File sums
MD5
82ffff3a21f4c819ef87c3a0a814a3db
SHA1
371b09369d2337d93d557e5835db12a1cf3b848b
SHA256
fd7e7e23db5f645db9ed47a5d36e7cf57ca2dbdf46a37484eafa1e04f657bf02
Size
7.87MB
APKiD
Information computed with APKiD .
/tmp/tmpdv1qg_xl!classes.dex
compiler
SSdeep
Information computed with ssdeep .
APK file
98304:RHsN1nqVekRdIJWUTl/DNM4O2Yp4ECidNGSXiDTJNelLtRT7XMYLxyXutGnsGpT/:RHIINRu1Nq4bvnJY1tJcgo+TGjpjsqR
Manifest
768:iSUFHB8Tyi7NyUlauycmXJ68p6nAmPCATQQXz95Z2h6vA0dNbDYLcqLtex5eTnBr:…
classes.dex
12288:0j0wa2qU5B5Qg+xS/gSdxN/rHJ6/beHoSwGWRcI0rp5O3s16mvKthKfi28J32c:…
Dexofuzzy
Information computed with Dexofuzzy .
APK file
1536:IKtqeBrAVuq3XNg9Svko+fuZZm1Cjr7UD:IydAVuq3X29Svko+fuZZm1Cjr7UD
classes.dex
1536:IKtqeBrAVuq3XNg9Svko+fuZZm1Cjr7UD:IydAVuq3X29Svko+fuZZm1Cjr7UD
APK details
Information computed with AndroGuard
and Pithus .
Package
com.tag.right
App name
QR CreatorScanner
Version name
1.0
Version code
1
SDK
24 - 28
UAID
8a06f0b1efe3d12524334d00cf2e3d9ce3cd9701
Signature
Signature V1
Frosting
Not frosted
Certificate details
Information computed with AndroGuard .
MD5
e89b158e4bcf988ebd09eb83f5378e87
SHA1
61ed377e85d386a8dfee6b864bd85b0bfaa5af81
SHA256
a40da80a59d170caa950cf15c18c454d47a39b26989d8b640ecd745ba71bf5dc
Issuer
Email Address: android@android.com, Common Name: Android, Organizational Unit: Android, Organization: Android, Locality: Mountain View, State/Province: California, Country: US
Not before
2008-02-29T01:33:46+00:00
Not after
2035-07-17T01:33:46+00:00
Manifest analysis
Information computed with MobSF .
Medium
Application Data can be Backed up[android:allowBackup] flag is missing.
The flag [android:allowBackup] should be set to false. By default it is set to true and allows anyone to backup your application data via adb. It allows users who have enabled USB debugging to copy application data off of the device.
Main Activity
Information computed with AndroGuard .
com.tulecazopabi.banewo.zamosa
Activities
Information computed with AndroGuard .
com.tulecazopabi.banewo.LNnTjTyUmGsNkJeRuPyUnQaFgAbJqGbGgXiUpUtNnZfDlHx com.tulecazopabi.banewo.ZFfCiLsOpXgIhZqKsJwEdUoNlZhPwXwTgKmPeJrUbMpHjMxSyJj com.tulecazopabi.banewo.INsZtCm com.tulecazopabi.banewo.IHqQlRrOuWiHfKbUpNmWwJjMiInLfYgHrIwAqLiJeMlDnNuKe com.tulecazopabi.banewo.UTaYjCnKqGmMeZuPyRsJfHlUxJhPbUrRwOeUjHjHmFcNxLxNqEnZr com.tulecazopabi.banewo.FUqMtSbCcHtUaDlBiDzNy com.tulecazopabi.banewo.URmLmYiKqCyKlFnQzHpZaXlYoTiYhOgMrMpHuUeRk com.tulecazopabi.banewo.UFtXmAbZhIaWwZiHhPnHuZn com.tulecazopabi.banewo.PDoIsGeCcAjOaImQj com.tulecazopabi.banewo.xexerexejeko.canosahuco