1/59
Threat
Analyzed on 2022-06-04T09:53:15.542936
MD5 | fb6daa9a00b97cd4284d0c4db42bbc9f | |
SHA1 | 8bb28d22aff437b24d0f68862be9e8efcf1d8d9f | |
SHA256 | b9fe6eb29f5a138935b6585e17899586e522c992acfa08b94b14bae569a5960a | |
Size | 0.13MB |
Information computed with APKiD.
/tmp/tmpphay8nzq!classes.dex | |
compiler |
|
Information computed with ssdeep.
APK file | 1536:m+K7CQQDsNx5DapgyQ2xwr+GoY2IgKHMnEFf2rcHyM6ZuYRg1n3kPQBhBEYabKMz:SvQDsNvygD2DXZEFf2rcHonTohBEel8 | |
Manifest | 96:L1A1U1vbRxbaWLlSf7/tIZf38t/cl+FU6SqI5Dp1Vv9Fs8MZco:L1RbRt7LlSz/tIZ… | |
classes.dex | 3072:7BNgWvPwedAaKmicP1ALY8ggN32yl3GI2mpwpapF0dPgx/eqRGqMBEqlUiii6IeT… |
Information computed with Dexofuzzy.
APK file | 192:51IYei9eS9zd5qlyF681206Mi78zk4vT0:52YvkkzThp1crUkV | |
classes.dex | 192:51IYei9eS9zd5qlyF681206Mi78zk4vT0:52YvkkzThp1crUkV |
Information computed with AndroGuard and Pithus.
Information computed with AndroGuard.
Information computed with MobSF.
Findings | Files |
---|---|
Certificate/Key files hardcoded inside the app. |
SEC-INF/buildConfirm.crt |
Information computed with MobSF.
High | Service (com.samsung.android.dsms.DsmsUploaderService) is Protected by a permission, but the protection level of the permission should be checked.Permission: com.samsung.android.dsms.permission.SEND_MESSAGE [android:exported=true] A Service is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission which is not defined in the analysed application. As a result, the protection level of the permission should be checked where it is defined. If it is set to normal or dangerous, a malicious application can request and obtain the permission and interact with the component. If it is set to signature, only applications signed with the same certificate can obtain the permission. |
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Oldest file found in APK | Jan. 1, 2009, midnight |
Latest file found in APK | Jan. 1, 2009, midnight |
Certificate valid not before | Nov. 13, 2018, 8:18 a.m. |
First submission on VT | Aug. 16, 2021, 5:52 a.m. |
Last submission on VT | Aug. 16, 2021, 5:52 a.m. |
Upload on Pithus | June 4, 2022, 9:53 a.m. |
Certificate valid not after | Nov. 12, 2118, 3 p.m. |
Score | 1/59 |
Report | https://www.virustotal.com/gui/file/b9fe6eb29f5a138935b6585e17899586e522c992acfa08b94b14bae569a5960a/detection |
Information computed with MobSF.
FCS_RBG_EXT.1.1 | The application invoke platform-provided DRBG functionality for its cryptographic operations. Random Bit Generation Services |
FCS_STO_EXT.1.1 | The application does not store any credentials to non-volatile memory. Storage of Credentials |
FCS_CKM_EXT.1.1 | The application generate no asymmetric cryptographic keys. Cryptographic Key Generation Services |
FDP_DEC_EXT.1.1 | The application has access to ['network connectivity']. Access to Platform Resources |
FDP_DEC_EXT.1.2 | The application has access to no sensitive information repositories. Access to Platform Resources |
FDP_NET_EXT.1.1 | The application has no network communications. Network Communications |
FDP_DAR_EXT.1.1 | The application does not encrypt files in non-volatile memory. Encryption Of Sensitive Application Data |
FMT_MEC_EXT.1.1 | The application invoke the mechanisms recommended by the platform vendor for storing and setting configuration options. Supported Configuration Mechanism |
FTP_DIT_EXT.1.1 | The application does encrypt some transmitted data with HTTPS/TLS/SSH between itself and another trusted IT product. Protection of Data in Transit |
FCS_RBG_EXT.2.1 FCS_RBG_EXT.2.2 |
The application perform all deterministic random bit generation (DRBG) services in accordance with NIST Special Publication 800-90A using Hash_DRBG. The deterministic RBG is seeded by an entropy source that accumulates entropy from a platform-based DRBG and a software-based noise source, with a minimum of 256 bits of entropy at least equal to the greatest security strength (according to NIST SP 800-57) of the keys and hashes that it will generate. Random Bit Generation from Application |
FCS_COP.1.1(2) | The application perform cryptographic hashing services in accordance with a specified cryptographic algorithm SHA-1/SHA-256/SHA-384/SHA-512 and message digest sizes 160/256/384/512 bits. Cryptographic Operation - Hashing |
FCS_HTTPS_EXT.1.1 | The application implement the HTTPS protocol that complies with RFC 2818. HTTPS Protocol |
FCS_HTTPS_EXT.1.2 | The application implement HTTPS using TLS. HTTPS Protocol |
FIA_X509_EXT.2.1 | The application use X.509v3 certificates as defined by RFC 5280 to support authentication for HTTPS , TLS. X.509 Certificate Authentication |
Information computed with MobSF.
Map computed by Pithus.
Information computed with MobSF.
Information computed with MobSF.
https://diagmon-serviceapi.samsungdm.com https://diagmon-policy.samsungdm.com Defined in a/b/a/a/a/a/c/d.java |
|
https://diagmon-serviceapi.samsungdm.com https://diagmon-policy.samsungdm.com Defined in a/b/a/a/a/a/c/d.java |
|
https://stg-api.di.atlas.samsung.com https://regi.di.atlas.samsung.com https://dc.di.atlas.samsung.com Defined in a/a/a/a/a/a/a/c.java |
|
https://stg-api.di.atlas.samsung.com https://regi.di.atlas.samsung.com https://dc.di.atlas.samsung.com Defined in a/a/a/a/a/a/a/c.java |
|
https://stg-api.di.atlas.samsung.com https://regi.di.atlas.samsung.com https://dc.di.atlas.samsung.com Defined in a/a/a/a/a/a/a/c.java |
Information computed with MobSF.
Information computed with Quark-Engine.
Confidence:
|
Connect to a URL and receive input stream from the server |
Confidence:
|
Method reflection |
Confidence:
|
Put data in cursor to JSON object |
Confidence:
|
Connect to a URL and get the response code |
Confidence:
|
Monitor the broadcast action events (BOOT_COMPLETED) |
Confidence:
|
Connect to a URL and set request method |
Confidence:
|
Get resource file from res/raw directory |
Confidence:
|
Read data and put it into a buffer stream |
Confidence:
|
Read file and put it into a stream |
Confidence:
|
Put buffer stream (data) to JSON object |
Confidence:
|
Read file into a stream and put it into a JSON object |
Information computed with MobSF.
Information computed by Pithus.