Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
AV Detection: |
|
---|
Antivirus / Scanner detection for submitted sample |
Source: |
Avira: |
Multi AV Scanner detection for submitted file |
Source: |
Virustotal: |
Perma Link |
Location Tracking: |
|
---|
Queries the phones location (GPS) |
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
Privilege Escalation: |
|
---|
Checks if the device administrator is active |
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
Tries to add a new device administrator |
Source: |
API Call: |
||
Source: |
Method string: |
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
Networking: |
|
---|
Checks an internet connection is available |
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
Detected TCP or UDP traffic on non-standard ports |
Source: |
TCP traffic: |
||
Source: |
TCP traffic: |
Opens an internet connection |
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
||
Source: |
TCP traffic detected without corresponding DNS query: |
Source: |
DNS traffic detected: |
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
||
Source: |
API Call: |
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing: |
|
---|
Found potential keylogger |
Source: |
Instruction: |
||
Source: |
Instruction: |
||
Source: |
Instruction: |
||
Source: |
Instruction: |
||
Source: |
Instruction: |
||
Source: |
Instruction: |
||
Source: |
Instruction: |
||
Source: |
Instruction: |
||
Source: |
Instruction: |
||
Source: |
Instruction: |
Has permission to record audio in the background |
Source: |
Request permission: |
Records audio/media |
Source: |
API Call: |
||
Source: |
API Call: |
Source: |
API Call: |
||
Source: |
API Call: |
E-Banking Fraud: |
|
---|
Detected Anubis BankBot ransomware / banking trojan |
Source: |
Method string: |
||
Source: |
Method string: |
||
Source: |
Method string: |
||
Source: |
Method string: |
||
Source: |
Method string: |
||
Source: |
Method string: |
||
Source: |
Method string: |
Found large list of e-Banking application (likely related to e-Banking fraud) |
Contains package name strings related to banking (usually for identifying banking APKs) |
Source: |
Method String: |