0/61
Threat
Analyzed on 2021-12-26T22:55:00.576762
MD5 | c3091bba3306b7f9f1b1184e551251bd | |
SHA1 | db8004c8b9e69cf6241b73dc23d5d19b250bd147 | |
SHA256 | fb3a01a74375e82d569c5b34827fc4792273b679a879c1f24e6974a6dbacb77e | |
Size | 45.94MB |
Information computed with APKiD.
/tmp/tmpbg1ayhi2!classes.dex | |
anti_vm |
|
compiler |
|
/tmp/tmpbg1ayhi2!classes2.dex | |
anti_vm |
|
anti_debug |
|
compiler |
|
/tmp/tmpbg1ayhi2!classes3.dex | |
compiler |
|
/tmp/tmpbg1ayhi2!classes4.dex | |
compiler |
|
Information computed with ssdeep.
APK file | 786432:rQQ4Km9lMTce0zsZt8yQdoN506NkKt8dVkbyS4R0/QSNXd+QyJ7oDga6zze3uaT7:ZXm940zsQysoN5LNkxdV9AQSRd+PA12e | |
Manifest | 384:qPijseP9UQtzRzwy/GAtYZjdXNXmk4FAFaeYUrrTKJgZnNWJ0p3aPRb4D9ih/SqF:… | |
classes.dex | 98304:gB9mMtwsz378mGMRGPh61F/O+pKSX3+0dK62KIhNFg77:/OGMIPFS+JhkH | |
classes2.dex | 98304:7CYPUsdWJJALQk7z9oOPSMyJv+EFVtaX0MN77e3KJHay5k/Bpb:7CTJNk5EFVta… | |
classes3.dex | 98304:YRz5Fz/ebz4JJQGEFVtaX0MN70EqKWMW1VA5VbX:YteEQGEFVtaX0MN7Uz1VA5V… | |
classes4.dex | 3072:xIfMIK1qKol4JCJHeMRXf/f/f/OkmXgRwo9nr8ALPMLSklp6Pd6fV9dV3brfQ4ZT… |
Information computed with Dexofuzzy.
Information computed with AndroGuard and Pithus.
Information computed with AndroGuard.
Information computed with MobSF.
Findings | Files |
---|---|
Certificate/Key files hardcoded inside the app. |
okhttp3/internal/publicsuffix/NOTICE stamp-cert-sha256 |
Information computed with MobSF.
High | Broadcast Receiver (com.costarastrology.push.NotificationPublisher) is not Protected. [android:exported=true] A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. |
High | Activity (com.facebook.CustomTabActivity) is not Protected. [android:exported=true] An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. |
High | Activity (androidx.compose.ui.tooling.PreviewActivity) is not Protected. [android:exported=true] An Activity is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. |
High | Broadcast Receiver (com.google.firebase.iid.FirebaseInstanceIdReceiver) is Protected by a permission, but the protection level of the permission should be checked.Permission: com.google.android.c2dm.permission.SEND [android:exported=true] A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission which is not defined in the analysed application. As a result, the protection level of the permission should be checked where it is defined. If it is set to normal or dangerous, a malicious application can request and obtain the permission and interact with the component. If it is set to signature, only applications signed with the same certificate can obtain the permission. |
High | Broadcast Receiver (androidx.profileinstaller.ProfileInstallReceiver) is Protected by a permission, but the protection level of the permission should be checked.Permission: android.permission.DUMP [android:exported=true] A Broadcast Receiver is found to be shared with other apps on the device therefore leaving it accessible to any other application on the device. It is protected by a permission which is not defined in the analysed application. As a result, the protection level of the permission should be checked where it is defined. If it is set to normal or dangerous, a malicious application can request and obtain the permission and interact with the component. If it is set to signature, only applications signed with the same certificate can obtain the permission. |
Information computed with MobSF.
com.facebook.CustomTabActivity |
Hosts: cct.com.costarastrology Schemes: fbconnect:// |
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Information computed with AndroGuard.
|
Oldest file found in APK | Jan. 1, 1981, 1:01 a.m. |
Latest file found in APK | Jan. 1, 1981, 1:01 a.m. |
Certificate valid not before | Dec. 9, 2019, 11:36 p.m. |
First submission on VT | Dec. 11, 2021, 10:03 a.m. |
Last submission on VT | Dec. 11, 2021, 10:03 a.m. |
Upload on Pithus | Dec. 26, 2021, 10:55 p.m. |
Certificate valid not after | Dec. 2, 2044, 11:36 p.m. |
Score | 0/61 |
Report | https://www.virustotal.com/gui/file/fb3a01a74375e82d569c5b34827fc4792273b679a879c1f24e6974a6dbacb77e/detection |
Information computed with MobSF.
