0/64
Threat
Analyzed on 2022-05-09T15:37:12.086015
MD5 | 14edc6b628b5d1ffdd2588f36b6a0159 | |
SHA1 | 168a491b280071e4a3138ed89112252b89bfe647 | |
SHA256 | 138fbaaf69f175f79dda0df672244b4fd1c36f9be0a22b1a569afb0e4539beea | |
Size | 6.52MB |
Information computed with APKiD.
/tmp/tmpx065z70v!classes.dex | |
anti_vm |
|
anti_debug |
|
compiler |
|
Information computed with ssdeep.
APK file | 196608:VF33m3ZNHFkrj3LBxoXA1QexTI3+RLUcQ6a:VFH8XHSoXA11TI3wL8 | |
Manifest | 384:r9m5nRKTAdG55e6toWci3Ey/GA7hCtkCUdXza4Flfi2NSiKpKlVLcJb2IhdS:r9m5… | |
classes.dex | 49152:NEil8oEFJttnJaz+HlBxmPh3RRRC5nDSb6Dfkxk2zTB8N4NK62XI3eYvcRSOo7X… |
Information computed with Dexofuzzy.
APK file | 12288:wpANr7VK+SWJwWz9BwgvAKXpVWGxpqbp0R:qAp7V2WbzYv8pD | |
classes.dex | 12288:wpANr7VK+SWJwWz9BwgvAKXpVWGxpqbp0R:qAp7V2WbzYv8pD |
Information computed with AndroGuard and Pithus.
Information computed with AndroGuard.
Information computed with MobSF.
Medium | Application Data can be Backed up[android:allowBackup=true] This flag allows anyone to backup your application data via adb. It allows users who have enabled USB debugging to copy application data off of the device. |
High | Service (com.example.barcodescanner.feature.tile.QuickSettingsTileService) is Protected by a permission, but the protection level of the permission should be checked.Permission: android.permission.BIND_QUICK_SETTINGS_TILE [android:exported=true] A Service is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission which is not defined in the analysed application. As a result, the protection level of the permission should be checked where it is defined. If it is set to normal or dangerous, a malicious application can request and obtain the permission and interact with the component. If it is set to signature, only applications signed with the same certificate can obtain the permission. |
High | Activity (com.example.barcodescanner.feature.tabs.scan.file.ScanBarcodeFromFileActivity) is not Protected. [android:exported=true] An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. |
High | Activity (com.example.barcodescanner.feature.tabs.create.CreateBarcodeActivity) is not Protected. [android:exported=true] An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. |
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Oldest file found in APK | Jan. 1, 1981, 1:01 a.m. |
Latest file found in APK | Jan. 1, 1981, 1:01 a.m. |
Certificate valid not before | Sept. 16, 2020, 10:53 a.m. |
First submission on VT | April 17, 2022, 8:50 p.m. |
Last submission on VT | May 5, 2022, 5:22 p.m. |
Upload on Pithus | May 9, 2022, 3:37 p.m. |
Certificate valid not after | Feb. 2, 2048, 10:53 a.m. |
Score | 0/64 |
Report | https://www.virustotal.com/gui/file/138fbaaf69f175f79dda0df672244b4fd1c36f9be0a22b1a569afb0e4539beea/detection |
Information computed with MobSF.