com.tulecazopabi.banewo.LYsUlJfClNrThRzWrJhIrYnLd com.tulecazopabi.banewo.MLzMpGzXsZfUdDeIaKrXhYqJtGiFuYyEdFo com.tulecazopabi.banewo.xexerexejeko.webiti com.tulecazopabi.banewo.EUqTrRcKkDyOnZuChMpLcIgKbZrDaHaUoQjImCsFrNkAuPxRzKf com.tulecazopabi.banewo.xexerexejeko.cevuna com.tulecazopabi.banewo.FEwEnMqWr com.tulecazopabi.banewo.MIzZnKqJnUpCoGh com.tulecazopabi.banewo.WSxYaGuHyZfNsMdWpHpToHcQrElJtIpYpHd com.tulecazopabi.banewo.WXdKjQpAtCeAaEcXhKbKpWkPqDkZxEcYnSiFoEiZo com.tulecazopabi.banewo.HBpSbGbSpEmEyDzGhDtEeHmNqBqJgJeUr com.tulecazopabi.banewo.RYqWkYiEhXrWoQuUxIbJxIsGnPlJcSwSuDkHlFtXfWaYtJt com.tulecazopabi.banewo.KAcCgHhNzDuElWnLo com.tulecazopabi.banewo.xexerexejeko.nemuyahelu com.tulecazopabi.banewo.ZKxGiKmYlNnMuHcEaJrXkGjDnKfMgBkUdJoBsYpXfNsMhFrWcQd com.tulecazopabi.banewo.KKxLfZtWqRkSkEz com.google.android.gms.common.api.GoogleApiActivity com.tulecazopabi.banewo.SFdJwXwRiSaFnZsUsXlUyYdAkLcUgLyKhZrUmBxPgSi com.tulecazopabi.banewo.QBoQfHgQxWmCfGzZyFyRnOfGjWnEbUxCk com.tulecazopabi.banewo.HLbDrYhDeLlTmYf com.tulecazopabi.banewo.YEeDjNiAcKjLo com.tulecazopabi.banewo.xexerexejeko.xiwi com.tulecazopabi.banewo.AYkOaIeQyFfYrHeQgIlYcZiIsGwJbIpDhAuHlAbKqPbRpPt com.tulecazopabi.banewo.zamosa com.tulecazopabi.banewo.ZKpUeDzTtYkRwSyKmCkXpWcJzTsRkBcQl com.tulecazopabi.banewo.XGwDtChUl com.tulecazopabi.banewo.xarenu.pavu com.tulecazopabi.banewo.TMhJqNgOgBgMfHzYwLcCtJiFcQzDcDzHrLoIxOjGqCoFl com.tulecazopabi.banewo.FKpHkCcZkJeFjLmRlBfCxFb com.tulecazopabi.banewo.kivamu.moye com.tulecazopabi.banewo.YDrLxLkJxXpIsFdSzYeAs com.tulecazopabi.banewo.KSaGbXnXbFrHaCzXmYoLgNxLsRdQi com.tulecazopabi.banewo.QTpFbMlEs com.tulecazopabi.banewo.YCeKyWmHqImKhFyKbAl com.tulecazopabi.banewo.MQdFyOjEbDkRzUrEg com.tulecazopabi.banewo.GYzWfWzPjUiIlPlNuTgUnBgYjOfHkEz com.tulecazopabi.banewo.UAbCcOePbMkGbYrCiKwMkOqKsQjRcAfGaAbOmTaBn
Receivers
Information computed with AndroGuard .
com.tulecazopabi.banewo.fiyidi.vuyibifadehodaje com.tulecazopabi.banewo.kivamu.duyehi com.tulecazopabi.banewo.fiyidi.waki com.tulecazopabi.banewo.xarenu.tayokigeduwoti com.tulecazopabi.banewo.kivamu.yekasetefayi com.tulecazopabi.banewo.fiyidi.kasomicalafo
Services
Information computed with AndroGuard .
com.tulecazopabi.banewo.tebojatuci.xefetune com.tulecazopabi.banewo.tebojatuci.duporexicocivu com.tulecazopabi.banewo.tebojatuci.limemica com.tulecazopabi.banewo.tebojatuci.capakusame com.tulecazopabi.banewo.tebojatuci.pisisuyugicucu com.tulecazopabi.banewo.tebojatuci.lomu com.tulecazopabi.banewo.kivamu.yipo
Sample timeline
Certificate valid not before
Feb. 29, 2008, 1:33 a.m.
