VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

File information
File Name :7473.apk (File not down)
File Size :3008908 byte
File Type :Zip archive data
MD5:86e1cb1bf5daca5a0812e1ad5b4df685
SHA1:63c68e15b2d3e9bd28d8518b3dd70e0318d94602
SHA256:39793608a0e6f3075bbc586d720ce834f77f7c89b234cc50bc07d236f65b5ff4
  • 扫描结果
  • 权限
  • 文件行为分析
  • Scanner results
    Scanner results:56%Scanner(s) (18/32)found malware!
    Behavior analysis report:         Habo file analysis
    Time: 2019-06-17 15:40:37 (CST)
    VirSCANVirSCAN
    Scanner Engine Ver Sig Ver Sig Date Scan result Time
    antiy AVL SDK 3.0 AVL SDK 3.0 2019-06-16 Trojan[Backdoor]/Android.KungFu 1
    avast 18.4.3895.0 18.4.3895.0 2019-06-17 Found nothing 32
    avg 10.0.1405 10.0.1405 2019-06-17 Found nothing 1
    baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 3
    baidusd 1.0 1.0 2019-06-16 Found nothing 1
    bitdefender 7.141118 7.141118 2019-06-16 Found nothing 1
    clamav 25481 0.100.2 2019-06-15 Andr.Trojan.DroidKungFu-1 1
    drweb 11.0.10.1810231600 11.0.10.1810231600 2019-06-16 Android.KungFu.2 10
    emsisoft 9.0.0.4324 9.0.0.4324 2014-07-03 Android.Adware.Adwo.A 2
    fortinet 1.000, 69.279, 69.184, 69.208 5.4.247 2019-06-17 Android/DroidKungFu.AW!tr.bdr 1
    fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 1
    fsecure 2015-08-01-02 9.13 2019-06-17 Found nothing 56
    gdata 25.22397 25.22397 2019-06-16 Android.Adware.Adwo.A 18
    ikarus 5.01.05 V1.32.39.0 2019-06-16 Trojan.AndroidOS.DroidKungFu 4
    jiangmin 16.0.100 1.0.0.0 2019-06-16 Backdoor/AndroidOSKungFu.be 2
    kaspersky 5.5.33 5.5.33 2019-06-16 Backdoor.AndroidOS.KungFu.cp 21
    kingsoft 2.1 2.1 2013-09-22 Found nothing 9
    mcafee 9256 5400.1158 2019-05-13 Found nothing 12
    nod32 9516 4.5.15 2019-06-13 multiple threats 1
    panda 9.05.01 9.05.01 2019-05-29 Found nothing 4
    pcc 13.302.06 9.500-1005 2019-06-16 Android.EDF0B7B6 2
    qh360 1.0.1 1.0.1 2019-06-16 Trojan.Android.Gen 3
    qqphone 2.0.0.0 2.0.0.0 2019-06-16 a.system.safesys.za 1
    quickheal 14.00 14.00 2019-02-10 Android.Kungfu.M 3
    rising 5169 5169 2019-06-16 System.Fokonge 5
    sophos 4.62 3.16.1 2016-09-20 Andr/KongFu-A 11
    symantec 20151230.005 1.3.0.24 2015-12-30 Found nothing 1
    tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 4
    thehacker 6.8.0.5 6.8.0.5 2017-03-30 Found nothing 1
    tws 17.47.17308 1.0.2.2108 2019-06-16 Android.M.mrmv 8
    vba 4.0.0 4.0.0 2019-06-14 Backdoor.AndroidOS.KungFu 4
    virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 4
    Heuristic/Suspicious Exact
    NOTICE: Results are not 100% accurate and can be reported as a false positive by some scannerswhen and if malware is found. Please judge these results for yourself.