FCS_RBG_EXT.1.1 | The application invoke platform-provided DRBG functionality for its cryptographic operations. Random Bit Generation Services |
FCS_STO_EXT.1.1 | The application does not store any credentials to non-volatile memory. Storage of Credentials |
FCS_CKM_EXT.1.1 | The application generate no asymmetric cryptographic keys. Cryptographic Key Generation Services |
FDP_DEC_EXT.1.1 | The application has access to ['camera', 'network connectivity']. Access to Platform Resources |
FDP_DEC_EXT.1.2 | The application has access to ['address book']. Access to Platform Resources |
FDP_NET_EXT.1.1 | The application has user/application initiated network communications. Network Communications |
FDP_DAR_EXT.1.1 | The application implement functionality to encrypt sensitive data in non-volatile memory. Encryption Of Sensitive Application Data |
FMT_MEC_EXT.1.1 | The application invoke the mechanisms recommended by the platform vendor for storing and setting configuration options. Supported Configuration Mechanism |
FTP_DIT_EXT.1.1 | The application does encrypt some transmitted data with HTTPS/TLS/SSH between itself and another trusted IT product. Protection of Data in Transit |
FCS_RBG_EXT.2.1 FCS_RBG_EXT.2.2 |
The application perform all deterministic random bit generation (DRBG) services in accordance with NIST Special Publication 800-90A using Hash_DRBG. The deterministic RBG is seeded by an entropy source that accumulates entropy from a platform-based DRBG and a software-based noise source, with a minimum of 256 bits of entropy at least equal to the greatest security strength (according to NIST SP 800-57) of the keys and hashes that it will generate. Random Bit Generation from Application |
FCS_HTTPS_EXT.1.1 | The application implement the HTTPS protocol that complies with RFC 2818. HTTPS Protocol |
FCS_HTTPS_EXT.1.2 | The application implement HTTPS using TLS. HTTPS Protocol |
FPT_TUD_EXT.2.1 | The application shall be distributed using the format of the platform-supported package manager. Integrity for Installation and Update |
Information computed with MobSF.
Map computed by Pithus.
Information computed with MobSF.
Information computed with MobSF.
http://maps.google.com/ https://maps.google.com/ Defined in a0/h.java |
|
http://maps.google.com/ https://maps.google.com/ Defined in a0/h.java |
|
http://www.youtube.com https://www.youtube.com Defined in a0/u.java |
|
http://www.youtube.com https://www.youtube.com Defined in a0/u.java |
|
http://play.google.com/ https://play.google.com/ Defined in a0/a.java |
|
http://play.google.com/ https://play.google.com/ Defined in a0/a.java |
|
https://github.com/ReactiveX/RxJava/wiki/Error-Handling Defined in o2/c.java |
|
https://github.com/ReactiveX/RxJava/wiki/What's-different-in-2.0#error-handling Defined in o2/d.java |
|
http://www.w3.org/2000/svg Defined in b0/i.java |
|
https://www.bing.com/search?q= https://duckduckgo.com/?q= https://www.google.com/search?q= https://www.qwant.com/?q= https://www.startpage.com/sp/search?query= https://search.yahoo.com/search?p= https://www.yandex.ru/search/?text= Defined in z/e.java |
|
https://www.bing.com/search?q= https://duckduckgo.com/?q= https://www.google.com/search?q= https://www.qwant.com/?q= https://www.startpage.com/sp/search?query= https://search.yahoo.com/search?p= https://www.yandex.ru/search/?text= Defined in z/e.java |
|
https://www.bing.com/search?q= https://duckduckgo.com/?q= https://www.google.com/search?q= https://www.qwant.com/?q= https://www.startpage.com/sp/search?query= https://search.yahoo.com/search?p= https://www.yandex.ru/search/?text= Defined in z/e.java |
|
https://www.bing.com/search?q= https://duckduckgo.com/?q= https://www.google.com/search?q= https://www.qwant.com/?q= https://www.startpage.com/sp/search?query= https://search.yahoo.com/search?p= https://www.yandex.ru/search/?text= Defined in z/e.java |
|
https://www.bing.com/search?q= https://duckduckgo.com/?q= https://www.google.com/search?q= https://www.qwant.com/?q= https://www.startpage.com/sp/search?query= https://search.yahoo.com/search?p= https://www.yandex.ru/search/?text= Defined in z/e.java |
|
https://www.bing.com/search?q= https://duckduckgo.com/?q= https://www.google.com/search?q= https://www.qwant.com/?q= https://www.startpage.com/sp/search?query= https://search.yahoo.com/search?p= https://www.yandex.ru/search/?text= Defined in z/e.java |
