0/63

Threat

com.samsung.android.game.gametools

Game Booster

Analyzed on 2022-09-27T10:13:03.211071

40

permissions

15

activities

7

services

7

receivers

5

domains

File sums

MD5 429280a7d0469d39f08e47024f08cbbd
SHA1 f5528abe0f7e87c0be9efc6cb5956f00f46ff20d
SHA256 f7062a2bff91431fa6dfe3621e6e118441373fa487fa5a4c25a4f47f7cc63055
Size 8.09MB

APKiD

Information computed with APKiD.

/tmp/tmpkq0ph37o!classes.dex
yara_issue
  • yara issue - dex file recognized by apkid but not yara module
anti_vm
  • Build.FINGERPRINT check
  • Build.MANUFACTURER check
compiler
  • unknown (please file detection issue!)

SSdeep

Information computed with ssdeep.

APK file 98304:ny79rbpEZ6UwzUhnIh6Xe3LY2wb+y08sfrCFJ573JtZebs/:ny79kKUN/2wb+y069JtZN
Manifest 768:DF9RHWGCb8bCu9NAl1yyDYZ4BU5WDLpkQsGg2orEopONJaz5e3Fj3vMlXOXMK0hb:…
classes.dex 49152:+I379aE60bjSb0EZscCUe4q1VtbFGldhn5CmFIbd63VVe3XbY2K8uPb+y06:+y7…

Dexofuzzy

Information computed with Dexofuzzy.

classes.dex None

APK details

Information computed with AndroGuard and Pithus.

Package com.samsung.android.game.gametools
App name Game Booster
Version name 4.0.00.35
Version code 400004035
SDK 30 - 31
UAID ad783f2ffb5c9185635faef478e4ae49944a1616
Signature Signature V1 Signature V2
Frosting Not frosted
Blocks found within V2 signature:
  • 0x7109871a: Unknown
  • 0x42726577: Verity padding

Certificate details

Information computed with AndroGuard.

MD5 d087e72912fba064cafa78dc34aea839
SHA1 9ca5170f381919dfe0446fcdab18b19a143b3163
SHA256 34df0e7a9f1cf1892e45c056b4973cd81ccf148a4050d11aea4ac5a65f900a42
Issuer Email Address: android.os@samsung.com, Common Name: Samsung Cert, Organizational Unit: DMC, Organization: Samsung Corporation, Locality: Suwon City, State/Province: South Korea, Country: KR
Not before 2011-06-22T12:25:12+00:00
Not after 2038-11-07T12:25:12+00:00

File Analysis

Information computed with MobSF.

Findings Files
Certificate/Key files hardcoded inside the app. SEC-INF/buildConfirm.crt

Manifest analysis

Information computed with MobSF.

