VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, VirSCAN can scan compressed files with password 'infected' or 'virus'.

Language
Server load
Server Load



File information
File Name : JrdTorch.apk (File not down)
File Size :1033140 byte
File Type :application/jar
MD5:4575d9315edf6fb782bfe14bf0dc654e
SHA1:8d26f4f42ac995d98083614770e3c9908b0242ac
  • 扫描结果
  • 权限
  • 文件行为分析
  • Scanner results
    Scanner results:0%Scanner(s) (0/32)found malware!        Behavior
    Time: 2015-10-31 16:40:32 (CST)
    VirSCANVirSCAN
    Scanner Engine Ver Sig Ver Sig Date Scan result Time
    antiy AVL SDK 3.0 1970-01-01 Found nothing 5
    asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
    avast 150725-1 4.7.4 2015-07-25 Found nothing 0
    avg 2109/8133 10.0.1405 2014-11-26 Found nothing 0
    baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 5
    baidusd 1.0 1.0 2014-04-02 Found nothing 1
    bitdefender 7.58469 7.90123 2014-12-25 Found nothing 0
    clamav 19861 0.97.5 2014-12-31 Found nothing 0
    drweb 5.0.2.3300 5.0.1.1 2014-12-31 Found nothing 0
    fortinet 23.345, 23.345 5.1.158 2014-12-08 Found nothing 0
    fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 0
    fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 0
    gdata 25.4136 25.4136 2015-10-31 Found nothing 8
    ikarus 1.06.01 V1.32.31.0 2014-12-08 Found nothing 0
    jiangmin 16.0.100 1.0.0.0 2015-07-25 Found nothing 40
    kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 0
    kingsoft 2.1 2.1 2013-09-22 Found nothing 42
    mcafee 7638 5400.1158 2014-11-30 Found nothing 0
    nod32 0920 3.0.21 2014-12-23 Found nothing 0
    panda 9.05.01 9.05.01 2015-07-26 Found nothing 4
    pcc 11.380.07 9.500-1005 2014-12-31 Found nothing 0
    qh360 1.0.1 1.0.1 1.0.1 Found nothing 2
    qqphone 1.0.0.0 1.0.0.0 2014-12-09 Found nothing 0
    quickheal 14.00 14.00 2015-07-25 Found nothing 2
    rising 25.76.04.01 25.76.04.01 2015-07-24 Found nothing 1
    sophos 5.08 3.55.0 2014-12-01 Found nothing 0
    symantec 20141230.001 1.3.0.24 2014-12-30 Found nothing 0
    tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
    thehacker 6.8.0.5 6.8.0.5 2015-07-23 Found nothing 1
    tws 17.47.17308 1.0.2.2108 2014-12-08 Found nothing 13
    vba 3.12.26.3 3.12.26.3 2014-12-31 Found nothing 0
    virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 0
    Heuristic/Suspicious Exact
    NOTICE: Results are not 100% accurate and can be reported as a false positive by some scannerswhen and if malware is found. Please judge these results for yourself.
    Copy to clipboard
  • 权限列表
    许可名称信息
    android.permission.WAKE_LOCK手机屏幕关闭后后台进程仍运行
    android.permission.FLASHLIGHT访问闪光灯
    android.permission.CAMERA访问照相机设备
    android.permission.GET_TASKS获取有关当前或最近运行的任务信息
  • 文件信息
    安全评分 :
    基本信息
    MD5:4575d9315edf6fb782bfe14bf0dc654e
    包名:com.jrdcom.torch
    最低运行环境:Android 2.2.x
    版权:TCT
    关键行为
    行为描述:写权限映射文件
    详情信息:CiceroSharedMemDefaultS-*
    4bc1021d6119700d919a35ff52795e19c3367185
    行为描述:设置特殊文件夹属性
    详情信息:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
    C:\Documents and Settings\Administrator\Local Settings\History
    C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
    C:\Documents and Settings\Administrator\Cookies
    进程行为
    行为描述:枚举进程
    详情信息:N/A
    文件行为