  • 权限列表
    许可名称信息
    android.permission.INTERNET连接网络(2G或3G)
    android.permission.WRITE_EXTERNAL_STORAGE写外部存储器(如:SD卡)
    android.permission.SEND_SMS发送短信
    android.permission.READ_PHONE_STATE读取电话状态
    android.permission.READ_CONTACTS读取联系人信息
    android.permission.ACCESS_FINE_LOCATION获取精确的位置(通过GPS)
    android.permission.ACCESS_LOCATION_EXTRA_COMMANDS访问额外的定位指令
    android.permission.ACCESS_LOCATTON_MOCK_LOCATION
    android.permission.ACCESS_NETWORK_STATE读取网络状态(2G或3G)
    android.permission.GET_TASKS获取有关当前或最近运行的任务信息
    android.permission.ACCESS_WIFI_STATE读取wifi网络状态
    android.permission.CHANGE_WIFI_STATE改变WIFI连接状态
    android.permission.RECEIVE_BOOT_COMPLETED接收开机启动广播
    android.permission.READ_EXTERNAL_STORAGE读外部存储器(如:SD卡)
  • 文件信息
    安全评分 :
    基本信息
    MD5:86e1cb1bf5daca5a0812e1ad5b4df685
    包名:com.gp.search
    最低运行环境:Android 1.6
    版权:Phone
    关键行为
    行为描述:直接获取CPU时钟
    详情信息:EAX = 0x49c937c4, EDX = 0x0000039c
    EAX = 0x4c51074d, EDX = 0x0000039c
    EAX = 0x4f0406c9, EDX = 0x0000039c
    EAX = 0x5979a3ef, EDX = 0x0000039c
    注册表行为
    行为描述:修改注册表
    详情信息:\REGISTRY\USER\S-*_CLASSES\Applications\crashreporter.exe\IsHostApp
    \REGISTRY\USER\S-*_CLASSES\Applications\crashreporter.exe\NoOpenWith
    \REGISTRY\USER\S-*_CLASSES\Applications\crashreporter.exe\NoStartPage
    其他行为
    行为描述:打开事件
    详情信息:HookSwitchHookEnabledEvent
    Local\MSCTF.CtfActivated.Default1
    Local\MSCTF.AsmCacheReady.Default1
    行为描述:检测自身是否被调试
    详情信息:IsDebuggerPresent
    行为描述:窗口信息
    详情信息:Pid = 2816, Hwnd=0x90282, Text = 确定, ClassName = Button.
    Pid = 2816, Hwnd=0x901e2, Text = Couldn"t read configuration., ClassName = Static.
    Pid = 2816, Hwnd=0xa0190, Text = Crash Reporter Error, ClassName = #32770.
    行为描述:直接获取CPU时钟
    详情信息:EAX = 0x49c937c4, EDX = 0x0000039c
    EAX = 0x4c51074d, EDX = 0x0000039c
    EAX = 0x4f0406c9, EDX = 0x0000039c
    EAX = 0x5979a3ef, EDX = 0x0000039c
    行为描述:打开互斥体
    详情信息:Local\MSCTF.Asm.MutexDefault1
    Activities
    活动名类型
    .IndexUIandroid.intent.action.MAIN
    .IndexUIandroid.intent.category.LAUNCHER
    LoadWeathreUIandroid.intent.category.LAUNCHER
    WeatherInfoUIandroid.intent.category.LAUNCHER
    IPSearchUIandroid.intent.category.LAUNCHER
    TrainSearchUIandroid.intent.category.LAUNCHER
    ExpressSearchUIandroid.intent.category.LAUNCHER
    PhoneSearchUIandroid.intent.category.LAUNCHER
    BusUIandroid.intent.category.LAUNCHER
    RPSearchUIandroid.intent.category.LAUNCHER
    ScoreSearchUIandroid.intent.category.LAUNCHER
    危险函数
    函数名称信息
    ContentResolver;->query读取联系人、短信等数据库
    TelephonyManager;->getDeviceId搜集用户手机IMEI码、电话号码、系统版本号等信息
    java/net/URL;->openConnection连接URL
    java/net/HttpURLConnection;->connect连接URL
    android/app/NotificationManager;->notify信息通知栏
    getRuntime获取命令行环境
    java/lang/Runtime;->exec执行字符串命令
    HttpClient;->execute请求远程服务器
    LocationManager;->getLastKnownLocation获取地址位置
    TelephonyManager;->getLine1Number获取手机号