High Service (com.samsung.android.game.gametools.floatingui.service.external.GameBoosterService) is Protected by a permission, but the protection level of the permission should be checked.
Permission: android.permission.HARDWARE_TEST [android:exported=true]
A Service is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission which is not defined in the analysed application. As a result, the protection level of the permission should be checked where it is defined. If it is set to normal or dangerous, a malicious application can request and obtain the permission and interact with the component. If it is set to signature, only applications signed with the same certificate can obtain the permission.
Low Service (com.samsung.android.game.gametools.floatingui.service.external.GamePadIntentService) is Protected by a permission, but the protection level of the permission should be checked.
Permission: com.samsung.android.game.gametools.permission.UI_REQUEST
protectionLevel: signatureOrSystem [android:exported=true]
A Service is found to be exported, but is protected by a permission. However, the protection level of the permission is set to signatureOrSystem. It is recommended that signature level is used instead. Signature level should suffice for most purposes, and does not depend on where the applications are installed on the device.
Low Broadcast Receiver (com.samsung.android.game.gametools.floatingui.receiver.GppOptimizationReceiver) is Protected by a permission, but the protection level of the permission should be checked.
Permission: com.samsung.android.game.gametools.permission.UI_REQUEST
protectionLevel: signatureOrSystem [android:exported=true]
A Broadcast Receiver is found to be exported, but is protected by a permission. However, the protection level of the permission is set to signatureOrSystem. It is recommended that signature level is used instead. Signature level should suffice for most purposes, and does not depend on where the applications are installed on the device.
High Broadcast Receiver (com.samsung.android.game.gametools.floatingui.receiver.XCloudReceiver) is Protected by a permission, but the protection level of the permission should be checked.
Permission: com.samsung.android.game.gametools.permission.GAME_BOOSTER
protectionLevel: normal [android:exported=true]
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission. However, the protection level of the permission is set to normal. This means that a malicious application can request and obtain the permission and interact with the component. If it was set to signature, only applications signed with the same certificate could obtain the permission.
High Broadcast Receiver (com.samsung.android.game.gametools.setting.receiver.PackageChangedReceiver) is Protected by a permission, but the protection level of the permission should be checked.
Permission: android.permission.WRITE_SECURE_SETTINGS [android:exported=true]
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission which is not defined in the analysed application. As a result, the protection level of the permission should be checked where it is defined. If it is set to normal or dangerous, a malicious application can request and obtain the permission and interact with the component. If it is set to signature, only applications signed with the same certificate can obtain the permission.
High Broadcast Receiver (com.samsung.android.game.gametools.ssrm.OverHeatReceiver) is Protected by a permission, but the protection level of the permission should be checked.
Permission: android.permission.HARDWARE_TEST [android:exported=true]
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission which is not defined in the analysed application. As a result, the protection level of the permission should be checked where it is defined. If it is set to normal or dangerous, a malicious application can request and obtain the permission and interact with the component. If it is set to signature, only applications signed with the same certificate can obtain the permission.
High Broadcast Receiver (com.samsung.android.game.gametools.setting.receiver.LocalChangedReceiver) is not Protected. [android:exported=true]
A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device.
High TaskAffinity is set for Activity
(com.samsung.android.game.gametools.setting.ui.SettingGameBoosterMainActivity)
If taskAffinity is set, then other application could read the Intents sent to Activities belonging to another task. Always use the default setting keeping the affinity as the package name in order to prevent sensitive information inside sent or received Intents from being read by another application.
Low Activity (com.samsung.android.game.gametools.setting.ui.SettingGameBoosterDefaultActivity) is Protected by a permission, but the protection level of the permission should be checked.
Permission: com.samsung.android.permission.LAUNCH_SETTING_GAMES
protectionLevel: signatureOrSystem [android:exported=true]
An Activity is found to be exported, but is protected by a permission. However, the protection level of the permission is set to signatureOrSystem. It is recommended that signature level is used instead. Signature level should suffice for most purposes, and does not depend on where the applications are installed on the device.
High TaskAffinity is set for Activity
(com.samsung.android.game.gametools.setting.ui.SettingHelpActivity)
If taskAffinity is set, then other application could read the Intents sent to Activities belonging to another task. Always use the default setting keeping the affinity as the package name in order to prevent sensitive information inside sent or received Intents from being read by another application.
High TaskAffinity is set for Activity
(com.samsung.android.game.gametools.setting.ui.SettingLabsActivity)
If taskAffinity is set, then other application could read the Intents sent to Activities belonging to another task. Always use the default setting keeping the affinity as the package name in order to prevent sensitive information inside sent or received Intents from being read by another application.
High TaskAffinity is set for Activity
(com.samsung.android.game.gametools.setting.ui.SettingAboutActivity)
If taskAffinity is set, then other application could read the Intents sent to Activities belonging to another task. Always use the default setting keeping the affinity as the package name in order to prevent sensitive information inside sent or received Intents from being read by another application.
High TaskAffinity is set for Activity
(com.samsung.android.game.gametools.setting.ui.SettingPopupPanelActivity)
If taskAffinity is set, then other application could read the Intents sent to Activities belonging to another task. Always use the default setting keeping the affinity as the package name in order to prevent sensitive information inside sent or received Intents from being read by another application.
High TaskAffinity is set for Activity
(com.samsung.android.game.gametools.setting.ui.SettingBlockDuringGameActivity)
If taskAffinity is set, then other application could read the Intents sent to Activities belonging to another task. Always use the default setting keeping the affinity as the package name in order to prevent sensitive information inside sent or received Intents from being read by another application.
High Content Provider (com.samsung.android.game.gametools.setting.GameBoosterSettingSearchProvider) is Protected by a permission, but the protection level of the permission should be checked.
Permission: android.permission.READ_SEARCH_INDEXABLES [android:exported=true]
A Content Provider is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission which is not defined in the analysed application. As a result, the protection level of the permission should be checked where it is defined. If it is set to normal or dangerous, a malicious application can request and obtain the permission and interact with the component. If it is set to signature, only applications signed with the same certificate can obtain the permission.

Activities

Information computed with AndroGuard.

com.samsung.android.game.gametools.floatingui.activity.ScreenshotDeleteDialogActivity
com.samsung.android.game.gametools.floatingui.activity.RecordedFileDeleteDialogActivity
com.samsung.android.game.gametools.floatingui.activity.DiscordRequestPermissionActivity
com.samsung.android.game.gametools.floatingui.activity.RuntimePermissionActivity
com.samsung.android.game.gametools.priority.EmptyActivity
com.samsung.android.game.gametools.setting.ui.SettingGameBoosterMainActivity
com.samsung.android.game.gametools.setting.ui.SettingGameBoosterDefaultActivity
com.samsung.android.game.gametools.setting.ui.SettingHelpActivity
com.samsung.android.game.gametools.setting.ui.SettingLabsActivity
com.samsung.android.game.gametools.setting.ui.SettingAboutActivity
com.samsung.android.game.gametools.setting.ui.SettingPopupPanelActivity
com.samsung.android.game.gametools.setting.ui.MaxPerformanceWelcomeActivity
com.samsung.android.game.gametools.setting.ui.DreamOpenSourceLicenseActivity
com.samsung.android.game.gametools.setting.ui.SettingBlockDuringGameActivity
com.samsung.android.game.gametools.setting.ui.SettingMaxPerformanceBoostWarningDialogActivity

Receivers

Information computed with AndroGuard.

com.samsung.android.game.gametools.floatingui.receiver.GameBoosterBootCompleteReceiver
com.samsung.android.game.gametools.floatingui.receiver.GameToolsSetupWizardCompleteReceiver
com.samsung.android.game.gametools.floatingui.receiver.GppOptimizationReceiver
com.samsung.android.game.gametools.floatingui.receiver.XCloudReceiver
com.samsung.android.game.gametools.setting.receiver.PackageChangedReceiver
com.samsung.android.game.gametools.ssrm.OverHeatReceiver
com.samsung.android.game.gametools.setting.receiver.LocalChangedReceiver

Services

Information computed with AndroGuard.