FCS_RBG_EXT.1.1 | The application invoke platform-provided DRBG functionality for its cryptographic operations. Random Bit Generation Services |
FCS_STO_EXT.1.1 | The application does not store any credentials to non-volatile memory. Storage of Credentials |
FCS_CKM_EXT.1.1 | The application generate no asymmetric cryptographic keys. Cryptographic Key Generation Services |
FDP_DEC_EXT.1.1 | The application has access to ['network connectivity']. Access to Platform Resources |
FDP_DEC_EXT.1.2 | The application has access to ['address book']. Access to Platform Resources |
FDP_NET_EXT.1.1 | The application has user/application initiated network communications. Network Communications |
FDP_DAR_EXT.1.1 | The application implement functionality to encrypt sensitive data in non-volatile memory. Encryption Of Sensitive Application Data |
FMT_MEC_EXT.1.1 | The application invoke the mechanisms recommended by the platform vendor for storing and setting configuration options. Supported Configuration Mechanism |
FTP_DIT_EXT.1.1 | The application does encrypt some transmitted data with HTTPS/TLS/SSH between itself and another trusted IT product. Protection of Data in Transit |
FCS_RBG_EXT.2.1 FCS_RBG_EXT.2.2 |
The application perform all deterministic random bit generation (DRBG) services in accordance with NIST Special Publication 800-90A using Hash_DRBG. The deterministic RBG is seeded by an entropy source that accumulates entropy from a platform-based DRBG and a software-based noise source, with a minimum of 256 bits of entropy at least equal to the greatest security strength (according to NIST SP 800-57) of the keys and hashes that it will generate. Random Bit Generation from Application |
FCS_COP.1.1(2) | The application perform cryptographic hashing services not in accordance with FCS_COP.1.1(2) and uses the cryptographic algorithm RC2/RC4/MD4/MD5. Cryptographic Operation - Hashing |
FCS_COP.1.1(3) | The application perform cryptographic signature services (generation and verification) in accordance with a specified cryptographic algorithm RSA schemes using cryptographic key sizes of 2048-bit or greater. Cryptographic Operation - Signing |
FCS_HTTPS_EXT.1.1 | The application implement the HTTPS protocol that complies with RFC 2818. HTTPS Protocol |
FCS_HTTPS_EXT.1.2 | The application implement HTTPS using TLS. HTTPS Protocol |
FCS_HTTPS_EXT.1.3 | The application notify the user and not establish the connection or request application authorization to establish the connection if the peer certificate is deemed invalid. HTTPS Protocol |
FIA_X509_EXT.2.1 | The application use X.509v3 certificates as defined by RFC 5280 to support authentication for HTTPS , TLS. X.509 Certificate Authentication |
FPT_TUD_EXT.2.1 | The application shall be distributed using the format of the platform-supported package manager. Integrity for Installation and Update |
Information computed with MobSF.
Map computed by Pithus.
Information computed with MobSF.
Information computed with MobSF.
