VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

File information
File Name :6970.apk (File not down)
File Size :7374748 byte
File Type :Zip archive data
MD5:565eea01f9a1765d7c50b452e4475f32
SHA1:c8cb116260fcf639d5f3960aa5ae6adc2bd87271
SHA256:4887a6aa54234309757cf1fc0763957fff5b26c140a8f2ddedaa6c1748bd520f
  • 扫描结果
  • 权限
  • 文件行为分析
  • Scanner results
    Scanner results:59%Scanner(s) (19/32)found malware!
    Behavior analysis report:         Habo file analysis
    Time: 2019-06-17 02:27:07 (CST)
    VirSCANVirSCAN
    Scanner Engine Ver Sig Ver Sig Date Scan result Time
    antiy AVL SDK 3.0 AVL SDK 3.0 2019-06-16 Trojan[Backdoor]/Android.KungFu 1
    avast 18.4.3895.0 18.4.3895.0 2019-06-17 Found nothing 2
    avg 10.0.1405 10.0.1405 2019-06-17 Found nothing 1
    baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 1
    baidusd 1.0 1.0 2019-06-16 Found nothing 1
    bitdefender 7.141118 7.141118 2019-06-16 Found nothing 1
    clamav 25481 0.100.2 2019-06-15 Andr.Trojan.DroidKungFu-1 2
    drweb 11.0.10.1810231600 11.0.10.1810231600 2019-06-16 Android.KungFu.2 10
    emsisoft 9.0.0.4324 9.0.0.4324 2014-07-03 Android.Adware.Adwo.A 2
    fortinet 1.000, 69.279, 69.184, 69.208 5.4.247 2019-06-17 Android/DroidKungFu.AW!tr.bdr 1
    fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 1
    fsecure 2015-08-01-02 9.13 2019-06-17 Found nothing 56
    gdata 25.22397 25.22397 2019-06-16 Android.Adware.Adwo.A 12
    ikarus 5.01.05 V1.32.39.0 2019-06-16 Trojan.AndroidOS.Mseg 5
    jiangmin 16.0.100 1.0.0.0 2019-06-16 Backdoor/AndroidOS.uy 3
    kaspersky 5.5.33 5.5.33 2019-06-16 Backdoor.AndroidOS.KungFu.cz 21
    kingsoft 2.1 2.1 2013-09-22 Android.Troj.ya_Kongfu.op.(kcloud) 3
    mcafee 9256 5400.1158 2019-05-13 Found nothing 13
    nod32 9516 4.5.15 2019-06-13 multiple threats 2
    panda 9.05.01 9.05.01 2019-05-29 Found nothing 5
    pcc 13.302.06 9.500-1005 2019-06-16 Android.EDF0B7B6 2
    qh360 1.0.1 1.0.1 2019-06-16 Trojan.Android.Gen 3
    qqphone 2.0.0.0 2.0.0.0 2019-06-16 a.system.safesys.e 1
    quickheal 14.00 14.00 2019-02-10 Android.Kungfu.L 3
    rising 5169 5169 2019-06-16 System.Fokonge 5
    sophos 4.62 3.16.1 2016-09-20 Andr/KongFu-A 12
    symantec 20151230.005 1.3.0.24 2015-12-30 Found nothing 1
    tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 4
    thehacker 6.8.0.5 6.8.0.5 2017-03-30 Found nothing 1
    tws 17.47.17308 1.0.2.2108 2019-06-15 Android.M.tblo 7
    vba 4.0.0 4.0.0 2019-06-14 Backdoor.AndroidOS.KungFu.a 4
    virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 4
    Heuristic/Suspicious Exact
    NOTICE: Results are not 100% accurate and can be reported as a false positive by some scannerswhen and if malware is found. Please judge these results for yourself.