com.samsung.android.game.gametools.floatingui.service.external.GameBoosterService
com.samsung.android.game.gametools.floatingui.service.external.GamePadIntentService
com.samsung.android.game.gametools.floatingui.service.internal.NavigationIntentService
com.samsung.android.game.gametools.floatingui.service.internal.NotificationIntentService
com.samsung.android.game.gametools.floatingui.service.internal.AlarmIntentService
com.samsung.android.game.gametools.floatingui.service.internal.ScreenShotIntentService
com.samsung.android.game.gametools.floatingui.service.internal.RecordingEndIntentService

Sample timeline

Oldest file found in APK Jan. 1, 2009, midnight
Latest file found in APK Jan. 1, 2009, midnight
Certificate valid not before June 22, 2011, 12:25 p.m.
First submission on VT July 9, 2022, midnight
Last submission on VT July 9, 2022, midnight
Upload on Pithus Sept. 27, 2022, 10:13 a.m.
Certificate valid not after Nov. 7, 2038, 12:25 p.m.

NIAP analysis

Information computed with MobSF.

FCS_RBG_EXT.1.1 The application invoke platform-provided DRBG functionality for its cryptographic operations.
Random Bit Generation Services
FCS_STO_EXT.1.1 The application does not store any credentials to non-volatile memory.
Storage of Credentials
FCS_CKM_EXT.1.1 The application generate no asymmetric cryptographic keys.
Cryptographic Key Generation Services
FDP_DEC_EXT.1.1 The application has access to ['microphone', 'network connectivity'].
Access to Platform Resources
FDP_DEC_EXT.1.2 The application has access to no sensitive information repositories.
Access to Platform Resources
FDP_NET_EXT.1.1 The application has user/application initiated network communications.
Network Communications
FDP_DAR_EXT.1.1 The application implement functionality to encrypt sensitive data in non-volatile memory.
Encryption Of Sensitive Application Data
FMT_MEC_EXT.1.1 The application invoke the mechanisms recommended by the platform vendor for storing and setting configuration options.
Supported Configuration Mechanism
FTP_DIT_EXT.1.1 The application does encrypt some transmitted data with HTTPS/TLS/SSH between itself and another trusted IT product.
Protection of Data in Transit
FCS_RBG_EXT.2.1
FCS_RBG_EXT.2.2
The application perform all deterministic random bit generation (DRBG) services in accordance with NIST Special Publication 800-90A using Hash_DRBG. The deterministic RBG is seeded by an entropy source that accumulates entropy from a platform-based DRBG and a software-based noise source, with a minimum of 256 bits of entropy at least equal to the greatest security strength (according to NIST SP 800-57) of the keys and hashes that it will generate.
Random Bit Generation from Application
FCS_COP.1.1(2) The application perform cryptographic hashing services in accordance with a specified cryptographic algorithm SHA-1/SHA-256/SHA-384/SHA-512 and message digest sizes 160/256/384/512 bits.
Cryptographic Operation - Hashing
FCS_HTTPS_EXT.1.1 The application implement the HTTPS protocol that complies with RFC 2818.
HTTPS Protocol
FCS_HTTPS_EXT.1.2 The application implement HTTPS using TLS.
HTTPS Protocol
FCS_HTTPS_EXT.1.3 The application notify the user and not establish the connection or request application authorization to establish the connection if the peer certificate is deemed invalid.
HTTPS Protocol
FIA_X509_EXT.2.1 The application use X.509v3 certificates as defined by RFC 5280 to support authentication for HTTPS , TLS.
X.509 Certificate Authentication

Code analysis

Information computed with MobSF.

