Malicious
17
/59
Threat
Analyzed on 2021-12-31T08:55:09.943092
MD5 | 848ed096d641e9c2861f29eee353d992 | |
SHA1 | c1af6b078c278f6d1886ec3108ab5a0ade4c25f4 | |
SHA256 | 000b9d0a7ea4e612958389d5d7a6e32a256f4af60087b06254314f98632d2107 | |
Size | 4.14MB |
Information computed with APKiD.
/tmp/tmptny4oua1!classes.dex | |
anti_vm |
|
compiler |
|
/tmp/tmptny4oua1!extra/__pasys_remote_banner.jar!classes.dex | |
anti_vm |
|
compiler |
|
Information computed with ssdeep.
APK file | 98304:B0PeY7cUez3Qe0Tk2Rq0uq72HvpkLC8fKD4pyWQOwzc//jIeEDvdl6fC3:GTGRkLCtC1QOwzcDIea | |
Manifest | 192:CmsnqpeOgSgWywWUh3mVrAk1ozOQAurQQWUl1bi02CBK/+GxgtPfpXL+QVlRxjkO:… | |
classes.dex | 49152:bKYn1fCfmuLFwLtMY+Ge000002fZ5Qrl4Xoo:51fCfmuLFwLtMYBe000002fnQZo |
Information computed with Dexofuzzy.
APK file | 3072:vKSYN98ThpBX2lUw+80jsCYkKzr7IicpzlSx55x0:6N96uPk/izrZiz5 | |
classes.dex | 3072:vKSYN98ThpBX2lUw+80jsCYkKzr7IicpzlSx55x0:6N96uPk/izrZiz5 |
Information computed with AndroGuard and Pithus.
Package | com.onlyeejk.kaoyango | |
App name | 考研go | |
Version name | 2.3 | |
Version code | 5 | |
SDK | 8 - 19 | |
UAID | 79f290bf1be85eef12e38d5cd153692388823e70 | |
Signature | Signature V1 | |
Frosting | Not frosted |
Information computed with AndroGuard.
Information computed with MobSF.
Medium | Application Data can be Backed up[android:allowBackup=true] This flag allows anyone to backup your application data via adb. It allows users who have enabled USB debugging to copy application data off of the device. |
High | Broadcast Receiver (com.onlyeejk.kaoyango.notification.AlarmForNotification) is not Protected.An intent-filter exists. A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Broadcast Receiver is explicitly exported. |
High | Broadcast Receiver (com.onlyeejk.kaoyango.notification.AutoStart) is not Protected.An intent-filter exists. A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Broadcast Receiver is explicitly exported. |
High | Broadcast Receiver (com.onlyeejk.kaoyango.widget.CountDownWidgetProvider) is not Protected.An intent-filter exists. A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Broadcast Receiver is explicitly exported. |
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Oldest file found in APK | March 15, 2014, 1:08 p.m. |
Certificate valid not before | July 20, 2014, 3:51 p.m. |
Latest file found in APK | July 20, 2014, 11:54 p.m. |
First submission on VT | July 23, 2014, 5:43 a.m. |
Last submission on VT | Sept. 12, 2021, 7:46 p.m. |
Upload on Pithus | Dec. 31, 2021, 8:55 a.m. |
Certificate valid not after | Nov. 20, 3013, 3:51 p.m. |
Score | 17/59 |
Report | https://www.virustotal.com/gui/file/000b9d0a7ea4e612958389d5d7a6e32a256f4af60087b06254314f98632d2107/detection |
Provided by VirusTotal
Threat name: admogo | Identified 4 times |
Threat name: adwo | Identified 2 times |
Threat name: artemis | Identified 2 times |
Information computed with MobSF.
