0/62
Threat
Analyzed on 2021-10-04T15:07:01.877425
MD5 | fc97ca8a1caca448fb536a09e09966f6 | |
SHA1 | 1add349256d5ae9818dde4be60953623fdbc94e0 | |
SHA256 | 92d95d370f810d64f023ff241e35e36f21a86f7b41ac9c2f7a0b0532ec426df7 | |
Size | 4.81MB |
Information computed with APKiD.
/tmp/tmpda7o2j7n!assets/audience_network.dex | |
anti_vm |
|
compiler |
|
/tmp/tmpda7o2j7n!classes.dex | |
anti_vm |
|
compiler |
|
Information computed with ssdeep.
APK file | 98304:sFq2/ltrso8Th37u1bZNJlS2fc7V7VsZmJ2yJRvZqQeLl9O/TquU:ettOCp07V7VsZmJ2yobPka | |
Manifest | 192:H4WektoTmntyDVAKYET+tT++T+7T+70TpqS2W2yi3hvs:H4WektoTmntyDVAKYqYl… | |
assets/audience_network.dex | 24576:aBzUrqSgQJTXFRU583L+za7dNH1Vs1qEq7kC3gg:/JTEy3L+ydh1VWukCwg | |
classes.dex | 98304:hoLfmCp27q9YJH7LOEaQ90p0K62a0dD18TaggugJf:qLuCp2obUZgJf |
Information computed with Dexofuzzy.
Information computed with AndroGuard and Pithus.
Information computed with AndroGuard.
Information computed with MobSF.
High | Activity (com.vmos.adclient.ad.AdActivity) is not Protected.An intent-filter exists. An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Activity is explicitly exported. |
High | Activity (com.vmos.adclient.ad.vungle.VungleAdActivity) is not Protected.An intent-filter exists. An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Activity is explicitly exported. |
High | Service (com.vmos.adclient.ad.AdService) is not Protected. [android:exported=true] A Service is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. |
High | Broadcast Receiver (com.vungle.warren.NetworkProviderReceiver) is not Protected.An intent-filter exists. A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. The presence of intent-filter indicates that the Broadcast Receiver is explicitly exported. |
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Certificate valid not before | Dec. 25, 2018, 11:45 a.m. |
First submission on VT | May 24, 2020, 3:07 p.m. |
Last submission on VT | March 2, 2021, 3:06 p.m. |
Upload on Pithus | Oct. 4, 2021, 3:07 p.m. |
Certificate valid not after | Dec. 19, 2043, 11:45 a.m. |
Information computed by Pithus.
Score | 0/62 |
Report | https://www.virustotal.com/gui/file/92d95d370f810d64f023ff241e35e36f21a86f7b41ac9c2f7a0b0532ec426df7/detection |
Information computed with MobSF.
FCS_RBG_EXT.1.1 | The application invoke platform-provided DRBG functionality for its cryptographic operations. Random Bit Generation Services |
FCS_STO_EXT.1.1 | The application does not store any credentials to non-volatile memory. Storage of Credentials |
FCS_CKM_EXT.1.1 | The application implement asymmetric key generation. Cryptographic Key Generation Services |
FDP_DEC_EXT.1.1 | The application has access to ['network connectivity']. Access to Platform Resources |
FDP_DEC_EXT.1.2 | The application has access to no sensitive information repositories. Access to Platform Resources |
FDP_NET_EXT.1.1 | The application has user/application initiated network communications. Network Communications |
FDP_DAR_EXT.1.1 | The application implement functionality to encrypt sensitive data in non-volatile memory. Encryption Of Sensitive Application Data |
FMT_MEC_EXT.1.1 | The application invoke the mechanisms recommended by the platform vendor for storing and setting configuration options. Supported Configuration Mechanism |
FTP_DIT_EXT.1.1 | The application does encrypt some transmitted data with HTTPS/TLS/SSH between itself and another trusted IT product. Protection of Data in Transit |
FCS_RBG_EXT.2.1 FCS_RBG_EXT.2.2 |
The application perform all deterministic random bit generation (DRBG) services in accordance with NIST Special Publication 800-90A using Hash_DRBG. The deterministic RBG is seeded by an entropy source that accumulates entropy from a platform-based DRBG and a software-based noise source, with a minimum of 256 bits of entropy at least equal to the greatest security strength (according to NIST SP 800-57) of the keys and hashes that it will generate. Random Bit Generation from Application |
FCS_CKM.1.1(1) | The application generate asymmetric cryptographic keys not in accordance with FCS_CKM.1.1(1) using key generation algorithm RSA schemes and cryptographic key sizes of 1024-bit or lower. Cryptographic Asymmetric Key Generation |
FCS_COP.1.1(1) | The application perform encryption/decryption in accordance with a specified cryptographic algorithm AES-CBC (as defined in NIST SP 800-38A) mode or AES-GCM (as defined in NIST SP 800-38D) and cryptographic key sizes 256-bit/128-bit. Cryptographic Operation - Encryption/Decryption |
FCS_COP.1.1(2) | The application perform cryptographic hashing services not in accordance with FCS_COP.1.1(2) and uses the cryptographic algorithm RC2/RC4/MD4/MD5. Cryptographic Operation - Hashing |
FCS_HTTPS_EXT.1.1 | The application implement the HTTPS protocol that complies with RFC 2818. HTTPS Protocol |
FCS_HTTPS_EXT.1.2 | The application implement HTTPS using TLS. HTTPS Protocol |
FCS_HTTPS_EXT.1.3 | The application notify the user and not establish the connection or request application authorization to establish the connection if the peer certificate is deemed invalid. HTTPS Protocol |
FIA_X509_EXT.2.1 | The application use X.509v3 certificates as defined by RFC 5280 to support authentication for HTTPS , TLS. X.509 Certificate Authentication |
FPT_TUD_EXT.2.1 | The application shall be distributed using the format of the platform-supported package manager. Integrity for Installation and Update |
Information computed with MobSF.