Low
CVSS:7.5
The App logs information. Sensitive information should never be logged.
MASVS: MSTG-STORAGE-3
CWE-532 Insertion of Sensitive Information into Log File
Files:
 com/bumptech/glide/load/data/l.java
com/bumptech/glide/load/n/h.java
a/g/f/j.java
a/g/e/d/a.java
com/bumptech/glide/load/o/t.java
com/bumptech/glide/u/l/a.java
com/bumptech/glide/p/s.java
com/bumptech/glide/s/h.java
a/g/f/k.java
com/bumptech/glide/load/data/o/e.java
b/b/a/a/a/b/e/a.java
com/bumptech/glide/p/r.java
a/g/m/h.java
com/bumptech/glide/load/data/b.java
a/s/a/a/i.java
com/bumptech/glide/p/f.java
a/g/m/j.java
com/bumptech/glide/load/o/f.java
b/b/a/a/a/b/e/b.java
a/g/m/g0/c.java
com/bumptech/glide/load/p/h/j.java
com/bumptech/glide/load/n/q.java
a/l/e.java
b/a/a/a/a0/g.java
com/bumptech/glide/load/p/h/d.java
com/bumptech/glide/load/n/b0/i.java
com/bumptech/glide/load/data/j.java
com/bumptech/glide/p/e.java
com/bumptech/glide/o/e.java
a/l/d.java
a/a/l/a/a.java
com/bumptech/glide/p/o.java
com/bumptech/glide/load/n/k.java
com/bumptech/glide/load/data/o/c.java
b/a/a/a/x/d.java
com/bumptech/glide/load/n/c0/b.java
b/c/a/a/a/b/a.java
a/j/a/a.java
com/bumptech/glide/load/p/d/d.java
a/p/h/e.java
a/p/h/h.java
com/samsung/context/sdk/samsunganalytics/j/k/b.java
a/n/a/b.java
a/g/e/d/b.java
a/g/i/d.java
a/r/y.java
com/bumptech/glide/load/n/a0/j.java
com/bumptech/glide/load/n/z.java
com/bumptech/glide/load/p/d/n.java
a/a/p/c.java
com/bumptech/glide/load/p/h/a.java
a/p/a.java
com/bumptech/glide/load/p/d/z.java
a/g/f/e.java
com/samsung/android/game/gametools/common/monitor/request/SimpleRequest.java
b/a/a/a/y/b.java
a/g/m/f0.java
a/q/a.java
com/bumptech/glide/load/p/d/b0.java
com/bumptech/glide/load/p/d/c.java
com/bumptech/glide/load/p/a.java
com/bumptech/glide/load/p/d/m.java
com/bumptech/glide/t/b.java
a/g/f/c.java
a/g/m/b.java
a/g/f/f.java
a/g/k/b.java
com/bumptech/glide/load/n/a0/k.java
a/g/m/y.java
a/g/e/d/f.java
a/g/l/c.java
com/bumptech/glide/o/d.java
a/e/b/k/f.java
b/b/a/b/a/a/b.java
a/i/a/c.java
com/bumptech/glide/q/d.java
com/bumptech/glide/load/p/d/k.java
com/bumptech/glide/load/o/c.java
com/bumptech/glide/GeneratedAppGlideModuleImpl.java
com/bumptech/glide/p/p.java
com/bumptech/glide/c.java
a/g/f/g.java
com/bumptech/glide/load/n/c0/a.java
com/bumptech/glide/s/j/i.java
a/g/m/a0.java
a/a/q/g.java
com/bumptech/glide/load/n/b0/e.java
a/g/m/x.java
b/a/a/a/l/h.java
com/bumptech/glide/load/p/d/r.java
com/airbnb/lottie/y/c.java
com/bumptech/glide/load/o/d.java
com/airbnb/lottie/LottieAnimationView.java
a/l/c.java
com/bumptech/glide/load/o/s.java
com/bumptech/glide/load/n/i.java
a/r/i0.java
Medium
CVSS:7.4
Files may contain hardcoded sensitive information like usernames, passwords, keys etc.
MASVS: MSTG-STORAGE-14
CWE-312 Cleartext Storage of Sensitive Information
M9: Reverse Engineering
Files:
 com/bumptech/glide/load/h.java
com/bumptech/glide/load/n/d.java
com/bumptech/glide/load/n/p.java
com/bumptech/glide/load/n/x.java
Medium
CVSS:5.5
App creates temp file. Sensitive information should never be written into a temp file.
MASVS: MSTG-STORAGE-2
CWE-276 Incorrect Default Permissions
M2: Insecure Data Storage
Files:
 a/j/a/a.java
b/a/b/e.java
Medium
CVSS:5.9
App uses SQLite Database and execute raw SQL query. Untrusted user input in raw SQL queries can cause SQL Injection. Also sensitive information should be encrypted and written to the database.
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
M7: Client Code Quality
Files:
 com/samsung/context/sdk/samsunganalytics/j/h/h/b/a.java
com/samsung/context/sdk/samsunganalytics/j/h/h/b/b.java
Info
CVSS:0
This App uses SSL certificate pinning to detect or prevent MITM attacks in secure communication channel.
MASVS: MSTG-NETWORK-4
Files:
 com/samsung/context/sdk/samsunganalytics/j/g/a.java
Medium
CVSS:5.9
SHA-1 is a weak hash known to have hash collisions.
MASVS: MSTG-CRYPTO-4
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
M5: Insufficient Cryptography
Files:
 b/a/b/l/a/d/l.java
Pygal Ireland: 100 United States: 200

Map computed by Pithus.

Domains analysis

Information computed with MobSF.

US regi.di.atlas.samsung.com 34.102.190.55
schemas.android.com
US dc.di.atlas.samsung.com 34.120.24.208
IE vas.samsungapps.com 34.241.41.39
ns.adobe.com

URL analysis

Information computed with MobSF.

https://regi.di.atlas.samsung.com
https://dc.di.atlas.samsung.com
Defined in com/samsung/context/sdk/samsunganalytics/j/c/c.java
https://regi.di.atlas.samsung.com
https://dc.di.atlas.samsung.com
Defined in com/samsung/context/sdk/samsunganalytics/j/c/c.java
https://vas.samsungapps.com/product/getContentCategoryProductList.as
Defined in com/samsung/android/game/gametools/common/utility/o0.java
https://vas.samsungapps.com/stub/stubUpdateCheck.as
Defined in b/b/a/a/a/b/i/f.java
http://schemas.android.com/apk/res/android
Defined in a/g/e/d/g.java
http://ns.adobe.com/xap/1.0/
Defined in a/j/a/a.java

Permissions analysis

Information computed with MobSF.