|
https://www.bing.com/search?q= https://duckduckgo.com/?q= https://www.google.com/search?q= https://www.qwant.com/?q= https://www.startpage.com/sp/search?query= https://search.yahoo.com/search?p= https://www.yandex.ru/search/?text= Defined in z/e.java |
|
http://maps.google.com/maps?q= Defined in z/d.java |
|
https://github.com/wewewe718/QrAndBarcodeScanner Defined in v/n.java |
|
http://xml.apache.org/xslt}indent-amount Defined in ezvcard/io/xml/XCardOutputProperties.java |
|
http://apache.org/xml/features/disallow-doctype-decl http://xml.org/sax/features/external-general-entities http://xml.org/sax/features/external-parameter-entities http://apache.org/xml/features/nonvalidating/load-external-dtd http://javax.xml.XMLConstants/property/accessExternalDTD http://javax.xml.XMLConstants/property/accessExternalStylesheet Defined in ezvcard/util/XmlUtils.java |
|
http://apache.org/xml/features/disallow-doctype-decl http://xml.org/sax/features/external-general-entities http://xml.org/sax/features/external-parameter-entities http://apache.org/xml/features/nonvalidating/load-external-dtd http://javax.xml.XMLConstants/property/accessExternalDTD http://javax.xml.XMLConstants/property/accessExternalStylesheet Defined in ezvcard/util/XmlUtils.java |
|
http://apache.org/xml/features/disallow-doctype-decl http://xml.org/sax/features/external-general-entities http://xml.org/sax/features/external-parameter-entities http://apache.org/xml/features/nonvalidating/load-external-dtd http://javax.xml.XMLConstants/property/accessExternalDTD http://javax.xml.XMLConstants/property/accessExternalStylesheet Defined in ezvcard/util/XmlUtils.java |
|
http://apache.org/xml/features/disallow-doctype-decl http://xml.org/sax/features/external-general-entities http://xml.org/sax/features/external-parameter-entities http://apache.org/xml/features/nonvalidating/load-external-dtd http://javax.xml.XMLConstants/property/accessExternalDTD http://javax.xml.XMLConstants/property/accessExternalStylesheet Defined in ezvcard/util/XmlUtils.java |
|
http://freemarker.org/docs/ref_directive_list.html). http://freemarker.org/docs/ref_directive_alphaidx.html; Defined in c2/r3.java |
|
http://freemarker.org/docs/ref_directive_list.html). http://freemarker.org/docs/ref_directive_alphaidx.html; Defined in c2/r3.java |
|
https://freemarker.apache.org/docs/ref_builtins.html; Defined in c2/q.java |
Information computed with MobSF.
Information computed with Quark-Engine.
Confidence:
|
Load external class |
Confidence:
|
Implicit intent(view a web page, make a phone call, etc.) |
Confidence:
|
Find a method from given class name, usually for reflection |
Confidence:
|
Connect to a URL and receive input stream from the server |
Confidence:
|
Method reflection |
Confidence:
|
Connect to a URL and read data from it |
Confidence:
|
Retrieve data from broadcast |
Confidence:
|
Get declared method from given method name |
Confidence:
|
Read sensitive data(SMS, CALLLOG, etc) |
Confidence:
|
Open a file from given absolute path of the file |
Confidence:
|
Connect to a URL and get the response code |
Confidence:
|
Monitor the broadcast action events (BOOT_COMPLETED) |
Confidence:
|
Get absolute path of the file and store in string |
Confidence:
|
Read file from assets directory |
Confidence:
|
Get last known location of the device |
Confidence:
|
Get calendar information |
Confidence:
|
Get location of the device |
Confidence:
|
Method reflection |
Confidence:
|
Connect to the remote server through the given URL |
Confidence:
|
Get the time of current location |
Confidence:
|
Initialize class object dynamically |
Confidence:
|
Connect to a URL and set request method |
Confidence:
|
Get resource file from res/raw directory |
Confidence:
|
Get specific method from other Dex files |
Confidence:
|
Read data and put it into a buffer stream |
Confidence:
|
Read file and put it into a stream |
Confidence:
|
Implicit intent(view a web page, make a phone call, etc.) via setData |
Confidence:
|
Check if the given file path exist |
Confidence:
|
Executes the specified string Linux command |
Information computed with MobSF.
Information computed by Pithus.