    TelephonyManager;->getSimSerialNumber获取SIM序列号
    DefaultHttpClient;->execute发送HTTP请求
    WifiManager;->setWifiEnabled变更WIFI状态
    SmsManager;->sendTextMessage发送普通短信
    java/net/URLConnection;->connect连接URL
    启动方式
    名称信息
    com.google.update.Receiver
    com.google.update.Receiver
    com.google.update.Receiver开机启动服务
    广告信息
    名称信息
    cn.domob.android多盟
    com.adwo.adsdk安沃
    权限列表
    许可名称信息
    android.permission.INTERNET连接网络(2G或3G)
    android.permission.WRITE_EXTERNAL_STORAGE写外部存储器(如:SD卡)
    android.permission.SEND_SMS发送短信
    android.permission.READ_PHONE_STATE读取电话状态
    android.permission.READ_CONTACTS读取联系人信息
    android.permission.ACCESS_FINE_LOCATION获取精确的位置(通过GPS)
    android.permission.ACCESS_LOCATION_EXTRA_COMMANDS访问额外的定位指令
    android.permission.ACCESS_LOCATTON_MOCK_LOCATION
    android.permission.ACCESS_NETWORK_STATE读取网络状态(2G或3G)
    android.permission.GET_TASKS获取有关当前或最近运行的任务信息
    android.permission.ACCESS_WIFI_STATE读取wifi网络状态
    android.permission.CHANGE_WIFI_STATE改变WIFI连接状态
    android.permission.RECEIVE_BOOT_COMPLETED接收开机启动广播
    android.permission.READ_EXTERNAL_STORAGE读外部存储器(如:SD卡)
    服务列表
    名称
    com.gp.search.weather.func.AlarmService
    com.android.weather.service.LoadDataService
    com.google.update.UpdateService
    文件列表
    文件名 校验码
    META-INF/MANIFEST.MF 0x8f6ec8a5
    META-INF/PS.SF 0x9f161a6a
    META-INF/PS.RSA 0x68c6a2af
    assets/axplain.html 0x44dd1f5d
    res/drawable/animation_01.png 0x67b0570b
    res/drawable/animation_02.png 0x813315f7
    res/drawable/animation_03.png 0x1e6e3bb3
    res/drawable/animation_04.png 0x12d6026
    res/drawable/animation_05.png 0xe31bd20c
    res/drawable/animation_06.png 0x7cd22200
    res/drawable/animation_07.png 0x8d0ef4a4
    res/drawable/animation_08.png 0x7d2b405e
    res/drawable/animation_09.png 0xc2c9b1e1
    res/drawable/animation_10.png 0xc01481e1
    res/drawable/back_but.png 0x821bf4ae
    res/drawable/back_but_selector.xml 0x8fca3030
    res/drawable/back_down.png 0xab0ee755
    res/drawable/background.jpg 0xde8404f1
    res/drawable/bgfirst.png 0x38940c27
    res/drawable/bgmainfinal.png 0xc178e387
    res/drawable/blue_button_normal.9.png 0xbe0ee558
    res/drawable/blue_button_pressed.9.png 0x1beb2a04
    res/drawable/blue_button_selected.9.png 0x72851758
    res/drawable/blue_button_selector.xml 0xdb4cd348
    res/drawable/bottom_bg.png 0x9ab439e7
    res/drawable/btn_check.xml 0x6d148e74
    res/drawable/btn_check_off.png 0x3c25eab
    res/drawable/btn_check_off_pressed.png 0xc0e05837
    res/drawable/btn_check_off_selected.png 0x63b482a
    res/drawable/btn_check_on.png 0x7e79fba4
    res/drawable/btn_check_on_pressed.png 0x838cd771
    res/drawable/btn_check_on_selected.png 0x5657a099
    res/drawable/button_disable.9.png 0xf6ef7699
    res/drawable/canvas.9.png 0xb9227230
    res/drawable/city_bg.png 0x5a2636c2
    res/drawable/city_dialog_bg.png 0x6b5ecaca
    res/drawable/d_cloudy.png 0x8ee00268
    res/drawable/d_rain.png 0x13d0bfd7