High android.permission.SET_PROCESS_LIMIT limit number of running processes
Allows an application to control the maximum number of processes that will run. Never needed for common applications.
High android.permission.RECORD_AUDIO record audio
Allows application to access the audio record path.
High android.permission.SYSTEM_ALERT_WINDOW display system-level alerts
Allows an application to show system-alert windows. Malicious applications can take over the entire screen of the phone.
High android.permission.WRITE_SETTINGS modify global system settings
Allows an application to modify the system's settings data. Malicious applications can corrupt your system's configuration.
Low android.permission.FOREGROUND_SERVICE Allows a regular application to use Service.startForeground.
Low android.permission.ACCESS_NETWORK_STATE view network status
Allows an application to view the status of all networks.
Low android.permission.INTERNET full Internet access
Allows an application to create network sockets.
Low android.permission.EXPAND_STATUS_BAR expand/collapse status bar
Allows application to expand or collapse the status bar.
Low android.permission.RECEIVE_BOOT_COMPLETED automatically start at boot
Allows an application to start itself as soon as the system has finished booting. This can make it take longer to start the phone and allow the application to slow down the overall phone by always running.
Low android.permission.KILL_BACKGROUND_PROCESSES kill background processes
Allows an application to kill background processes of other applications, even if memory is not low.
Low android.permission.QUERY_ALL_PACKAGES Allows query of any normal app on the device, regardless of manifest declarations.
Low android.permission.SCHEDULE_EXACT_ALARM Allows an app to use exact alarm scheduling APIs to perform timing sensitive background work.
Medium android.permission.FORCE_STOP_PACKAGES force-stop other applications
Allows an application to stop other applications forcibly.
Medium android.permission.PACKAGE_USAGE_STATS update component usage statistics
Allows the modification of collected component usage statistics. Not for use by common applications.
Medium android.permission.STOP_APP_SWITCHES prevent app switches
Prevents the user from switching to another application.
Medium android.permission.INTERNAL_SYSTEM_WINDOW display unauthorised windows
Allows the creation of windows that are intended to be used by the internal system user interface. Not for use by common applications.
Medium android.permission.DEVICE_POWER turn phone on or off
Allows the application to turn the phone on or off.
Medium android.permission.ACCESS_SURFACE_FLINGER access SurfaceFlinger
Allows application to use SurfaceFlinger low-level features.
Medium android.permission.READ_FRAME_BUFFER read frame buffer
Allows application to read the content of the frame buffer.
Medium android.permission.STATUS_BAR_SERVICE status bar
Allows the application to be the status bar.
Medium android.permission.INJECT_EVENTS press keys and control buttons
Allows an application to deliver its own input events (key presses, etc.) to other applications. Malicious applications can use this to take over the phone.
Medium android.permission.STATUS_BAR disable or modify status bar
Allows application to disable the status bar or add and remove system icons.
Medium android.permission.WRITE_SECURE_SETTINGS modify secure system settings
Allows an application to modify the system's secure settings data. Not for use by common applications.
android.permission.REAL_GET_TASKS Unknown permission
Unknown permission from android reference
android.permission.READ_PRIVILEGED_PHONE_STATE Unknown permission
Unknown permission from android reference
android.permission.START_ACTIVITIES_FROM_BACKGROUND Unknown permission
Unknown permission from android reference
com.sec.android.permission.IN_APP_SOUND Unknown permission
Unknown permission from android reference
android.permission.MANAGE_APP_OPS_RESTRICTIONS Unknown permission
Unknown permission from android reference
android.permission.MANAGE_MEDIA_PROJECTION Unknown permission
Unknown permission from android reference
android.permission.INTERACT_ACROSS_USERS_FULL Unknown permission
Unknown permission from android reference
android.permission.GET_INTENT_SENDER_INTENT Unknown permission
Unknown permission from android reference
android.permission.MANAGE_NOTIFICATIONS Unknown permission
Unknown permission from android reference
com.discord.permission.CONNECT Unknown permission
Unknown permission from android reference
com.samsung.permission.READ_SEC_COMMON_POLICY Unknown permission
Unknown permission from android reference
com.samsung.android.game.gamehome.permission.INVOKE Unknown permission
Unknown permission from android reference
com.samsung.android.bixby.agent.permission.RECEIVE_BIXBY_VIEW_STATE Unknown permission
Unknown permission from android reference
com.gamepass.permission.UPDATE_STATUS Unknown permission
Unknown permission from android reference
com.samsung.android.app.screenrecorder.permission.ACCESS_SCREEN_RECORDER_SVC Unknown permission
Unknown permission from android reference
com.samsung.android.mdx.permission.RECEIVE_MIRRORING_STATE Unknown permission
Unknown permission from android reference
android.permission.READ_SEARCH_INDEXABLES Unknown permission
Unknown permission from android reference

Threat analysis

Information computed with Quark-Engine.

Confidence:
100%
Load external class
Confidence:
100%
Implicit intent(view a web page, make a phone call, etc.)
Confidence:
100%
Query the list of the installed packages
Confidence:
100%
Find a method from given class name, usually for reflection
Confidence:
100%
Connect to a URL and receive input stream from the server
Confidence:
100%
Method reflection
Confidence:
100%
Load class from given class name
Confidence:
100%
Get declared method from given method name
Confidence:
100%
Read sensitive data(SMS, CALLLOG, etc)
Confidence:
100%
Open a file from given absolute path of the file
Confidence:
100%
Implicit intent(view a web page, make a phone call, etc.) via setData
Confidence:
100%
Connect to a URL and get the response code
Confidence:
100%
Monitor the broadcast action events (BOOT_COMPLETED)
Confidence:
100%
Get absolute path of the file and store in string
Confidence:
100%
Check the current active network type
Confidence:
100%
Query the IMSI number
Confidence:
100%
Query The ISO country code
Confidence:
100%
Check the network capabilities
Confidence:
100%
Get last known location of the device
Confidence:
100%
Load additional DEX files dynamically
Confidence:
100%
Method reflection
Confidence:
100%
Hide the current app's icon
Confidence:
100%
Connect to the remote server through the given URL
Confidence:
100%
Query data from URI (SMS, CALLLOGS)
Confidence:
100%
Get the time of current location
Confidence:
100%
Initialize class object dynamically
Confidence:
100%
Connect to a URL and set request method
Confidence:
100%
Get resource file from res/raw directory
Confidence:
100%
Get specific method from other Dex files
Confidence:
80%
Start another application from current application
Confidence:
80%
Read data and put it into a buffer stream
Confidence:
80%
Read file and put it into a stream
Confidence:
80%
Get calendar information
Confidence:
80%
Get location of the device

Behavior analysis

Information computed with MobSF.