Oldest file found in APK
Oct. 8, 2021, 7:49 p.m.
Latest file found in APK
Oct. 8, 2021, 7:49 p.m.
First submission on VT
Dec. 2, 2021, 12:15 a.m.
Last submission on VT
Dec. 2, 2021, 12:15 a.m.
Upload on Pithus
Jan. 21, 2022, 5:10 p.m.
Certificate valid not after
July 17, 2035, 1:33 a.m.
MalwareBazaar
ReversingLabs
Threat name
Android.Trojan.Cerberus
Status
MALICIOUS
First seen
2021-12-02 00:28:51
Score
17/43
Hatching Triage
CERT-PL MWDB
VirusTotal
Most Popular AV Detections
Provided by VirusTotal
Threat name: hqwar
Identified 3 times
Threat name: artemis
Identified 2 times
Threat name: cerberus
Identified 2 times
NIAP analysis
Information computed with MobSF .
FCS_STO_EXT.1.1
The application does not store any credentials to non-volatile memory.
Storage of Credentials
FCS_CKM_EXT.1.1
The application generate no asymmetric cryptographic keys.
Cryptographic Key Generation Services
FDP_DEC_EXT.1.1
The application has access to ['network connectivity'].
Access to Platform Resources
FDP_DEC_EXT.1.2
The application has access to ['address book'].
Access to Platform Resources
FDP_NET_EXT.1.1
The application has user/application initiated network communications.
Network Communications
FDP_DAR_EXT.1.1
The application does not encrypt files in non-volatile memory.
Encryption Of Sensitive Application Data
FTP_DIT_EXT.1.1
The application does not encrypt any data in traffic or does not transmit any data between itself and another trusted IT product.
Protection of Data in Transit
FCS_HTTPS_EXT.1.3
The application notify the user and not establish the connection or request application authorization to establish the connection if the peer certificate is deemed invalid.
HTTPS Protocol
Code analysis
Information computed with MobSF .
Low
CVSS:7.5
The App logs information. Sensitive information should never be logged.
MASVS: MSTG-STORAGE-3
CWE-532 Insertion of Sensitive Information into Log File
Files:
com/airbnb/lottie/utils/LogcatLogger.java
Permissions analysis
Information computed with MobSF .
Unknown permission
Unknown permission from android reference
Threat analysis
Information computed with Quark-Engine .
Confidence:
Find a method from given class name, usually for reflection
Confidence:
Connect to a URL and receive input stream from the server
Confidence:
Method reflection
Confidence:
Connect to a URL and read data from it
Confidence:
Open a file from given absolute path of the file
Confidence:
Connect to a URL and get the response code
Confidence:
Method reflection
Confidence:
Connect to the remote server through the given URL
Confidence:
Initialize class object dynamically
Confidence:
Read the input stream from given URL
Confidence:
Connect to a URL and set request method
Confidence:
Read file and put it into a stream
Confidence:
Get absolute path of the file and store in string
Behavior analysis
Information computed with MobSF .
Base64 decode
com/airbnb/lottie/manager/ImageAssetManager.java
Dynamic class and dexloading
com/tag/right/OZdBuNiNdLuMdNjWePcTnGpGdBxOuIwBnIjNqSgQtAiNcTuIqEkJaSa.java
Get system service
com/tag/situate/NCnYfTgMrDxZlKxUfPlSaOhXxFxIqUqSjMmIbUaLeEkEw.java com/tag/right/maximum/HGuTkDyWbEqJkJnSfRdDdKcWnQzIuKu.java com/tag/right/real/HUfXaGcAbCaDkDz.java com/tag/pencil/LUmNhMaXqBuOdEwOqBrRpRjJsRhKkAtNd.java com/tag/verb/FFhEiEbDkIpCl.java com/tag/broom/PJcUnZzMzCpAdRnSiTcZeSySmAwFh.java com/tag/right/KKdCuWl.java com/tag/pencil/NOjYkLpAaWrKkOzEpErLmGkJyQfHoLfWnFeKbKg.java com/tag/right/define/YEtJhWjOqLnNrUkCmQrXrZePcEoFgUqLmJdMhLqGx.java com/tag/right/energy/YArYyYjZhMfCp.java com/tag/right/define/JKuDdPnEzYdTyBxTbMjMxGcUaFdZyMoYfNxQqJgYgIkAaLjFaCjFtKz.java com/tag/right/define/YIcUqFhBfBgJbSyQdRtRqKmGjQlCuPjFiZlJbKzRdYaMwReQbSqYk.java com/tag/miracle/NZxBdChUbMtXzHfQdElShZyOjOgImZrPqDjFtMtWcQb.java com/tag/situate/UQhGoKlQjTlUgWeHzNuTpZeOhZzZbOmLjUx.java com/tag/situate/RYkMsGyOjDkSdZjWkHyBxSeIpLhFjMlIxEh.java com/tag/right/real/DYmZcArSjBqOiPjYxLjLfHtWjHuCiJmEqYoKdPdMkAoOyFkIxRs.java com/tag/right/JCfEnIoBbHsIfUwIqQpXdKeShMeQkLuOuChArKdRqPsSuGaWxUoKs.java com/tag/pencil/AWdJcRzEpQnAzSyLcLjYdGeXsIePeFtWpUaYfLz.java com/tag/pencil/HIiStEmZjAeOtQgUx.java com/tag/right/SIdOzQgNxUsQmKnLnOlMuEpZsXcTrQwWqSgIdFwXi.java com/tag/verb/XHhZsCoDdXdCuSlBm.java com/tag/right/OOjYrUm.java com/tag/right/real/HGiPeThEuQxDbIwGwLiYgTfXtNqTbWsEb.java com/tag/right/GIlPkHxXzBmDfKzOwWoIjHkXzDdQsDkOhSsRtOhAzEg.java com/tag/right/BNuTiFjUpCrZdLcKrLh.java com/tag/broom/JMkAdTmWaHeMkSpXeQmYfBmYzTe.java com/tag/broom/DDyElTbAsJpCcAfWaXpMcQoBq.java com/tag/pencil/BMpHsEkNzNwAmPhDyWrFbHmKkNsYqRhSr.java com/tag/verb/ATrUxSx.java com/tag/right/energy/RXwBhUrHaUiFpZtNdXjNiGnLk.java com/tag/miracle/PDyLdHoNdKrUrKbOdZrDlWd.java com/tag/right/define/XGaCyGeNqOkQfTwCgMxQaClYnEhZxCrGxQtShWy.java com/tag/right/JNzDrRrEiOsDp.java com/tag/right/CMjJyBtQtGgXcWeDrGiTzYgMbWuFfFbNoNs.java com/tag/verb/DAcElXfTbJgUtGnTmPcEu.java com/tag/right/real/IWzWtWpDnMbLoEoZnTyGwBnNqXzRmPtAfTcArHsBkErPsKkUcRn.java com/tag/miracle/KMgSmUgJeYtCxWuDnZaWoLpMzPgYrShZjBoIoIu.java
Http connection
com/airbnb/lottie/network/NetworkFetcher.java
Inter process communication