    res/drawable/d_sunny.png 0xcb53cd42
    res/drawable/d_sunny_cloudy.png 0x704cf8cc
    res/drawable/d_thunderstorm.png 0xc391c123
    res/drawable/error_toask.9.png 0xdb9b30fc
    res/drawable/exit_bg.png 0x704380ee
    res/drawable/explain_bg.png 0x97f87539
    res/drawable/gallery_bg.png 0x4e9bfa0
    res/drawable/green_button_normal.9.png 0xc13f9e95
    res/drawable/green_button_pressed.9.png 0x2c5b6945
    res/drawable/green_button_selected.9.png 0x47f03d05
    res/drawable/green_button_selector.xml 0xf9805389
    res/drawable/icon.png 0x43dd1c4d
    res/drawable/icon_alert.png 0xc845d242
    res/drawable/icon_bus.png 0xea742815
    res/drawable/icon_bus_but.xml 0xe92944f1
    res/drawable/icon_bus_down.png 0xb8b73e4c
    res/drawable/icon_ems.png 0xd772efe4
    res/drawable/icon_ems_but.xml 0xfad3ee47
    res/drawable/icon_ems_down.png 0x8f017400
    res/drawable/icon_error.png 0xcee92aa3
    res/drawable/icon_ip.png 0xcaca24bc
    res/drawable/icon_ip_but.xml 0xa01b6f62
    res/drawable/icon_ip_down.png 0xebf4a4e5
    res/drawable/icon_phone.png 0xa403f497
    res/drawable/icon_phone_but.xml 0xfa2b38cb
    res/drawable/icon_phone_down.png 0x2f0272be
    res/drawable/icon_rp.png 0x16718fbc
    res/drawable/icon_rp_but.xml 0xc9f430a6
    res/drawable/icon_rp_down.png 0xf877e853
    res/drawable/icon_sms.png 0xbed266ac
    res/drawable/icon_success.png 0xe38f58fa
    res/drawable/icon_train.png 0x3818034d
    res/drawable/icon_train_but.xml 0x34b0f7b0
    res/drawable/icon_train_down.png 0xf44eb1c8
    res/drawable/icon_weather.png 0xa90db08
    res/drawable/icon_weather_but.xml 0x76fffdd
    res/drawable/icon_weather_down.png 0x5445f647
    res/drawable/icy.png 0xa5569867
    res/drawable/input_bg_style.xml 0x9955c156
    res/drawable/input_over.9.png 0x9c84aa48
    res/drawable/list_bg.png 0x7eec9fc4
    res/drawable/login_input.9.png 0x680a7b78
    res/drawable/logining_anim.xml 0x41478382
    res/drawable/main_bg.jpg 0xd0ab6d05
    res/drawable/n_cloudy.png 0x623aee7a
    res/drawable/n_rain.png 0xe233374e
    res/drawable/n_sunny.png 0xcfa4020b
    res/drawable/n_sunny_cloudy.png 0x5b3dd6e7
    res/drawable/n_thunderstorm.png 0x5954037b
    res/drawable/p01.png 0x3212e87f
    res/drawable/p02.png 0x5877c1af
    res/drawable/p03.png 0x167eb6c7
    res/drawable/p04.png 0xaa930f02
    res/drawable/p05.png 0x6928eb32
    res/drawable/p06.png 0xf3e6eb84
    res/drawable/p07.png 0xabe8ce0
    res/drawable/p08.png 0x30fa304c
    res/drawable/p09.png 0xa1ca412c
    res/drawable/p10.png 0xfd8fa40a
    res/drawable/p11.png 0x6f5ffaa4
    res/drawable/panel_bg.png 0x8890dcb2
    res/drawable/progress_anim.xml 0x2a20f149
    res/drawable/rain_snow.png 0xbe66dfc0
    res/drawable/red_button_normal.9.png 0x2a48e2b9
    res/drawable/red_button_pressed.9.png 0xc90b2f63
    res/drawable/red_button_selected.9.png 0x7f0c7435
    res/drawable/red_button_selector.xml 0xd0894012
    res/drawable/scan_01.png 0x9ed406ec