  • 权限列表
    许可名称信息
    android.permission.INTERNET连接网络(2G或3G)
    android.permission.READ_EXTERNAL_STORAGE读外部存储器(如:SD卡)
    android.permission.READ_PHONE_STATE读取电话状态
    android.permission.ACCESS_COARSE_LOCATION获取粗略的位置(通过wifi、基站)
    android.permission.ACCESS_FINE_LOCATION获取精确的位置(通过GPS)
    android.permission.ACCESS_NETWORK_STATE读取网络状态(2G或3G)
    android.permission.ACCESS_LOCATION_EXTRA_COMMANDS访问额外的定位指令
    android.permission.WRITE_EXTERNAL_STORAGE写外部存储器(如:SD卡)
    android.permission.ACCESS_WIFI_STATE读取wifi网络状态
    android.permission.CHANGE_WIFI_STATE改变WIFI连接状态
    android.permission.INSTALL_PACKAGES安装应用
    android.permission.READ_SMS读取短信
    android.permission.WRITE_SMS写短信
    android.permission.GET_TASKS获取有关当前或最近运行的任务信息
  • 文件信息
    安全评分 :
    基本信息
    MD5:565eea01f9a1765d7c50b452e4475f32
    包名:com.alan
    最低运行环境:Android 2.1.x
    版权:
    关键行为
    行为描述:对比可疑进程名
    详情信息:stricmp: [System Process] <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: System <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: smss.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: csrss.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: winlogon.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: services.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: lsass.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: HNgxService.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: nescthlp.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: svchost.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: spoolsv.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: jqs.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: HYGpgradeHelper.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: alg.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: explorer.exe <------> avp.exe Des: 卡巴斯基
    行为描述:搜索可疑进程名
    详情信息:strstr: avp.exe <------> Des: 卡巴斯基
    进程行为
    行为描述:创建本地线程
    详情信息:TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2548, ThreadID = 2616, StartAddress = 77DC845A, Parameter = 00000000
    TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2548, ThreadID = 2620, StartAddress = 77C0A341, Parameter = 003F4340
    行为描述:枚举进程
    详情信息:N/A
    网络行为
    行为描述:建立到一个指定的套接字连接
    详情信息:URL: mi****et, IP: **.133.40.**:6521, SOCKET = 0x00000104
    行为描述:按名称获取主机地址
    详情信息:gethostbyname: mi****et
    注册表行为
    行为描述:修改注册表
    详情信息:\REGISTRY\USER\S-*\Software\Microsoft\ActiveMovie\devenum\Version
    其他行为
    行为描述:创建互斥体
    详情信息:mineros.dynu.net
    CTF.LBES.MutexDefaultS-*
    CTF.Compart.MutexDefaultS-*
    CTF.Asm.MutexDefaultS-*
    CTF.Layouts.MutexDefaultS-*
    CTF.TMD.MutexDefaultS-*
    CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
    eed3bd3a-a1ad-4e99-987b-d7cb3fcfa7f0 - S-*
    行为描述:创建事件对象
    详情信息:EventName = DINPUTWINMM
    EventName = Global\crypt32LogoffEvent
    行为描述:对比可疑进程名
    详情信息:stricmp: [System Process] <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: System <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: smss.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: csrss.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: winlogon.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: services.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: lsass.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: HNgxService.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: nescthlp.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: svchost.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: spoolsv.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: jqs.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: HYGpgradeHelper.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: alg.exe <------> avp.exe Des: 卡巴斯基