com/tag/situate/NCnYfTgMrDxZlKxUfPlSaOhXxFxIqUqSjMmIbUaLeEkEw.java com/tag/right/energy/LYrFjEgKmHuJsNhWzNuXmHxYeNnQqSbPeYgWmCo.java com/tag/right/PYnNxNyPfWoDgCqStQfNwXrEiWkWlLnSrJbEsEpRzSkQoFb.java com/tag/right/define/XHeEcQiFyIpOjRtTt.java com/tag/miracle/RTbOrDjZuSs.java com/tag/pencil/COeEpCxHrLqZkQhXrQpIz.java com/tag/pencil/NOjYkLpAaWrKkOzEpErLmGkJyQfHoLfWnFeKbKg.java com/tag/right/energy/YArYyYjZhMfCp.java com/tag/right/define/JKuDdPnEzYdTyBxTbMjMxGcUaFdZyMoYfNxQqJgYgIkAaLjFaCjFtKz.java com/tag/right/energy/AEdJzUgSlGfZwWbXeCoJrKw.java com/tag/right/define/YIcUqFhBfBgJbSyQdRtRqKmGjQlCuPjFiZlJbKzRdYaMwReQbSqYk.java com/tag/miracle/NZxBdChUbMtXzHfQdElShZyOjOgImZrPqDjFtMtWcQb.java com/tag/situate/RYkMsGyOjDkSdZjWkHyBxSeIpLhFjMlIxEh.java com/tag/right/real/DYmZcArSjBqOiPjYxLjLfHtWjHuCiJmEqYoKdPdMkAoOyFkIxRs.java com/tag/right/define/GFjGxKwXbOpUxNsOj.java com/tag/right/JCfEnIoBbHsIfUwIqQpXdKeShMeQkLuOuChArKdRqPsSuGaWxUoKs.java com/tag/pencil/AWdJcRzEpQnAzSyLcLjYdGeXsIePeFtWpUaYfLz.java com/tag/verb/JXoRuUpRcCyGyQgOuTkDfTxUrKtLwUmYbTk.java com/tag/right/SIdOzQgNxUsQmKnLnOlMuEpZsXcTrQwWqSgIdFwXi.java com/tag/broom/BZaIqLjAtJsFrHtQkReRyMxStHcMhRxXgOoEoXuYgYi.java com/tag/right/BNuTiFjUpCrZdLcKrLh.java com/tag/broom/DDyElTbAsJpCcAfWaXpMcQoBq.java com/tag/pencil/BMpHsEkNzNwAmPhDyWrFbHmKkNsYqRhSr.java com/tag/verb/ATrUxSx.java com/tag/right/maximum/JAkKcYuGbDoDzEpNqTzHbIyFpTbOfDsWmPhMzYxLaPuCcJfBjLzYwYe.java com/tag/right/OTqMeIrPgNdPhWsOdGuTdAfAoGjEsBtMwOpYuPi.java com/tag/right/JLwUaQfKmCmHeMjToEw.java com/tag/miracle/PDyLdHoNdKrUrKbOdZrDlWd.java com/tag/right/JIeMfXuGlQsRpJrOhKcNgBzNkLkPfAuYfLdCqHhTrTmFzSzZiQp.java com/tag/situate/XYpKfCdKqCcBgWjZxHyChXgPsLeXxMfBcApUhRa.java com/tag/right/define/XGaCyGeNqOkQfTwCgMxQaClYnEhZxCrGxQtShWy.java com/tag/right/JNzDrRrEiOsDp.java com/tag/verb/ARqWgDeSqWh.java com/tag/right/energy/TRnKxYsHtOyZuIwCuNuJg.java com/tag/miracle/PRmGkItFzBkIl.java com/tag/verb/DAcElXfTbJgUtGnTmPcEu.java com/tag/right/real/IWzWtWpDnMbLoEoZnTyGwBnNqXzRmPtAfTcArHsBkErPsKkUcRn.java com/tag/right/real/MEgTaRgSzAfIeBlLeWkEnQiEkRoFrXoOyTlAtGxZxTxRaOnYjGyYw.java com/tag/miracle/KMgSmUgJeYtCxWuDnZaWoLpMzPgYrShZjBoIoIu.java
Java reflection
com/tag/right/BUeCzSoZfXtYuUkYdDfOzSzZqAoUcUzEhXfCjPwCnMwQxHwEyXzFm.java com/tag/right/GEyFfPkBdBiDgQpRiYcCkZaBz.java com/tag/right/OZdBuNiNdLuMdNjWePcTnGpGdBxOuIwBnIjNqSgQtAiNcTuIqEkJaSa.java
Local file i/o operations
com/airbnb/lottie/network/NetworkCache.java
Starting activity
