× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 9d215103ddbd19f7b64837afe5c94b6aefbbd4b301b7b9df2abc6584708b8a56
File name: vti-rescan
Detection ratio: 0 / 55
Analysis date: 2016-02-21 16:16:34 UTC ( 3 years ago ) View latest
Antivirus Result Update
Ad-Aware 20160221
AegisLab 20160221
Yandex 20160220
AhnLab-V3 20160221
Alibaba 20160221
Antiy-AVL 20160221
Arcabit 20160221
Avast 20160221
AVG 20160221
Avira (no cloud) 20160221
AVware 20160221
Baidu-International 20160221
BitDefender 20160221
Bkav 20160220
ByteHero 20160221
CAT-QuickHeal 20160220
ClamAV 20160221
CMC 20160219
Comodo 20160221
Cyren 20160221
DrWeb 20160221
Emsisoft 20160221
ESET-NOD32 20160221
F-Prot 20160221
F-Secure 20160219
Fortinet 20160220
GData 20160221
Ikarus 20160221
Jiangmin 20160221
K7AntiVirus 20160221
K7GW 20160221
Kaspersky 20160221
Malwarebytes 20160221
McAfee 20160221
McAfee-GW-Edition 20160220
Microsoft 20160221
eScan 20160221
NANO-Antivirus 20160221
nProtect 20160219
Panda 20160221
Qihoo-360 20160221
Rising 20160221
Sophos AV 20160221
SUPERAntiSpyware 20160221
Symantec 20160221
Tencent 20160221
TheHacker 20160217
TotalDefense 20160221
TrendMicro 20160221
TrendMicro-HouseCall 20160221
VBA32 20160220
VIPRE 20160221
ViRobot 20160221
Zillya 20160219
Zoner 20160221
The file being studied is Android related! APK Android file more specifically. The application's main package name is de.lotum.whatsinthefoto.us. The internal version number of the application is 54. The displayed version string of the application is 4.8.0-en. The minimum Android API level for the application to run (MinSDKVersion) is 8. The target Android API level for the application to run (TargetSDKVersion) is 16.
Required permissions
com.google.android.c2dm.permission.RECEIVE (Unknown permission from android reference)
android.permission.ACCESS_WIFI_STATE (view Wi-Fi status)
android.permission.WAKE_LOCK (prevent phone from sleeping)
android.permission.ACCESS_NETWORK_STATE (view network status)
android.permission.INTERNET (full Internet access)
de.lotum.whatsinthefoto.us.permission.C2D_MESSAGE (C2DM permission.)
android.permission.WRITE_EXTERNAL_STORAGE (modify/delete SD card contents)
com.android.vending.BILLING (Unknown permission from android reference)
android.permission.GET_ACCOUNTS (discover known accounts)
Activities
de.lotum.whatsinthefoto.activity.Splash
de.lotum.whatsinthefoto.activity.Quiz
de.lotum.whatsinthefoto.activity.Main
de.lotum.whatsinthefoto.activity.Imprint
de.lotum.whatsinthefoto.activity.Settings
de.lotum.whatsinthefoto.activity.Shop
de.lotum.whatsinthefoto.activity.Premium
com.facebook.LoginActivity
com.facebook.ads.InterstitialAdActivity
com.gamesforfriends.cps.internal.CpsActivity
com.mopub.mobileads.MoPubActivity
com.mopub.common.MoPubBrowser
com.mopub.mobileads.MraidActivity
com.mopub.mobileads.MraidVideoPlayerActivity
com.vungle.sdk.VungleAdvert
com.inmobi.androidsdk.IMBrowserActivity
com.millennialmedia.android.MMActivity
com.millennialmedia.android.VideoPlayer
com.video.adsdk.internal.ADActivity
com.google.android.gms.ads.AdActivity
com.unity3d.ads.android.view.UnityAdsFullscreenActivity
com.sponsorpay.publisher.ofw.SPOfferWallActivity
Receivers
com.adjust.sdk.ReferrerReceiver
de.lotum.whatsinthefoto.adapter.LetterReceiver
de.lotum.whatsinthefoto.adapter.BonusPuzzleReceiver
de.lotum.whatsinthefoto.adapter.EventGiftReceiver
com.sponsorpay.advertiser.InstallReferrerReceiver
Providers
de.lotum.whatsinthefoto.adapter.ShareFileProvider
Activity-related intent filters
de.lotum.whatsinthefoto.activity.Splash
actions: android.intent.action.MAIN
categories: android.intent.category.LAUNCHER
Receiver-related intent filters
com.sponsorpay.advertiser.InstallReferrerReceiver
actions: com.android.vending.INSTALL_REFERRER
com.adjust.sdk.ReferrerReceiver
actions: com.android.vending.INSTALL_REFERRER
Application certificate information
Interesting strings
The file being studied is a compressed stream! Details about the compressed contents follow.
Contained files
Compression metadata
Contained files
5369
Uncompressed size
3224866
Highest datetime
2015-04-17 11:47:50
Lowest datetime
2015-04-16 15:59:48
Contained files by extension
jpg
999
xml
1
Contained files by type
JPG
999
XML
1
File identification
MD5 eb00950c3667ae1736d5c7e3397efa42
SHA1 62cfbdd8a191a921c380bb1e8dd8ebac2f67793b
SHA256 9d215103ddbd19f7b64837afe5c94b6aefbbd4b301b7b9df2abc6584708b8a56
ssdeep
393216:MfoJewHE4r4OKZtt7vvs7x5U2MB3fduZ9EO/++X9xWP7G5o61DF:yZHvvg5ULB3lKVDWD41x