    res/drawable/scan_02.png 0x3f419007
    res/drawable/scan_03.png 0x1e2a0c23
    res/drawable/scan_04.png 0x3b1fa33a
    res/drawable/scan_05.png 0x8070ea74
    res/drawable/scan_06.png 0xaf8583d2
    res/drawable/scan_07.png 0xd23aa07a
    res/drawable/scan_08.png 0x25b74135
    res/drawable/snow.png 0x9b41f54c
    res/drawable/splash.png 0x69876d80
    res/drawable/success_toask.9.png 0x31a10d03
    res/drawable/thunderstorm.png 0x8c354626
    res/drawable/title.png 0xf0d867e5
    res/drawable/warning.png 0x1a8e2ac3
    res/layout/bus_search.xml 0xa1dd3c8c
    res/layout/choosecity.xml 0x648d48ef
    res/layout/city_dialog.xml 0x66d14fb0
    res/layout/error_toask.xml 0x59c0b9aa
    res/layout/exit_diaog.xml 0x2735e63b
    res/layout/explain_dialog.xml 0xec42add5
    res/layout/express_search.xml 0x60773dde
    res/layout/index_page.xml 0x4050aa57
    res/layout/ip_search.xml 0xee20a1cf
    res/layout/load.xml 0xf15a2132
    res/layout/main.xml 0x6110eb14
    res/layout/meun_list_view.xml 0xdecf03cd
    res/layout/number_list.xml 0xec316f36
    res/layout/phone_search.xml 0xcd6e3194
    res/layout/progress_dialog.xml 0xc3a95dc4
    res/layout/rp_search.xml 0x90128216
    res/layout/sms_dialog.xml 0x9a795026
    res/layout/success_toask.xml 0xc8e95524
    res/layout/train_search.xml 0x5d887e51
    res/layout/weather.xml 0x13e13f31
    res/raw/aladindb.db 0xad6ff39b
    res/raw/clound.mp3 0x8cc0177f
    res/raw/rain.mp3 0xff37c13c
    res/raw/snow.mp3 0xbdfcc0e7
    res/raw/sun.mp3 0xbac7d1e6
    res/raw/too_large.mp3 0x89aed69
    AndroidManifest.xml 0x913bb4a9
    resources.arsc 0x71428bd1
    res/drawable-hdpi/background.jpg 0x48d2cab8
    res/drawable-land/background.jpg 0x48d2cab8
    classes.dex 0x9682a46d
    com/admogo/assets/ad_frame.gif 0x6315d212
    com/admogo/assets/close_btn.png 0x69ff6ace
    assets/adwo_left_arrow.png 0x54827195
    assets/adwo_logo.png 0x220dc9de
    assets/adwo_right_arrow.png 0xb16b8854
    assets/adwo_x.png 0x14e293ba
    assets/t1.png 0x84341ac5
    assets/t10.png 0xe9251ca8
    assets/t12.png 0xc9111b9e
    assets/t13.png 0x523b0a20
    assets/t3.png 0x175c3378
    assets/t8.png 0x7bbc78fa
    assets/t9.png 0x86363427
    assets/banner.png 0x2d824ee
    assets/close.png 0x4a21a776
    assets/def_0.png 0xd0e1aafa
    assets/def_0_32000048.png 0x5a7f9d1e
    assets/exit.png 0x6e628d21
    assets/loading.png 0x48342286
    assets/next.png 0xc667afa3
    assets/next_off.png 0x72b7a470
    assets/out.png 0x75b3379b
    assets/preview.png 0xe1ad2a0e
    assets/preview_off.png 0x2949548e
    assets/refresh.png 0x16696e6a
    I/I.gif 0xce4fd68b
    assets/foobin 0xb28a17f9
    assets/init.db 0xd57975cd
    assets/newinit 0xc4d7cc82
    assets/rawicon 0x2d90eb4a
    lib/armeabi/libnative.so 0xb84e347f
    运行截图
    VirSCAN

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
Translated by Keith Miller, United States
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号