAntiSpyware 20170524
Symantec 20170524
Symantec Mobile Insight 20170524
Tencent 20170524
TheHacker 20170522
TrendMicro 20170524
TrendMicro-HouseCall 20170524
Trustlook 20170524
VBA32 20170524
VIPRE 20170524
ViRobot 20170524
Webroot 20170524
Yandex 20170518
Zillya 20170524
ZoneAlarm by Check Point 20170524
Zoner 20170524
The file being studied is Android related! APK Android file more specifically. The application's main package name is com.geeksonsecurity.malwaredemo. The internal version number of the application is 2. The displayed version string of the application is 1.1. The minimum Android API level for the application to run (MinSDKVersion) is 14. The target Android API level for the application to run (TargetSDKVersion) is 22.
Required permissions
android.permission.GET_TASKS (retrieve running applications)
android.permission.RECEIVE_BOOT_COMPLETED (automatically start at boot)
android.permission.SYSTEM_ALERT_WINDOW (display system-level alerts)
Activities
com.geeksonsecurity.malwaredemo.MainActivity
com.geeksonsecurity.malwaredemo.OverlayActivity
Services
com.geeksonsecurity.malwaredemo.MainService
Receivers
com.geeksonsecurity.malwaredemo.BootReceiver
Activity-related intent filters
com.geeksonsecurity.malwaredemo.MainActivity
actions: android.intent.action.MAIN
categories: android.intent.category.LAUNCHER
Receiver-related intent filters
com.geeksonsecurity.malwaredemo.BootReceiver
actions: android.intent.action.BOOT_COMPLETED
Application certificate information
The file being studied is a compressed stream! Details about the compressed contents follow.
Contained files
Compression metadata
Contained files
296
Uncompressed size
2282395
Highest datetime
2017-05-24 19:20:06
Lowest datetime
2017-05-24 19:19:08
Contained files by extension
png
203
xml
88
dex
1
MF
1
RSA
1
SF
1
Contained files by type
PNG
203
XML
88
unknown
4
DEX
1
File identification
MD5 738241cf77fa20e5bcc8de6d0e521d90
SHA1 4b094aa5147db817325b8432c4425bc223bbde77
SHA256 7d30ae696667bfc8a963f48a8359257148ca4e9d0ff83ece942d2b770def0143
ssdeep
24576:Xrj+IAPUzJvmIvO8PojWYAh9Vd5Bh4wQH/VobWEuYSogJbFb1nV+5tuh0:7SPI9mMO8Poji9Vd5f4xobblPgJbF6T

File size 1.2 MB ( 1241491 bytes )
File type Android
Magic literal
Zip archive data, at least v2.0 to extract

TrID Android Package (73.9%)
Java Archive (20.4%)
ZIP compressed archive (5.6%)
Tags
apk android via-tor

VirusTotal metadata
First submission 2017-05-24 16:21:28 UTC ( 1 year, 10 months ago )
Last submission 2017-05-24 16:21:28 UTC ( 1 year, 10 months ago )
File names app-debug.apk
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!