Android notifications
       b/b/a/a/a/d/c/k.java
com/samsung/android/game/gametools/floatingui/service/external/GameBoosterService.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/p2.java
b/b/a/a/a/d/b/e.java
b/b/a/a/a/d/a/e/d.java
Base64 decode
       a/g/e/d/c.java
com/airbnb/lottie/u/b.java
com/bumptech/glide/load/o/e.java
com/samsung/android/game/gametools/common/utility/h1.java
Base64 encode
       com/samsung/android/game/gametools/common/utility/h1.java
a/g/j/d.java
Content provider
       b/b/a/b/a/a/b.java
b/b/a/b/a/a/d.java
Crypto
       b/b/a/a/a/b/d/f.java
com/samsung/android/game/gametools/common/utility/h1.java
Dynamic class and dexloading
       b/a/b/e.java
Get installed applications
       com/samsung/android/game/gametools/common/utility/z0.java
com/samsung/android/game/gametools/common/utility/p.java
Get sim provider details
       com/samsung/context/sdk/samsunganalytics/j/d/a.java
Get subscriber id
       b/b/a/a/a/b/c/d.java
Get system service
       a/i/a/a.java
a/h/a/c.java
a/g/e/a.java
b/b/a/a/a/b/c/c.java
com/samsung/context/sdk/samsunganalytics/j/h/b/b.java
com/samsung/context/sdk/samsunganalytics/j/b.java
com/bumptech/glide/load/n/b0/i.java
com/bumptech/glide/s/j/i.java
com/samsung/android/game/gametools/common/utility/y0.java
com/samsung/context/sdk/samsunganalytics/j/d/a.java
com/samsung/android/game/gametools/common/recorder/core/BaseMP4Recorder.java
com/bumptech/glide/p/e.java
a/g/m/x.java
a/a/q/d.java
Http connection
       b/b/a/a/a/b/i/d.java
com/airbnb/lottie/w/a.java
b/b/a/a/a/b/i/j.java
com/bumptech/glide/load/data/j.java
com/airbnb/lottie/w/b.java
b/b/a/a/a/b/i/f.java
Https connection
       com/samsung/context/sdk/samsunganalytics/j/e/a.java
com/samsung/context/sdk/samsunganalytics/j/j/a.java
com/samsung/context/sdk/samsunganalytics/j/h/b/a.java
b/b/a/a/a/b/i/f.java
Inter process communication
       b/b/a/a/a/d/a/e/e.java
com/samsung/android/game/gametools/floatingui/dreamtools/menu/DreamToolsMainView.java
b/b/a/a/a/b/c/f.java
com/samsung/android/game/gametools/common/utility/v0.java
com/samsung/android/game/gametools/setting/preference/controller/FAQPreferenceController.java
com/samsung/android/game/gametools/common/utility/l0.java
com/samsung/android/game/gametools/common/utility/o0.java
com/samsung/android/game/gametools/setting/preference/controller/HelpPreferenceController.java
com/samsung/android/game/gametools/floatingui/service/internal/ScreenShotIntentService.java
com/samsung/android/game/gametools/common/utility/d1.java
com/samsung/android/game/gametools/setting/ui/SettingGameBoosterMainActivity.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/q2.java
com/samsung/android/game/gametools/setting/preference/controller/AboutGameBoosterPreferenceController.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/u2.java
com/samsung/android/game/gos/IGosService.java
com/samsung/android/game/gametools/floatingui/dreamtools/menu/submenu/AppInterruptionsDetailMenu.java
com/samsung/android/game/gametools/common/utility/s.java
com/samsung/android/game/gametools/setting/ui/b0.java
com/samsung/android/game/gametools/common/recorder/exception/PhoneOffHookException$offHookLocalReceiver$1.java
b/b/a/a/a/b/g/j/a.java
com/samsung/android/game/gametools/floatingui/receiver/XCloudReceiver.java
com/samsung/android/game/gametools/setting/preference/controller/ContactUsInMainPreferenceController.java
com/samsung/android/game/gametools/setting/preference/controller/LabsPreferenceController.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/EventImpl.java
com/samsung/android/game/gametools/common/utility/g1.java
com/samsung/android/game/gametools/floatingui/receiver/a.java
com/samsung/android/game/gametools/floatingui/service/external/GamePadIntentService.java
com/samsung/android/game/gametools/common/utility/GosQueryUtil.java
com/samsung/context/sdk/samsunganalytics/j/k/d.java
com/samsung/android/game/gametools/ssrm/OverHeatReceiver.java
com/samsung/android/hardware/display/ILowRefreshRateToken.java
com/samsung/android/game/gametools/floatingui/service/internal/NotificationIntentService.java
com/samsung/android/game/gametools/common/utility/v1.java
com/samsung/android/game/gametools/floatingui/dreamtools/menu/FoxToolsMainView.java
com/samsung/android/game/gametools/setting/preference/controller/PopupPanelPreferenceController.java
com/samsung/android/game/gametools/common/recorder/exception/LowBatteryException$batteryBroadCastReceiver$1.java
b/b/a/a/a/d/a/e/d.java
com/samsung/android/game/gametools/common/utility/i1.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/o2.java
com/samsung/android/game/gametools/setting/preference/controller/BlockDuringGamePreferenceController.java
com/samsung/android/game/gametools/priority/c.java
com/samsung/android/game/gametools/floatingui/dreamtools/menu/EchoToolsMainView.java