https://github.com/ReactiveX/RxJava/wiki/Plugins Defined in io/reactivex/Flowable.java |
|
https://github.com/ReactiveX/RxJava/wiki/Plugins Defined in io/reactivex/Completable.java |
|
https://github.com/ReactiveX/RxJava/wiki/Plugins Defined in io/reactivex/Maybe.java |
|
https://github.com/ReactiveX/RxJava/wiki/Plugins Defined in io/reactivex/Observable.java |
|
https://github.com/ReactiveX/RxJava/wiki/Plugins Defined in io/reactivex/Single.java |
|
https://github.com/ReactiveX/RxJava/wiki/What's-different-in-2.0#error-handling Defined in io/reactivex/exceptions/UndeliverableException.java |
|
https://github.com/ReactiveX/RxJava/wiki/Error-Handling Defined in io/reactivex/exceptions/OnErrorNotImplementedException.java |
|
http://www.apache.org/licenses/LICENSE-2.0 Defined in kotlin/reflect/jvm/internal/impl/descriptors/annotations/BuiltInAnnotationDescriptor.java |
|
https://api.costarastrology.com Defined in com/costarastrology/BuildConfig.java |
|
https://www.costarastrology.com/contact Defined in com/costarastrology/configuration/RemoteConfigKey.java |
|
https://costar-app-user-profile-photos.s3.amazonaws.com/default-photos/body-mid-07.jpg https://costar-app-user-profile-photos.s3.amazonaws.com/default-photos/body-mid-04.jpg Defined in com/costarastrology/loverscope/purchase/LoverscopePurchaseScreenKt.java |
|
https://costar-app-user-profile-photos.s3.amazonaws.com/default-photos/body-mid-07.jpg https://costar-app-user-profile-photos.s3.amazonaws.com/default-photos/body-mid-04.jpg Defined in com/costarastrology/loverscope/purchase/LoverscopePurchaseScreenKt.java |
|
https://costar-app-user-profile-photos.s3.amazonaws.com/default-photos/body-mid-06.jpg https://costar-app-user-profile-photos.s3.amazonaws.com/default-photos/body-mid-07.jpg Defined in com/costarastrology/loverscope/content/ComposableSingletons$LoverscopeLoveNoteContentKt$lambda1$1.java |
|
https://costar-app-user-profile-photos.s3.amazonaws.com/default-photos/body-mid-06.jpg https://costar-app-user-profile-photos.s3.amazonaws.com/default-photos/body-mid-07.jpg Defined in com/costarastrology/loverscope/content/ComposableSingletons$LoverscopeLoveNoteContentKt$lambda1$1.java |
|
http://schemas.android.com/apk/res/android Defined in com/hbb20/CountryCodePicker.java |
|
https://horrorscope-1491761746782.firebaseio.com https://www.costarastrology.com/faq https://www.costarastrology.com/app-feedback?utm_medium=%1$d https://www.costarastrology.com/jobs https://www.instagram.com/costarastrology https://play.google.com/store/apps/details?id=com.costarastrology https://play.google.com/store/account/subscriptions?sku=%1$s&package=%2$s https://www.costarastrology.com/terms Defined in Android String Resource |
|
https://horrorscope-1491761746782.firebaseio.com https://www.costarastrology.com/faq https://www.costarastrology.com/app-feedback?utm_medium=%1$d https://www.costarastrology.com/jobs https://www.instagram.com/costarastrology https://play.google.com/store/apps/details?id=com.costarastrology https://play.google.com/store/account/subscriptions?sku=%1$s&package=%2$s https://www.costarastrology.com/terms Defined in Android String Resource |
|
https://horrorscope-1491761746782.firebaseio.com https://www.costarastrology.com/faq https://www.costarastrology.com/app-feedback?utm_medium=%1$d https://www.costarastrology.com/jobs https://www.instagram.com/costarastrology https://play.google.com/store/apps/details?id=com.costarastrology https://play.google.com/store/account/subscriptions?sku=%1$s&package=%2$s https://www.costarastrology.com/terms Defined in Android String Resource |
|
https://horrorscope-1491761746782.firebaseio.com https://www.costarastrology.com/faq https://www.costarastrology.com/app-feedback?utm_medium=%1$d https://www.costarastrology.com/jobs https://www.instagram.com/costarastrology https://play.google.com/store/apps/details?id=com.costarastrology https://play.google.com/store/account/subscriptions?sku=%1$s&package=%2$s https://www.costarastrology.com/terms Defined in Android String Resource |
|
https://horrorscope-1491761746782.firebaseio.com https://www.costarastrology.com/faq https://www.costarastrology.com/app-feedback?utm_medium=%1$d https://www.costarastrology.com/jobs https://www.instagram.com/costarastrology https://play.google.com/store/apps/details?id=com.costarastrology https://play.google.com/store/account/subscriptions?sku=%1$s&package=%2$s https://www.costarastrology.com/terms Defined in Android String Resource |
|
https://horrorscope-1491761746782.firebaseio.com https://www.costarastrology.com/faq https://www.costarastrology.com/app-feedback?utm_medium=%1$d https://www.costarastrology.com/jobs https://www.instagram.com/costarastrology https://play.google.com/store/apps/details?id=com.costarastrology https://play.google.com/store/account/subscriptions?sku=%1$s&package=%2$s https://www.costarastrology.com/terms Defined in Android String Resource |
|
https://horrorscope-1491761746782.firebaseio.com https://www.costarastrology.com/faq https://www.costarastrology.com/app-feedback?utm_medium=%1$d https://www.costarastrology.com/jobs https://www.instagram.com/costarastrology https://play.google.com/store/apps/details?id=com.costarastrology https://play.google.com/store/account/subscriptions?sku=%1$s&package=%2$s https://www.costarastrology.com/terms Defined in Android String Resource |
|
https://horrorscope-1491761746782.firebaseio.com https://www.costarastrology.com/faq https://www.costarastrology.com/app-feedback?utm_medium=%1$d https://www.costarastrology.com/jobs https://www.instagram.com/costarastrology https://play.google.com/store/apps/details?id=com.costarastrology https://play.google.com/store/account/subscriptions?sku=%1$s&package=%2$s https://www.costarastrology.com/terms Defined in Android String Resource |
Information computed with MobSF.
