Managed XDR

googleplay.apk — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
googleplay.apk
Тип файла
Zip archive data, at least v2.0 to extract
Размер файла
1.5 MB
Первое обнаружение
Последнее обнаружение

Окружение

droid7/x86 ru

Хеши

SHA1
4664c233205d2915ffc3c27fcc8fd6cb0e336a64
SHA256
8a962882571ce88c874e5478c0278841053aa72738e4f4bb57249fc10a37afd8
MD5
337b8033a34ebc3138da6e6e3cd40944

Сигнатуры

Other

coper: Coper banking trojan
dexclassloader: Uses class loader to executre dynamic code
metrics: Be used to get information from the screen
is_device_admin: Check accessibility - device admin
dynamic_load: Uses undocumented methods to load apk/dex/classes
acquire: Acquires the wake lock
skip_main_activity: Abort loading MainActivity
accessibility_event: Intercepting Accessibility Events
super_user: Checks root access
get_line1_num: Gets phone number
wake_lock: Creates a new wake lock
telephony_getsimcountryiso: Access country code of SIM
dex_elements: Modifies classes path (possibly, dynamic code loading)
reflection: Uses reflection
framework_check: Checks frida/xposed/substrate
wifi_info: Gets wifi connections data
sim_operator_name: Fetches SIM-SPN
register_receiver: Registers broadcast receiver
browsed_history: Reads web browser history
send_sms: Sends http request
network: Checks internet connection
read_or_write_global_settings: Read or write global settings
shared_prefs: Uses shared preferences
change_state_wifi_signature: Changes the state of Wi-Fi connection
read_or_write_system_settings: Read or write system settings
trowable: Throwable exceptions
start_activity: Starts activity
load_jni_lib: Loads native library
start_service: Starts service
keyguard_manager: Interaction with Keyguard Manager
alarm_manager: Sets a timer
access_network_state: Network state access
read_or_write_secure_settings: Read or write secure settings
notify: Attempts to create a notification