    行为描述:添加计划任务
    详情信息:C:\WINDOWS\Tasks\AchieveBalance.job
    行为描述:创建可执行文件
    详情信息:C:\Documents and Settings\All Users\Application Data\{8c0bdbeb-59fb-2353-8c0b-bdbeb59f6fad}\%temp%\1446231065.097389.exe
    行为描述:查找文件
    详情信息:FileName = c:\documents and settings\all users\application data\{8c0bdbeb-59fb-2353-8c0b-bdbeb59f6fad}\%temp%\1446231065.224638.exe
    行为描述:写权限映射文件
    详情信息:CiceroSharedMemDefaultS-*
    4bc1021d6119700d919a35ff52795e19c3367185
    行为描述:设置特殊文件夹属性
    详情信息:C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
    C:\Documents and Settings\Administrator\Local Settings\History
    C:\Documents and Settings\Administrator\Local Settings\History\History.IE5
    C:\Documents and Settings\Administrator\Cookies
    行为描述:修改文件内容
    详情信息:C:\Documents and Settings\All Users\Application Data\{8c0bdbeb-59fb-2353-8c0b-bdbeb59f6fad}\%temp%\1446231065.100896.exe---> Offset = 49152
    C:\Documents and Settings\All Users\Application Data\{8c0bdbeb-59fb-2353-8c0b-bdbeb59f6fad}\996e.dat---> Offset = 0
    C:\WINDOWS\Tasks\AchieveBalance.job---> Offset = 0
    C:\Documents and Settings\All Users\Application Data\{8c0bdbeb-59fb-2353-8c0b-bdbeb59f6fad}\1c7b8d947ba15ed2---> Offset = 0
    网络行为
    行为描述:连接指定站点
    详情信息:InternetConnectA: ServerName = mscallcat.net, PORT = 80
    InternetConnectA: ServerName = keyallstate.link, PORT = 80
    InternetConnectA: ServerName = allmodel-pro.com, PORT = 80
    行为描述:打开HTTP请求
    详情信息:HttpOpenRequestA: mscallcat.net:80/?q=xc8r2xzt%2bnephlvcegki%2fxmkdchcaw%2fyawfm1gytbuexpti3iperfc7crjzloghj9xy%2b0khfconlp6yb7dssm%2f2m3rnvuc11%2f2ndu2c4ox3wnib0lz8zpd2wrvvhy6stz7o3nfhj0ig7mvbe4rcadq%2fw5%2b%2b%2bq201msmlpzuje2w25llhrizwcljtpudcqxgvptobhcy%2
    HttpOpenRequestA: keyallstate.link:80/?q=xc8r2xzt%2bnephlvcegki%2fxmkdchcaw%2fyawfm1gytbuexpti3iperfc7crjzloghj9xy%2b0khfconlp6yb7dssm%2f2m3rnvuc11%2f2ndu2c4ox3wnib0lz8zpd2wrvvhy6stz7o3nfhj0ig7mvbe4rcadq%2fw5%2b%2b%2bq201msmlpzuje2w25llhrizwcljtpudcqxgvptobhc
    HttpOpenRequestA: allmodel-pro.com:80/get/?q=ghfhy%2bnz7njqu20rjl9fj0mnaigd5gu9uun4azkwlu3/vpn3fa%2burjfmxsr38h99jbwa8ifufarmgrujxbr3ytemhxasnuomuongfbliebvjvngejyvaiguoh2ilnolgel8htpqdm6nfy7tqcevjf0r5lfo7mj%2bszhizxilhdgkeza94li0/%2babffjv%2bxdwd5fosqwxlk80y
    注册表行为
    行为描述:修改注册表
    详情信息:\REGISTRY\USER\S-*\Software\Microsoft\Windows\CurrentVersion\Uninstall\c1ce916364786b64\
    其他行为
    行为描述:创建互斥体
    详情信息:CTF.LBES.MutexDefaultS-*
    CTF.Compart.MutexDefaultS-*
    CTF.Asm.MutexDefaultS-*
    CTF.Layouts.MutexDefaultS-*
    CTF.TMD.MutexDefaultS-*
    CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
    行为描述:枚举窗口
    详情信息:N/A
    动态列表行为
    行为描述:注册广播接收器
    详情信息:[u'com.jrdcom.torch.TorchActivity$1@41550418', u'android.content.IntentFilter@414f0b38']
    行为描述:读取系统设置
    详情信息:[u'android.app.ContextImpl$ApplicationContentResolver@415504b8', u'sound_effects_enabled']
    行为描述:窗口信息
    详情信息:{"text": "Cannot connect to camera.", "class": "android.widget.TextView"}
    {"text": "OK", "class": "android.widget.Button"}
    行为描述:添加View
    详情信息:[u'com.android.internal.policy.impl.PhoneWindow$DecorView@414f0248', u'WM.LayoutParams{(0,0)(wrapxwrap) gr=#11 sim=#120 ty=2 fl=#1820002 pfl=0x8 fmt=-2 wanim=0x1030290}', u'android.view.CompatibilityInfoHolder@414b8680']