File size 23.5 MB ( 24636472 bytes )
File type Android
Magic literal
Zip archive data, at least v2.0 to extract

TrID Android Package (62.1%)
Java Archive (17.1%)
BlueEyes Animation (15.9%)
ZIP compressed archive (4.7%)
Tags
apk android software-collection

VirusTotal metadata
First submission 2015-04-17 17:00:24 UTC ( 3 years, 11 months ago )
Last submission 2016-10-05 21:04:36 UTC ( 2 years, 5 months ago )
File names 4-pics-1-word.apk
4-pics-1-word-4-8-0-en-multi-android.apk
4-pics-1-word.apk
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!
Started receivers
android.intent.action.ACTION_POWER_CONNECTED
android.intent.action.ACTION_POWER_DISCONNECTED
android.net.conn.CONNECTIVITY_CHANGE
Opened files
/data/data/de.lotum.whatsinthefoto.us/files/whatsapp_share
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/session_analytics.tap.tmp
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/5074593C0216-0001-05E3-E3F979909F2DBeginSession.cls_temp
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/5074593C0216-0001-05E3-E3F979909F2DSessionApp.cls_temp
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/5074593C0216-0001-05E3-E3F979909F2DSessionOS.cls_temp
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/5074593C0216-0001-05E3-E3F979909F2DSessionDevice.cls_temp
/data/data/de.lotum.whatsinthefoto.us/files/.YFlurrySenderIndex.info.AnalyticsMain
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/session_analytics_to_send
APP_ASSETS/photodata.txt
/data/data/de.lotum.whatsinthefoto.us/files
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/session_analytics.tap
/data
Accessed files
/data/data/de.lotum.whatsinthefoto.us/files
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/session_analytics.tap
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/session_analytics_to_send
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/crash_marker
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/initialization_marker
/system/app/Superuser.apk
/system/xbin/su
/data/data/de.lotum.whatsinthefoto.us/files/.FlurrySenderIndex.info.AnalyticsMain
/data/data/de.lotum.whatsinthefoto.us/files/.YFlurrySenderIndex.info.AnalyticsMain
/proc/meminfo
/data/data/de.lotum.whatsinthefoto.us/files/solved.txt
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/invalidClsFiles
/data/data/de.lotum.whatsinthefoto.us/files/.TwitterSdk/v/com.crashlytics.sdk.android/com.crashlytics.settings.json
Interesting calls
Calls APIs that provide access to information about the telephony services on the device. Applications can use such methods to determine telephony services and states, as well as to access some types of subscriber information.
Contacted URLs
https://settings.crashlytics.com/spi/v2/platforms/android/apps/de.lotum.whatsinthefoto.us/settings?instance=029a8f9cd542fd2b329ff1cc57c48e52d4c24fa6&source=1&build_version=54&icon_hash=f0f3e7d49754ff1bea43142c2d663683dcc82792&display_version=4.8.0-en