Map computed by Pithus.
Information computed with MobSF.
US | px.moatads.com | 23.218.209.154 | ||
US | z.moatads.com | 23.218.209.154 | ||
DE | ads.api.vungle.com | 104.121.76.65 | ||
DE | api.vungle.com | 104.121.76.72 | ||
DE | vungle.com | 23.36.234.157 |
Information computed with MobSF.
https://z.moatads.com/' https://z.moatads.com/ Defined in com/moat/analytics/mobile/vng/g.java |
|
https://z.moatads.com/' https://z.moatads.com/ Defined in com/moat/analytics/mobile/vng/g.java |
|
https://z.moatads.com/ Defined in com/moat/analytics/mobile/vng/w.java |
|
https://px.moatads.com/pixel.gif?e=0&i=MOATSDK1&ac=1 Defined in com/moat/analytics/mobile/vng/n.java |
|
https://ads.api.vungle.com/ https://api.vungle.com/ Defined in com/vungle/warren/VungleApiClient.java |
|
https://ads.api.vungle.com/ https://api.vungle.com/ Defined in com/vungle/warren/VungleApiClient.java |
|
https://vungle.com/privacy/ Defined in com/vungle/warren/ui/presenter/LocalAdPresenter.java |
Information computed with MobSF.
Information computed with Exodus-core.
Facebook Ads | https://reports.exodus-privacy.eu.org/fr/trackers/65 |
Google AdMob | https://reports.exodus-privacy.eu.org/fr/trackers/312 |
Google Firebase Analytics | https://reports.exodus-privacy.eu.org/fr/trackers/49 |
Moat | https://reports.exodus-privacy.eu.org/fr/trackers/61 |
Vungle | https://reports.exodus-privacy.eu.org/fr/trackers/169 |
Information computed with Quark-Engine.
Confidence:
|
Load external class |
Confidence:
|
Query the current data network type |
Confidence:
|
Implicit intent(view a web page, make a phone call, etc.) |
Confidence:
|
Find a method from given class name, usually for reflection |
Confidence:
|
Connect to a URL and receive input stream from the server |
Confidence:
|
Method reflection |
Confidence:
|
Get the network operator name |
Confidence:
|
Save the response to JSON after connecting to the remote server |
Confidence:
|
Load class from given class name |
Confidence:
|
Retrieve data from broadcast |
Confidence:
|
Read sensitive data(SMS, CALLLOG, etc) |
Confidence:
|
Check if the given path is directory |
Confidence:
|
Implicit intent(view a web page, make a phone call, etc.) via setData |
Confidence:
|
Connect to a URL and get the response code |
Confidence:
|
Monitor the broadcast action events (BOOT_COMPLETED) |
Confidence:
|
Get absolute path of the file and store in string |
Confidence:
|
Read file from assets directory |
Confidence:
|
Get last known location of the device |
Confidence:
|
Get calendar information |
Confidence:
|
Get location of the device |
Confidence:
|
Method reflection |
Confidence:
|
Hide the current app's icon |
Confidence:
|
Connect to the remote server through the given URL |
Confidence:
|
Query data from URI (SMS, CALLLOGS) |
Confidence:
|
Get the time of current location |
Confidence:
|
Initialize class object dynamically |
Confidence:
|
Read the input stream from given URL |
Confidence:
|
Connect to a URL and set request method |
Confidence:
|
Get specific method from other Dex files |
Confidence:
|
Read data and put it into a buffer stream |
Confidence:
|
Get location info of the device and put it to JSON object |
Confidence:
|
Connect to a URL and read data from it |
Confidence:
|
Read file and put it into a stream |
Confidence:
|
Get declared method from given method name |
Confidence:
|
Query the network operator name |
Confidence:
|
Get resource file from res/raw directory |
Information computed with MobSF.
Information computed by Pithus.