    lstrcmpiA: explorer.exe <------> avp.exe Des: 卡巴斯基
    行为描述:搜索可疑进程名
    详情信息:strstr: avp.exe <------> Des: 卡巴斯基
    行为描述:调整进程token权限
    详情信息:SE_LOAD_DRIVER_PRIVILEGE
    行为描述:打开事件
    详情信息:HookSwitchHookEnabledEvent
    Global\crypt32LogoffEvent
    Global\SvcctrlStartEvent_A3752DX
    行为描述:打开互斥体
    详情信息:DBWinMutex
    Activities
    活动名类型
    .LoverExpressionandroid.intent.action.MAIN
    .LoverExpressionandroid.intent.category.LAUNCHER
    危险函数
    函数名称信息
    java/net/URL;->openConnection连接URL
    java/net/HttpURLConnection;->connect连接URL
    TelephonyManager;->getDeviceId搜集用户手机IMEI码、电话号码、系统版本号等信息
    HttpClient;->execute请求远程服务器
    LocationManager;->getLastKnownLocation获取地址位置
    TelephonyManager;->getLine1Number获取手机号
    TelephonyManager;->getSimSerialNumber获取SIM序列号
    android/app/NotificationManager;->notify信息通知栏
    DefaultHttpClient;->execute发送HTTP请求
    WifiManager;->setWifiEnabled变更WIFI状态
    getRuntime获取命令行环境
    java/lang/Runtime;->exec执行字符串命令
    ContentResolver;->query读取联系人、短信等数据库
    java/net/URLConnection;->connect连接URL
    启动方式
    名称信息
    com.google.update.Receiver
    com.google.update.Receiver
    com.google.update.Receiver开机启动服务
    广告信息
    名称信息
    com.google.adsAdMob
    com.vpon.adonVpon
    com.adwo.adsdk安沃
    权限列表
    许可名称信息
    android.permission.INTERNET连接网络(2G或3G)
    android.permission.READ_EXTERNAL_STORAGE读外部存储器(如:SD卡)
    android.permission.READ_PHONE_STATE读取电话状态
    android.permission.ACCESS_COARSE_LOCATION获取粗略的位置(通过wifi、基站)
    android.permission.ACCESS_FINE_LOCATION获取精确的位置(通过GPS)
    android.permission.ACCESS_NETWORK_STATE读取网络状态(2G或3G)
    android.permission.ACCESS_LOCATION_EXTRA_COMMANDS访问额外的定位指令
    android.permission.WRITE_EXTERNAL_STORAGE写外部存储器(如:SD卡)
    android.permission.ACCESS_WIFI_STATE读取wifi网络状态
    android.permission.CHANGE_WIFI_STATE改变WIFI连接状态
    android.permission.INSTALL_PACKAGES安装应用
    android.permission.READ_SMS读取短信
    android.permission.WRITE_SMS写短信
    android.permission.GET_TASKS获取有关当前或最近运行的任务信息
    服务列表
    名称
    com.google.update.UpdateService
    文件列表
    文件名 校验码
    assets/fonts/0.ttf 0x40bcfd49
    assets/fonts/1.ttf 0x6ef442d5
    assets/fonts/2.ttf 0xa30af2cd
    assets/fonts/3.ttf 0x81a71bfb
    assets/fonts/4.ttf 0xa8dcefc0
    assets/fonts/5.ttf 0x3b618e7b
    assets/fonts/6.ttf 0x80357e16
    assets/fonts/7.ttf 0x17b064cf
    assets/fonts/8.ttf 0xd53abd91
    assets/fonts/9.ttf 0x3d07653c
    res/anim/oneword.xml 0x4eb4b0c3
    res/drawable/cake.jpg 0xc28249a
    res/drawable/flower.jpg 0x57eb22ee
    res/drawable/heart.jpg 0xa23418ec
    res/drawable/kiss.jpg 0x49c85a6a
    res/drawable/love.jpg 0xa57954b8
    res/drawable/mycoin.jpg 0x88b0f619
    res/layout/add_bg.xml 0xfad73aa1
    res/layout/add_bg_item.xml 0xf9e22973
    res/layout/add_expression.xml 0xd4da0813
    res/layout/edit_expression.xml 0xd9d57dfb
    res/layout/expressions.xml 0xbd741d5
    res/layout/expressions_item.xml 0x98305697
    res/layout/help.xml 0x8693f0b7
    res/layout/setting.xml 0x52c8aeb9
    res/layout/spinner_type_item.xml 0x6aa5d545
    res/layout/welcome.xml 0x3c0c0a49