b/b/a/a/a/b/c/b.java
com/samsung/android/game/gametools/setting/preference/controller/GamePerformancePreferenceController.java
com/samsung/android/game/gametools/setting/ui/SettingBlockDuringGameActivity.java
b/b/a/a/a/d/c/k.java
com/samsung/android/game/gametools/floatingui/service/external/GameBoosterService.java
com/samsung/android/game/gametools/setting/preference/controller/HeatControlWhileChargingPreferenceController.java
b/b/a/a/a/d/b/e.java
com/samsung/android/game/gametools/setting/receiver/LocalChangedReceiver.java
a/g/e/a.java
com/samsung/android/game/gametools/common/utility/c0.java
com/samsung/android/game/gametools/common/utility/x0.java
com/samsung/android/game/gametools/setting/preference/controller/ContactUsInHelpPreferenceController.java
com/samsung/android/game/gametools/setting/receiver/PackageChangedReceiver.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/BaseLockScreenManager.java
a/r/k0.java
com/samsung/android/game/gametools/floatingui/activity/RuntimePermissionActivity.java
com/samsung/android/game/gametools/setting/ui/SettingGameBoosterDefaultActivity.java
com/bumptech/glide/p/e.java
com/samsung/android/game/gametools/floatingui/service/internal/a.java
com/samsung/android/game/gametools/common/utility/n0.java
com/samsung/android/game/gametools/floatingui/service/internal/NavigationIntentService.java
com/samsung/android/game/gametools/common/view/d.java
com/samsung/android/game/gametools/floatingui/receiver/GameToolsSetupWizardCompleteReceiver.java
com/samsung/context/sdk/samsunganalytics/j/h/c/a.java
com/samsung/android/game/gametools/common/utility/p.java
com/samsung/android/game/gametools/common/monitor/effect/ControlEdgeEffectDialog.java
com/samsung/android/game/gametools/common/utility/p0.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/XCloudEventImpl.java
com/samsung/android/game/gametools/floatingui/service/internal/AlarmIntentService.java
com/samsung/android/deviceidservice/IDeviceIdService.java
com/samsung/android/game/gametools/common/utility/e1.java
com/samsung/android/game/gametools/floatingui/activity/ScreenshotDeleteDialogActivity.java
b/c/a/a/b/a.java
com/samsung/android/game/gametools/common/utility/q1.java
com/samsung/android/game/gametools/floatingui/dreamtools/floating/SmartTipPopup.java
com/samsung/android/game/gametools/floatingui/activity/RecordedFileDeleteDialogActivity.java
com/samsung/android/game/gametools/common/recorder/exception/LowBatteryException.java
com/samsung/android/game/gametools/floatingui/receiver/GameBoosterBootCompleteReceiver.java
com/samsung/android/game/gametools/common/utility/z0.java
b/b/a/a/a/b/f/e.java
com/samsung/android/game/gametools/floatingui/receiver/GppOptimizationReceiver.java
b/b/a/a/a/b/d/b.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/t2.java
b/b/a/a/a/d/d/a.java
android/hardware/display/IDisplayManager.java
a/g/i/c.java
com/samsung/android/game/gametools/setting/ui/SettingAboutActivity.java
b/b/a/a/a/d/a/e/c.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/j2.java
com/samsung/android/game/gametools/floatingui/service/internal/RecordingEndIntentService.java
Java reflection
       a/g/i/d.java
a/r/y.java
a/p/i/d.java
a/g/f/j.java
a/p/c/a/a.java
b/a/b/a.java
a/p/a.java
a/g/f/e.java
a/g/m/f0.java
a/q/a.java
a/r/z.java
a/p/h/i.java
a/g/m/h.java
b/a/c/w/m.java
b/a/c/w/d.java
b/a/c/b.java
b/b/a/a/a/b/h/a.java
a/g/f/f.java
a/g/k/b.java
a/p/i/c.java
b/a/b/m/a.java
a/g/m/y.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/h2.java
a/p/i/e.java
a/g/e/d/f.java
com/bumptech/glide/q/d.java
a/p/h/d.java
a/p/h/a.java
a/p/f/a.java
a/p/b/a.java
b/a/c/w/n/i.java
com/samsung/android/game/gametools/common/utility/u.java
com/samsung/context/sdk/samsunganalytics/j/e/c.java
b/a/c/w/o/c.java
a/p/h/g.java
b/a/c/d.java
a/g/m/g.java
com/bumptech/glide/c.java
a/p/e/b.java
a/g/f/g.java
a/p/h/b.java
a/p/d/a/a.java
b/a/c/c.java
a/p/i/b.java
a/a/q/g.java
a/p/h/f.java
a/g/m/x.java
a/g/f/h.java
a/p/b/b/a.java
d/a/a/a/f/a.java
a/p/h/c.java
com/samsung/context/sdk/samsunganalytics/j/e/b.java
com/samsung/android/game/gametools/common/utility/q1.java
com/samsung/android/game/gametools/floatingui/dreamtools/floating/SmartTipPopup.java
a/p/h/e.java
b/b/a/a/a/b/h/b.java
a/p/h/h.java
b/b/a/a/a/b/h/e.java
a/p/g/a.java
a/r/i0.java
a/p/i/a.java
a/p/h/j/a.java
b/a/b/e.java
a/p/e/a.java
Kill process
       com/samsung/android/game/gametools/common/utility/y0.java
Loading native code (shared library)
       com/samsung/context/sdk/samsunganalytics/NativeHelper.java
Local file i/o operations
       com/samsung/android/game/gametools/common/utility/l1.java
com/samsung/context/sdk/samsunganalytics/j/e/c.java
com/samsung/context/sdk/samsunganalytics/j/e/b.java
com/samsung/context/sdk/samsunganalytics/j/k/c.java
com/airbnb/lottie/c.java