FCS_RBG_EXT.1.1 | The application invoke platform-provided DRBG functionality for its cryptographic operations. Random Bit Generation Services |
FCS_STO_EXT.1.1 | The application does not store any credentials to non-volatile memory. Storage of Credentials |
FCS_CKM_EXT.1.1 | The application generate no asymmetric cryptographic keys. Cryptographic Key Generation Services |
FDP_DEC_EXT.1.1 | The application has access to ['location', 'network connectivity']. Access to Platform Resources |
FDP_DEC_EXT.1.2 | The application has access to no sensitive information repositories. Access to Platform Resources |
FDP_NET_EXT.1.1 | The application has user/application initiated network communications. Network Communications |
FDP_DAR_EXT.1.1 | The application implement functionality to encrypt sensitive data in non-volatile memory. Encryption Of Sensitive Application Data |
FMT_MEC_EXT.1.1 | The application invoke the mechanisms recommended by the platform vendor for storing and setting configuration options. Supported Configuration Mechanism |
FTP_DIT_EXT.1.1 | The application does encrypt some transmitted data with HTTPS/TLS/SSH between itself and another trusted IT product. Protection of Data in Transit |
FCS_RBG_EXT.2.1 FCS_RBG_EXT.2.2 |
The application perform all deterministic random bit generation (DRBG) services in accordance with NIST Special Publication 800-90A using Hash_DRBG. The deterministic RBG is seeded by an entropy source that accumulates entropy from a platform-based DRBG and a software-based noise source, with a minimum of 256 bits of entropy at least equal to the greatest security strength (according to NIST SP 800-57) of the keys and hashes that it will generate. Random Bit Generation from Application |
FCS_COP.1.1(1) | The application perform encryption/decryption not in accordance with FCS_COP.1.1(1), AES-ECB mode is being used. Cryptographic Operation - Encryption/Decryption |
FCS_COP.1.1(2) | The application perform cryptographic hashing services not in accordance with FCS_COP.1.1(2) and uses the cryptographic algorithm RC2/RC4/MD4/MD5. Cryptographic Operation - Hashing |
FCS_COP.1.1(4) | The application perform keyed-hash message authentication with cryptographic algorithm ['HMAC-SHA1'] . Cryptographic Operation - Keyed-Hash Message Authentication |
FCS_HTTPS_EXT.1.2 | The application implement HTTPS using TLS. HTTPS Protocol |
FIA_X509_EXT.1.1 | The application invoked platform-provided functionality to validate certificates in accordance with the following rules: ['The certificate path must terminate with a trusted CA certificate']. X.509 Certificate Validation |
FIA_X509_EXT.2.1 | The application use X.509v3 certificates as defined by RFC 5280 to support authentication for HTTPS , TLS. X.509 Certificate Authentication |
Information computed with MobSF.
Map computed by Pithus.
Information computed with MobSF.
Information computed with MobSF.
http://open.bmob.cn/7/timestamp http://open.bmob.cn/7/email_verify http://open.bmob.cn/7/reset http://open.bmob.cn/7/push Defined in c/a.java |
|
http://open.bmob.cn/7/timestamp http://open.bmob.cn/7/email_verify http://open.bmob.cn/7/reset http://open.bmob.cn/7/push Defined in c/a.java |
|
http://open.bmob.cn/7/timestamp http://open.bmob.cn/7/email_verify http://open.bmob.cn/7/reset http://open.bmob.cn/7/push Defined in c/a.java |
|
http://open.bmob.cn/7/timestamp http://open.bmob.cn/7/email_verify http://open.bmob.cn/7/reset http://open.bmob.cn/7/push Defined in c/a.java |
|
http://open.bmob.cn/7/find Defined in cn/bmob/v3/BmobQuery.java |
|
http://cloud.codenow.cn/1/endpoint Defined in cn/bmob/v3/AsyncCustomEndpoints.java |
|
http://open.bmob.cn/7/batch http://open.bmob.cn/7/delete http://open.bmob.cn/7/create http://open.bmob.cn/7/update Defined in cn/bmob/v3/BmobObject.java |
|
http://open.bmob.cn/7/batch http://open.bmob.cn/7/delete http://open.bmob.cn/7/create http://open.bmob.cn/7/update Defined in cn/bmob/v3/BmobObject.java |
|
http://open.bmob.cn/7/batch http://open.bmob.cn/7/delete http://open.bmob.cn/7/create http://open.bmob.cn/7/update Defined in cn/bmob/v3/BmobObject.java |
|
http://open.bmob.cn/7/batch http://open.bmob.cn/7/delete http://open.bmob.cn/7/create http://open.bmob.cn/7/update Defined in cn/bmob/v3/BmobObject.java |
|
http://open.bmob.cn/7/login http://open.bmob.cn/7/signup http://open.bmob.cn/7/update Defined in cn/bmob/v3/BmobUser.java |
|
http://open.bmob.cn/7/login http://open.bmob.cn/7/signup http://open.bmob.cn/7/update Defined in cn/bmob/v3/BmobUser.java |
|
http://open.bmob.cn/7/login http://open.bmob.cn/7/signup http://open.bmob.cn/7/update Defined in cn/bmob/v3/BmobUser.java |
|
http://open.bmob.cn/7/find Defined in cn/bmob/v3/BmobQuery2.java |
|
http://cloud.codenow.cn/1/endpoint Defined in cn/bmob/v3/requestmanager/a.java |
|