    [u'com.android.internal.policy.impl.PhoneWindow$DecorView@414f8898', u'WM.LayoutParams{(0,0)(wrapxwrap) gr=#11 sim=#120 ty=2 fl=#1820002 pfl=0x8 fmt=-2 wanim=0x1030290}', u'android.view.CompatibilityInfoHolder@414b8680']
    [u'com.android.internal.policy.impl.PhoneWindow$DecorView@41551158', u'WM.LayoutParams{(0,0)(fillxfill) sim=#100 ty=1 fl=#1810100 pfl=0x8 wanim=0x10302e0}', u'android.view.CompatibilityInfoHolder@414b8680']
    行为描述:写入文件
    详情信息:path:/data/data/com.jrdcom.torch/shared_prefs/TorchPrefsFile.xml length:120
    行为描述:获得当前运行的程序列表
    详情信息:[u'1']
    [u'1']
    Activities
    活动名类型
    com.jrdcom.torch.TorchActivityandroid.intent.action.MAIN
    com.jrdcom.torch.TorchActivityandroid.intent.category.LAUNCHER
    危险函数
    函数名称信息
    Camera;->open开启相机
    权限列表
    许可名称信息
    android.permission.WAKE_LOCK手机屏幕关闭后后台进程仍运行
    android.permission.FLASHLIGHT访问闪光灯
    android.permission.CAMERA访问照相机设备
    android.permission.GET_TASKS获取有关当前或最近运行的任务信息
    文件列表
    文件名 校验码
    AndroidManifest.xml 0x5f8992ad
    classes.dex 0xff7d261e
    res/drawable-hdpi-960x540/icon.png 0xcc6632a6
    res/drawable-hdpi/backgroundoff_nolevel.png 0x983f6ec3
    res/drawable-hdpi/backgroundon_nolevel.png 0xd5bb6dbe
    res/drawable-hdpi/icon.png 0xa6b484ed
    res/drawable-hdpi/imageselector.xml 0x356d8886
    res/drawable-hdpi/off.png 0xdf4c1b9d
    res/drawable-hdpi/on.png 0x10408e57
    res/drawable-hdpi/popup_colorbar_bright.png 0xaaef4d18
    res/drawable-hdpi/switchnotpressed.png 0xecbc3aea
    res/drawable-hdpi/switchpressed.png 0x8fb4999a
    res/drawable-hdpi/switchpressing.png 0x1995e8b7
    res/drawable-mdpi/backgroundoff_nolevel.png 0xf9d4d86f
    res/drawable-mdpi/backgroundon_nolevel.png 0x9c5cafb7
    res/drawable-mdpi/icon.png 0xa671a769
    res/drawable-mdpi/imageselector.xml 0x356d8886
    res/drawable-mdpi/off.png 0xdf4c1b9d
    res/drawable-mdpi/on.png 0x10408e57
    res/drawable-mdpi/popup_colorbar_bright.png 0xaaef4d18
    res/drawable-mdpi/switchnotpressed.png 0xecbc3aea
    res/drawable-mdpi/switchpressed.png 0x8fb4999a
    res/drawable-mdpi/switchpressing.png 0x1995e8b7
    res/drawable-xhdpi/backgroundoff_nolevel.png 0x975d2d25
    res/drawable-xhdpi/backgroundon_nolevel.png 0x1d0162b7
    res/drawable-xhdpi/icon.png 0x74fe0147
    res/drawable-xhdpi/off.png 0x8151e53e
    res/drawable-xhdpi/on.png 0x580f3442
    res/drawable-xhdpi/popup_colorbar_bright.png 0x27bd93a7
    res/drawable-xhdpi/switchnotpressed.png 0xece21090
    res/drawable-xxhdpi/backgroundmedium.png 0xff5bfb0
    res/drawable-xxhdpi/backgroundoff_nolevel.png 0xd09c20f7
    res/drawable-xxhdpi/backgroundon_nolevel.png 0x49231a24
    res/drawable-xxhdpi/icon.png 0x19f5f847
    res/drawable-xxhdpi/off.png 0x44410775
    res/drawable-xxhdpi/on.png 0xe3518a73
    res/drawable-xxxhdpi/icon.png 0x2f4ae1d3
    res/layout-800x480/main.xml 0x6c1401cb
    res/layout-hdpi-960x540/main.xml 0x8a6a9108
    res/layout-port-1800x1200/main.xml 0x9b44aaa4
    res/layout-xhdpi/main.xml 0x1daa10f8
    res/layout-xxhdpi/main.xml 0x8a6a9108
    res/layout/main.xml 0xea730525
    resources.arsc 0xdd054819
    META-INF/MANIFEST.MF 0xd1e9ec5a
    META-INF/CERT.SF 0xd84529a5
    META-INF/CERT.RSA 0x386883da
    运行截图
    VirSCAN

About VirSCAN | Privacy Policy | Contact us | link | Help VirSCAN
Translated by Keith Miller, United States
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号