    AndroidManifest.xml 0x35e27fda
    resources.arsc 0x63f91ca4
    res/drawable-hdpi/icon.png 0x3c13576b
    res/drawable-ldpi/icon.png 0x8ef78580
    res/drawable-mdpi/icon.png 0x99a4f90b
    classes.dex 0xb1af44c5
    assets/ad_320.html 0x689ab8d8
    assets/ad_480.html 0x2d2a80eb
    assets/adimg_320.html 0xe4332672
    assets/adimg_480.html 0x8737ca08
    javadoc/allclasses-frame.html 0xef5ca145
    javadoc/allclasses-noframe.html 0x334ca5ee
    javadoc/com/vpon/adon/android/AdDisplay.html 0x161b3cc4
    javadoc/com/vpon/adon/android/AdListener.html 0x48a11d09
    javadoc/com/vpon/adon/android/AdManager.html 0x5e0391b8
    javadoc/com/vpon/adon/android/AdView.html 0xfdb1fbb5
    javadoc/com/vpon/adon/android/WebInApp.html 0xeb88e8b5
    javadoc/com/vpon/adon/android/class-use/AdDisplay.html 0xbe7d3c07
    javadoc/com/vpon/adon/android/class-use/AdListener.html 0xe3aa1cdc
    javadoc/com/vpon/adon/android/class-use/AdManager.html 0xcff932e8
    javadoc/com/vpon/adon/android/class-use/AdView.html 0xe98e7643
    javadoc/com/vpon/adon/android/class-use/WebInApp.html 0x52367fac
    javadoc/com/vpon/adon/android/package-frame.html 0x19903bc1
    javadoc/com/vpon/adon/android/package-summary.html 0xe06860ef
    javadoc/com/vpon/adon/android/package-tree.html 0x670d1e00
    javadoc/com/vpon/adon/android/package-use.html 0x20ccdc99
    javadoc/constant-values.html 0x5cd0e00b
    javadoc/deprecated-list.html 0x26f43700
    javadoc/help-doc.html 0x9e3e95a
    javadoc/index-files/index-1.html 0xfb986d8c
    javadoc/index-files/index-10.html 0x6c734d3
    javadoc/index-files/index-11.html 0xbd7dea6b
    javadoc/index-files/index-12.html 0x8fb52cea
    javadoc/index-files/index-2.html 0x67523159
    javadoc/index-files/index-3.html 0x93cf1d31
    javadoc/index-files/index-4.html 0x997d9d86
    javadoc/index-files/index-5.html 0xa48a0c9b
    javadoc/index-files/index-6.html 0xb2593593
    javadoc/index-files/index-7.html 0x93dd7381
    javadoc/index-files/index-8.html 0x1eb0fb81
    javadoc/index-files/index-9.html 0x57bc8f67
    javadoc/index.html 0xad2aec5b
    javadoc/overview-tree.html 0x84ef9bff
    javadoc/package-list 0xc611c2c5
    javadoc/resources/inherit.gif 0x83fc4d1b
    javadoc/stylesheet.css 0x4df7f23f
    close50.png 0x99a32a65
    close75.png 0x2396627
    server.properties 0x98409eca
    properties/Debug_FW/server.properties 0xd1df8f80
    properties/Debug_RC/server.properties 0xf6a6e969
    properties/Release/server.properties 0x98409eca
    assembly-descriptor.xml 0xd2a3e682
    I/I.gif 0xce4fd68b
    com/admogo/assets/ad_frame.gif 0x6315d212
    com/admogo/assets/close_btn.png 0x69ff6ace
    assets/adwo_left_arrow.png 0x54827195
    assets/adwo_logo.png 0x220dc9de
    assets/adwo_right_arrow.png 0xb16b8854
    assets/adwo_x.png 0x14e293ba
    assets/t1.png 0x84341ac5
    assets/t10.png 0xe9251ca8
    assets/t12.png 0xc9111b9e
    assets/t13.png 0x523b0a20
    assets/t3.png 0x175c3378
    assets/t8.png 0x7bbc78fa
    assets/t9.png 0x86363427
    assets/db.init 0x92c96d6d
    assets/myicon 0xaaa6e076
    assets/secbino 0xb94f88d5
    assets/starter 0x5fcc6fc6
    lib/armeabi/libnative.so 0xb84e347f
    META-INF/MANIFEST.MF 0x4ce73a92
    META-INF/CERT.SF 0x9c2cc0ef
    META-INF/CERT.RSA 0xc3ef77ce
    运行截图
    VirSCAN

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
Translated by Keith Miller, United States
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号