Information computed with Exodus-core.
Facebook Analytics | https://reports.exodus-privacy.eu.org/fr/trackers/66 |
Facebook Flipper | https://reports.exodus-privacy.eu.org/fr/trackers/392 |
Facebook Login | https://reports.exodus-privacy.eu.org/fr/trackers/67 |
Facebook Share | https://reports.exodus-privacy.eu.org/fr/trackers/70 |
Google CrashLytics | https://reports.exodus-privacy.eu.org/fr/trackers/27 |
Google Firebase Analytics | https://reports.exodus-privacy.eu.org/fr/trackers/49 |
Information computed with Quark-Engine.
Confidence:
|
Load external class |
Confidence:
|
Implicit intent(view a web page, make a phone call, etc.) |
Confidence:
|
Find a method from given class name, usually for reflection |
Confidence:
|
Connect to a URL and receive input stream from the server |
Confidence:
|
Method reflection |
Confidence:
|
Get the network operator name |
Confidence:
|
Connect to a URL and read data from it |
Confidence:
|
Monitor data identified by a given content URI changes(SMS, MMS, etc.) |
Confidence:
|
Load class from given class name |
Confidence:
|
Retrieve data from broadcast |
Confidence:
|
Read sensitive data(SMS, CALLLOG, etc) |
Confidence:
|
Put data in cursor to JSON object |
Confidence:
|
Check if the given path is directory |
Confidence:
|
Implicit intent(view a web page, make a phone call, etc.) via setData |
Confidence:
|
Read sensitive data(SMS, CALLLOG) and put it into JSON object |
Confidence:
|
Connect to a URL and get the response code |
Confidence:
|
Monitor the broadcast action events (BOOT_COMPLETED) |
Confidence:
|
Get Location of the device and append this info to a string |
Confidence:
|
Query The ISO country code |
Confidence:
|
Read file from assets directory |
Confidence:
|
Get last known location of the device |
Confidence:
|
Get calendar information |
Confidence:
|
Get location of the device |
Confidence:
|
Check if the given file path exist |
Confidence:
|
Method reflection |
Confidence:
|
Get the country code of the SIM card provider |
Confidence:
|
Connect to the remote server through the given URL |
Confidence:
|
Query data from URI (SMS, CALLLOGS) |
Confidence:
|
Read file into a stream and put it into a JSON object |
Confidence:
|
Get the time of current location |
Confidence:
|
Initialize class object dynamically |
Confidence:
|
Create a directory |
Confidence:
|
Read the input stream from given URL |
Confidence:
|
Connect to a URL and set request method |
Confidence:
|
Get specific method from other Dex files |
Confidence:
|
Check if the network is connected |
Confidence:
|
Start another application from current application |
Confidence:
|
Check the active network type |
Confidence:
|
Read data and put it into a buffer stream |
Confidence:
|
Save the response to JSON after connecting to the remote server |
Confidence:
|
Read file and put it into a stream |
Confidence:
|
Get absolute path of the file and store in string |
Confidence:
|
Get filename and put it to JSON object |
Confidence:
|
Get resource file from res/raw directory |
Information computed with MobSF.