0/61
Threat
Analyzed on 2022-05-24T03:01:41.391164
MD5 | 7fd62e17d61e10cbc87b0cb4a64d09eb | |
SHA1 | d009a53a30fe282de0944aa2d9ca1a36e2f3519f | |
SHA256 | 1d04175fc7663ed057ed520a3294e07f4044b76723a95b83b57e532b4ef567fe | |
Size | 2.64MB |
Information computed with APKiD.
/tmp/tmpj1taq7qs!classes.dex | |
yara_issue |
|
compiler |
|
Information computed with ssdeep.
APK file | 49152:UqAiiUM9DmoLdqkg845Ssz9ymATEG4eAFP2HJlvLPfTMwLZ9Yvo:UqAio9w5l9ym0EQHJ1LPfTMwLio | |
Manifest | 192:DegSKC/HSC4MJe6E8EdAfuI3YaXrad5VdKdtC7CpVcr/QCjVcSB:DegSK6yFMJe6E… | |
classes.dex | 49152:oLvv74JjVfWqMBP1sfsTK62PZnoQ3VKT8nk59L7:oLvmjkW4K62lS |
Information computed with AndroGuard and Pithus.
Information computed with AndroGuard.
Information computed with MobSF.
Findings | Files |
---|---|
Certificate/Key files hardcoded inside the app. |
SEC-INF/buildConfirm.crt |
Information computed with MobSF.
High | Service (.IrisService) is not Protected. [android:exported=true] A Service is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. |
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Oldest file found in APK | Jan. 1, 2009, midnight |
Latest file found in APK | Jan. 1, 2009, midnight |
Certificate valid not before | June 22, 2011, 12:25 p.m. |
First submission on VT | April 27, 2021, 3:56 a.m. |
Last submission on VT | April 27, 2021, 3:56 a.m. |
Upload on Pithus | May 24, 2022, 3:01 a.m. |
Certificate valid not after | Nov. 7, 2038, 12:25 p.m. |
Score | 0/61 |
Report | https://www.virustotal.com/gui/file/1d04175fc7663ed057ed520a3294e07f4044b76723a95b83b57e532b4ef567fe/detection |
Information computed with MobSF.
FCS_RBG_EXT.1.1 | The application invoke platform-provided DRBG functionality for its cryptographic operations. Random Bit Generation Services |
FCS_STO_EXT.1.1 | The application does not store any credentials to non-volatile memory. Storage of Credentials |
FCS_CKM_EXT.1.1 | The application generate no asymmetric cryptographic keys. Cryptographic Key Generation Services |
FDP_DEC_EXT.1.1 | The application has access to ['camera']. Access to Platform Resources |
FDP_DEC_EXT.1.2 | The application has access to no sensitive information repositories. Access to Platform Resources |
FDP_NET_EXT.1.1 | The application has no network communications. Network Communications |
FDP_DAR_EXT.1.1 | The application implement functionality to encrypt sensitive data in non-volatile memory. Encryption Of Sensitive Application Data |
FMT_MEC_EXT.1.1 | The application invoke the mechanisms recommended by the platform vendor for storing and setting configuration options. Supported Configuration Mechanism |
FTP_DIT_EXT.1.1 | The application does encrypt some transmitted data with HTTPS/TLS/SSH between itself and another trusted IT product. Protection of Data in Transit |
FCS_RBG_EXT.2.1 FCS_RBG_EXT.2.2 |
The application perform all deterministic random bit generation (DRBG) services in accordance with NIST Special Publication 800-90A using Hash_DRBG. The deterministic RBG is seeded by an entropy source that accumulates entropy from a platform-based DRBG and a software-based noise source, with a minimum of 256 bits of entropy at least equal to the greatest security strength (according to NIST SP 800-57) of the keys and hashes that it will generate. Random Bit Generation from Application |
FCS_COP.1.1(2) | The application perform cryptographic hashing services in accordance with a specified cryptographic algorithm SHA-1/SHA-256/SHA-384/SHA-512 and message digest sizes 160/256/384/512 bits. Cryptographic Operation - Hashing |
FCS_HTTPS_EXT.1.1 | The application implement the HTTPS protocol that complies with RFC 2818. HTTPS Protocol |
FCS_HTTPS_EXT.1.2 | The application implement HTTPS using TLS. HTTPS Protocol |
Information computed with MobSF.
Map computed by Pithus.
Information computed with MobSF.
US | dc.di.atlas.samsung.com | 34.120.24.208 | ||
US | www.samsung.com | 69.192.160.55 | ||
US | xmlpull.org | 74.50.61.58 |
Information computed with MobSF.
https://dc.di.atlas.samsung.com Defined in com/samsung/context/sdk/samsunganalytics/a/a/c.java |
|
http://xmlpull.org/v1/doc/features.html#indent-output Defined in com/samsung/android/server/iris/IrisesUserState.java |
Information computed with MobSF.
Information computed with Quark-Engine.
Confidence:
|
Find a method from given class name, usually for reflection |
Confidence:
|
Method reflection |
Confidence:
|
Load class from given class name |
Confidence:
|
Retrieve data from broadcast |
Confidence:
|
Read sensitive data(SMS, CALLLOG, etc) |
Confidence:
|
Monitor the broadcast action events (BOOT_COMPLETED) |
Confidence:
|
Method reflection |
Confidence:
|
Initialize class object dynamically |
Confidence:
|
Read file and put it into a stream |
Confidence:
|
Get declared method from given method name |
Confidence:
|
Get resource file from res/raw directory |
Information computed with MobSF.
Information computed by Pithus.