com/samsung/android/game/gametools/common/utility/h1.java
com/samsung/context/sdk/samsunganalytics/j/b.java
com/bumptech/glide/load/n/b0/f.java
com/samsung/context/sdk/samsunganalytics/j/i/b.java
a/g/f/k.java
com/samsung/context/sdk/samsunganalytics/j/e/a.java
com/samsung/context/sdk/samsunganalytics/j/i/a.java
com/samsung/android/game/gametools/common/utility/t1.java
Message digest
       com/bumptech/glide/load/n/n.java
com/samsung/context/sdk/samsunganalytics/j/e/c.java
com/bumptech/glide/load/h.java
com/bumptech/glide/load/p/d/o.java
com/bumptech/glide/t/d.java
com/bumptech/glide/load/p/h/f.java
com/bumptech/glide/load/n/d.java
com/bumptech/glide/t/a.java
com/bumptech/glide/t/c.java
com/bumptech/glide/load/p/d/i.java
com/bumptech/glide/load/o/g.java
com/bumptech/glide/load/p/d/q.java
com/bumptech/glide/load/p/d/j.java
com/bumptech/glide/load/g.java
b/a/b/l/a/d/l.java
com/bumptech/glide/load/p/d/b0.java
com/bumptech/glide/load/i.java
com/bumptech/glide/load/p/c.java
com/bumptech/glide/load/n/x.java
com/bumptech/glide/load/n/b0/j.java
Query database of sms, contacts etc
       com/bumptech/glide/load/data/o/c.java
com/bumptech/glide/load/data/o/e.java
com/samsung/android/game/gametools/common/utility/a2.java
Sending broadcast
       com/samsung/android/game/gametools/floatingui/dreamtools/manager/t2.java
Starting activity
       com/samsung/android/game/gametools/setting/preference/controller/FAQPreferenceController.java
com/samsung/android/game/gametools/common/utility/o0.java
a/g/e/a.java
com/samsung/android/game/gametools/common/utility/c0.java
com/samsung/android/game/gametools/setting/preference/controller/HelpPreferenceController.java
com/samsung/android/game/gametools/floatingui/service/internal/ScreenShotIntentService.java
com/samsung/android/game/gametools/setting/preference/controller/ContactUsInHelpPreferenceController.java
com/samsung/android/game/gametools/setting/preference/controller/AboutGameBoosterPreferenceController.java
com/samsung/android/game/gametools/floatingui/dreamtools/menu/submenu/AppInterruptionsDetailMenu.java
com/samsung/android/game/gametools/setting/ui/SettingGameBoosterDefaultActivity.java
com/samsung/android/game/gametools/setting/preference/controller/ContactUsInMainPreferenceController.java
com/samsung/android/game/gametools/setting/preference/controller/LabsPreferenceController.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/EventImpl.java
com/samsung/android/game/gametools/common/utility/g1.java
com/samsung/android/game/gametools/floatingui/service/internal/a.java
com/samsung/android/game/gametools/common/utility/n0.java
com/samsung/android/game/gametools/common/utility/p.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/XCloudEventImpl.java
com/samsung/android/game/gametools/floatingui/service/internal/NotificationIntentService.java
com/samsung/android/game/gametools/setting/preference/controller/PopupPanelPreferenceController.java
com/samsung/android/game/gametools/setting/preference/controller/BlockDuringGamePreferenceController.java
com/samsung/android/game/gametools/common/utility/z0.java
b/b/a/a/a/b/c/b.java
com/samsung/android/game/gametools/setting/preference/controller/GamePerformancePreferenceController.java
com/samsung/android/game/gametools/setting/ui/SettingAboutActivity.java
com/samsung/android/game/gametools/floatingui/service/internal/RecordingEndIntentService.java
Starting service
       com/samsung/android/game/gametools/common/utility/v0.java
com/samsung/android/game/gametools/common/utility/e1.java
b/b/a/a/a/b/g/j/a.java
com/samsung/android/game/gametools/floatingui/dreamtools/manager/t2.java
com/samsung/android/game/gametools/common/utility/GosQueryUtil.java
com/samsung/context/sdk/samsunganalytics/j/h/c/a.java
Tcp socket
       com/airbnb/lottie/y/h.java
b/b/a/a/a/b/i/d.java
Url connection to file/http/https/ftp/jar
       b/b/a/a/a/b/i/d.java
b/b/a/a/a/b/i/j.java

Control flow graphs analysis

Information computed by Pithus.

The application probably kills background processes

The application probably gets different information regarding the telephony capabilities

The application probably gets the subscriber ID associated to the SIM card/ Should never be collected

The application probably gets the location based on GPS and/or Wi-Fi

The application probably gets the network connections information

The application probably uses reflection

The application probably uses the phone sensors

The application probably plays sound

The application probably makes OS calls

The application probably sends data over HTTP/S

The application probably lists all installed applications

The application probably starts another application

The application probably gets memory and CPU information

The application probably listens accessibility events