com/tag/right/DAnZuTuEtBxTdRcWqHk.java com/tag/right/energy/LYrFjEgKmHuJsNhWzNuXmHxYeNnQqSbPeYgWmCo.java com/tag/right/PYnNxNyPfWoDgCqStQfNwXrEiWkWlLnSrJbEsEpRzSkQoFb.java com/tag/right/ITuMgFgYlOpZtUzEgNdJtErJsSxNjDlGoYsNuQeZnXmZtWt.java com/tag/right/maximum/EOxCqEiGuUeZpBtNdFf.java com/tag/right/define/XHeEcQiFyIpOjRtTt.java com/tag/miracle/EWqJbDeZnQzJtNhWaHgNoOyKdHtPeGqGwPcQgOz.java com/tag/right/define/EYrAjTrNeIfGaKeDx.java com/tag/miracle/RTbOrDjZuSs.java com/tag/situate/NYrNsAnYsTsXuIcSrNjOtWj.java com/tag/pencil/COeEpCxHrLqZkQhXrQpIz.java com/tag/right/define/ZCnSyRmMyUkKdOqNpNbGoJjLaNm.java com/tag/right/GAgNyRjWzDbCqGrHwYdWaAmOmTzRwSfPpJlTdMmUkRlBf.java com/tag/right/PZuSePuCaCbDf.java com/tag/right/maximum/IPaXrXgHhPcAjPbTlLwOiKbGdRgQpKoCgYrJeIdApObUfTr.java com/tag/pencil/QIlOnScXu.java com/tag/right/MOsYuGeZbAoDkBg.java com/tag/broom/WEbBhLsGjPgCwIdAfQjSuOqYaZl.java com/tag/right/energy/AEdJzUgSlGfZwWbXeCoJrKw.java com/tag/right/define/GFjGxKwXbOpUxNsOj.java com/tag/right/real/ZJiXzFgKaKnIrFaPjZnXpZcRfYoYrNfJrNkXyYkYrGiOuYpDnXl.java com/tag/verb/JXoRuUpRcCyGyQgOuTkDfTxUrKtLwUmYbTk.java com/tag/pencil/XWaApNaAtGwAjZwBuFeDqKjAjYxWpIgIeMdBdGwMcKyScMrKkYgTdOs.java com/tag/right/real/ZLzBrDnJdDiMbOaZeAcXzUtQfIcFsGeGpGzDwDwJwDuOyUdOyEx.java com/tag/broom/KMoNwCtPpKaJrMfKn.java com/tag/miracle/XJfUoPtTaLlPmObUqMeLuDpBxQpTtJhKaJr.java com/tag/right/UCbPjSoKqPw.java com/tag/pencil/FDfRdOuCmQwCxPnBlOjArRtOkQqOuAzMuXxAd.java com/tag/broom/BZaIqLjAtJsFrHtQkReRyMxStHcMhRxXgOoEoXuYgYi.java com/tag/right/real/XBeNcBlRk.java com/tag/right/define/DDbOkQhLfYpLwCeIyKyLlFkZkQeLaXd.java com/tag/right/maximum/JAkKcYuGbDoDzEpNqTzHbIyFpTbOfDsWmPhMzYxLaPuCcJfBjLzYwYe.java com/tag/right/OTqMeIrPgNdPhWsOdGuTdAfAoGjEsBtMwOpYuPi.java com/tag/right/JLwUaQfKmCmHeMjToEw.java com/tag/right/XRxDfEnCgQcYdGjUmJxSgZeRlJcPeQpHxBwCqBlDtYpUs.java com/tag/right/maximum/JOxAeEkLmZpBwClTiTtHxMaJaYiLbMdFhFrEuPoBhHjQbLcGxUuZhFx.java com/tag/right/JIeMfXuGlQsRpJrOhKcNgBzNkLkPfAuYfLdCqHhTrTmFzSzZiQp.java com/tag/situate/XYpKfCdKqCcBgWjZxHyChXgPsLeXxMfBcApUhRa.java com/tag/miracle/LZtUcXiWyKmIxPgJbIoKsTmBbCkSeLpTqNdOxByReIgDpHgRbBxAaPi.java com/tag/right/MNmTsCkEtLgToKcJnTjOeQdYoAtRsWaTrHmCmOjHiCeSpEa.java com/tag/verb/ARqWgDeSqWh.java com/tag/right/energy/TRnKxYsHtOyZuIwCuNuJg.java com/tag/miracle/PRmGkItFzBkIl.java com/tag/right/real/MEgTaRgSzAfIeBlLeWkEnQiEkRoFrXoOyTlAtGxZxTxRaOnYjGyYw.java com/tag/verb/GCyXfZpMmYpMwWcYcAjIqYjIcKwUpKmGwXfCuDdEmRqSzUkCfCe.java com/tag/right/maximum/XHcElAdGjQlArPuOnNkTkOjDaTxUuErRoRtPpEnDnEcUwTp.java
Tcp socket
com/airbnb/lottie/utils/Utils.java
Control flow graphs analysis
Information computed by
Pithus .
The application probably sends data over HTTP/S