http://open.bmob.cn/7/delfile http://file.bmob.cn/ http://open.bmob.cn/7/thumbnail Defined in cn/bmob/v3/datatype/BmobFile.java |
|
http://open.bmob.cn/7/delfile http://file.bmob.cn/ http://open.bmob.cn/7/thumbnail Defined in cn/bmob/v3/datatype/BmobFile.java |
|
http://open.bmob.cn/7/delfile http://file.bmob.cn/ http://open.bmob.cn/7/thumbnail Defined in cn/bmob/v3/datatype/BmobFile.java |
|
http://open.bmob.cn/7/find Defined in cn/bmob/v3/datatype/BmobPointer.java |
|
http://www.renren.com/ Defined in cn/sharesdk/renren/Renren.java |
|
https://api.renren.com http://graph.renren.com/renren_api/session_key https://graph.renren.com http://graph.renren.com/oauth/login_success.html Defined in cn/sharesdk/renren/d.java |
|
https://api.renren.com http://graph.renren.com/renren_api/session_key https://graph.renren.com http://graph.renren.com/oauth/login_success.html Defined in cn/sharesdk/renren/d.java |
|
https://api.renren.com http://graph.renren.com/renren_api/session_key https://graph.renren.com http://graph.renren.com/oauth/login_success.html Defined in cn/sharesdk/renren/d.java |
|
https://api.renren.com http://graph.renren.com/renren_api/session_key https://graph.renren.com http://graph.renren.com/oauth/login_success.html Defined in cn/sharesdk/renren/d.java |
|
http://api2.sharesdk.cn:5566 http://api2.sharesdk.cn:5566/conf3 http://s.sharesdk.cn/api/convert3.do http://up.sharesdk.cn/upload/image https://){1} Defined in cn/sharesdk/framework/b/a.java |
|
http://api2.sharesdk.cn:5566 http://api2.sharesdk.cn:5566/conf3 http://s.sharesdk.cn/api/convert3.do http://up.sharesdk.cn/upload/image https://){1} Defined in cn/sharesdk/framework/b/a.java |
|
http://api2.sharesdk.cn:5566 http://api2.sharesdk.cn:5566/conf3 http://s.sharesdk.cn/api/convert3.do http://up.sharesdk.cn/upload/image https://){1} Defined in cn/sharesdk/framework/b/a.java |
|
http://api2.sharesdk.cn:5566 http://api2.sharesdk.cn:5566/conf3 http://s.sharesdk.cn/api/convert3.do http://up.sharesdk.cn/upload/image https://){1} Defined in cn/sharesdk/framework/b/a.java |
|
http://instagram.com/ Defined in cn/sharesdk/instagram/Instagram.java |
|
https://api.instagram.com/oauth/access_token https://api.instagram.com/v1/users/ https://instagram.com/oauth/authorize/? Defined in cn/sharesdk/instagram/e.java |
|
https://api.instagram.com/oauth/access_token https://api.instagram.com/v1/users/ https://instagram.com/oauth/authorize/? Defined in cn/sharesdk/instagram/e.java |
|
https://api.instagram.com/oauth/access_token https://api.instagram.com/v1/users/ https://instagram.com/oauth/authorize/? Defined in cn/sharesdk/instagram/e.java |
|
http://126.fm/ http://t.163.com/ Defined in cn/sharesdk/netease/microblog/NetEaseMicroBlog.java |
|
http://126.fm/ http://t.163.com/ Defined in cn/sharesdk/netease/microblog/NetEaseMicroBlog.java |
|
https://api.t.163.com/account/verify_credentials.json https://api.t.163.com/statuses/upload.json https://api.t.163.com/users/show.json https://api.t.163.com/statuses/update.json https://api.t.163.com/oauth2/authorize? Defined in cn/sharesdk/netease/microblog/a.java |
|
https://api.t.163.com/account/verify_credentials.json https://api.t.163.com/statuses/upload.json https://api.t.163.com/users/show.json https://api.t.163.com/statuses/update.json https://api.t.163.com/oauth2/authorize? Defined in cn/sharesdk/netease/microblog/a.java |
|
https://api.t.163.com/account/verify_credentials.json https://api.t.163.com/statuses/upload.json https://api.t.163.com/users/show.json https://api.t.163.com/statuses/update.json https://api.t.163.com/oauth2/authorize? Defined in cn/sharesdk/netease/microblog/a.java |
|
https://api.t.163.com/account/verify_credentials.json https://api.t.163.com/statuses/upload.json https://api.t.163.com/users/show.json https://api.t.163.com/statuses/update.json https://api.t.163.com/oauth2/authorize? Defined in cn/sharesdk/netease/microblog/a.java |
|
https://api.t.163.com/account/verify_credentials.json https://api.t.163.com/statuses/upload.json https://api.t.163.com/users/show.json https://api.t.163.com/statuses/update.json https://api.t.163.com/oauth2/authorize? Defined in cn/sharesdk/netease/microblog/a.java |
|
https://api.linkedin.com/v1/people/~/shares https://www.linkedin.com/uas/oauth2/accessToken https://api.linkedin.com/v1/people/ https://www.linkedin.com/uas/oauth2/authorization? Defined in cn/sharesdk/linkedin/b.java |
|
https://api.linkedin.com/v1/people/~/shares https://www.linkedin.com/uas/oauth2/accessToken https://api.linkedin.com/v1/people/ https://www.linkedin.com/uas/oauth2/authorization? Defined in cn/sharesdk/linkedin/b.java |
|
https://api.linkedin.com/v1/people/~/shares https://www.linkedin.com/uas/oauth2/accessToken https://api.linkedin.com/v1/people/ https://www.linkedin.com/uas/oauth2/authorization? Defined in cn/sharesdk/linkedin/b.java |