Managed XDR

telegram_enstr.apk — malware analysis report

File info

Filename
telegram_enstr.apk
File type
Zip archive data, at least v2.0 to extract
File size
6.2 MB
First seen
Last seen

Environment

droid7/x86 ru

Hashes

SHA1
0be1d22a2e83101495d98447959e02ed85a4bee7
SHA256
5106fddfbb73a082436bcef847d5068cd5aea7e431adf28af4072b0173cd1222
MD5
1d929528112a91db4891503a5be55ba7

Signatures

Other

device_admin: Asks for device admin rights
metrics: Be used to get information from the screen
is_device_admin: Check accessibility - device admin
dynamic_load: Uses undocumented methods to load apk/dex/classes
acquire: Acquires the wake lock
accessibility_event: Intercepting Accessibility Events
super_user: Checks root access
wake_lock: Creates a new wake lock
telephony_getsimcountryiso: Access country code of SIM
ignoring_battery: Checks accessibility - unlimeted access to power options
power_vendor: Unlimited access to individual vendor power settings
reflection: Uses reflection
wifi_info: Gets wifi connections data
media_recorder: Using the MediaRecorder
register_receiver: Registers broadcast receiver
browsed_history: Reads web browser history
network: Checks internet connection
exit_system: Terminates current Java VM
read_or_write_global_settings: Read or write global settings
shared_prefs: Uses shared preferences
change_state_wifi_signature: Changes the state of Wi-Fi connection
read_or_write_system_settings: Read or write system settings
start_activity: Starts activity
load_jni_lib: Loads native library
start_service: Starts service
connect: Opening a connection
access_network_state: Network state access
read_or_write_secure_settings: Read or write secure settings
change_screen_status: Display status is changed
notify: Attempts to create a notification