VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

File information
File Name :4342.apk (File not down)
File Size :450288 byte
File Type :Zip archive data
MD5:211d424261064181ade1b015edd6c9cd
SHA1:a4b0e758e2f2c3da8359e410cbc8bf4c91bd6dab
SHA256:05a50d0d9420eac2c6aa11cddcfd46d479d5c26da9a43d2ee6848a4539c2d7f0
  • 扫描结果
  • 权限
  • 文件行为分析
  • Scanner results
    Scanner results:53%Scanner(s) (17/32)found malware!
    Behavior analysis report:         Habo file analysis
    Time: 2019-06-12 20:07:05 (CST)
    VirSCANVirSCAN
    Scanner Engine Ver Sig Ver Sig Date Scan result Time
    antiy AVL SDK 3.0 AVL SDK 3.0 2019-06-11 Trojan[Backdoor]/Android.KungFu 1
    avast 18.4.3895.0 18.4.3895.0 2019-06-12 Found nothing 46
    avg 10.0.1405 10.0.1405 2019-06-12 Found nothing 1
    baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 2
    baidusd 1.0 1.0 2019-06-11 Found nothing 1
    bitdefender 7.141118 7.141118 2019-06-11 Found nothing 1
    clamav 25476 0.100.2 2019-06-10 Andr.Trojan.KungFu-49 1
    drweb 11.0.10.1810231600 11.0.10.1810231600 2019-06-11 Android.Gongfu.2.origin 10
    emsisoft 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
    fortinet 1.000, 69.160, 69.017, 69.041 5.4.247 2019-06-12 Android/DroidKungFu.AW!tr.bdr 1
    fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 1
    fsecure 2015-08-01-02 9.13 2019-06-12 Found nothing 56
    gdata 25.22334 25.22334 2019-06-11 Android.Adware.Adwo.A 12
    ikarus 5.01.05 V1.32.39.0 2019-06-11 Trojan.AndroidOS.Mseg 4
    jiangmin 16.0.100 1.0.0.0 2019-06-11 Backdoor/AndroidOS.cmb 3
    kaspersky 5.5.33 5.5.33 2019-06-11 Backdoor.AndroidOS.KungFu.gn 20
    kingsoft 2.1 2.1 2013-09-22 Found nothing 8
    mcafee 9256 5400.1158 2019-05-13 Found nothing 13
    nod32 9446 4.5.15 2019-05-31 multiple threats 1
    panda 9.05.01 9.05.01 2019-05-29 Found nothing 3
    pcc 13.302.06 9.500-1005 2019-06-11 Android.10E8BFA9 2
    qh360 1.0.1 1.0.1 2019-06-11 Trojan.Android.Gen 3
    qqphone 2.0.0.0 2.0.0.0 2019-06-11 a.system.safesys.e 1
    quickheal 14.00 14.00 2019-02-10 Android.Kungfu.L 3
    rising 5146 5146 2019-06-11 System.Fokonge 3
    sophos 4.62 3.16.1 2016-09-20 Andr/KongFu-A 11
    symantec 20151230.005 1.3.0.24 2015-12-30 Found nothing 1
    tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
    thehacker 6.8.0.5 6.8.0.5 2017-03-30 Found nothing 1
    tws 17.47.17308 1.0.2.2108 2019-06-11 Android.M.trnx 7
    virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 3
    Heuristic/Suspicious Exact
    NOTICE: Results are not 100% accurate and can be reported as a false positive by some scannerswhen and if malware is found. Please judge these results for yourself.
  • 权限列表
    许可名称信息
    android.permission.INTERNET连接网络(2G或3G)
    android.permission.READ_EXTERNAL_STORAGE读外部存储器(如:SD卡)
    android.permission.READ_PHONE_STATE读取电话状态
    android.permission.ACCESS_COARSE_LOCATION获取粗略的位置(通过wifi、基站)
    android.permission.ACCESS_FINE_LOCATION获取精确的位置(通过GPS)
    android.permission.ACCESS_NETWORK_STATE读取网络状态(2G或3G)
    android.permission.ACCESS_LOCATION_EXTRA_COMMANDS访问额外的定位指令
    android.permission.WRITE_EXTERNAL_STORAGE写外部存储器(如:SD卡)
    android.permission.ACCESS_WIFI_STATE读取wifi网络状态
    android.permission.CHANGE_WIFI_STATE改变WIFI连接状态
    android.permission.INSTALL_PACKAGES安装应用
    android.permission.READ_SMS读取短信
    android.permission.WRITE_SMS写短信
    android.permission.GET_TASKS获取有关当前或最近运行的任务信息
  • 文件信息
    安全评分 :
    基本信息
    MD5:211d424261064181ade1b015edd6c9cd
    包名:com.alan.weather
    最低运行环境:Android 2.1.x
    版权:
    关键行为
    行为描述:直接获取CPU时钟
    详情信息:EAX = 0xd5d4de7a, EDX = 0x000000b3
    EAX = 0xd5d4dec6, EDX = 0x000000b3
    EAX = 0xf0261726, EDX = 0x000000b3
    EAX = 0xf0261772, EDX = 0x000000b3
    EAX = 0x769a5f45, EDX = 0x000000b4
    EAX = 0x769a5f91, EDX = 0x000000b4
    进程行为
    行为描述:创建本地线程
    详情信息:TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2456, ThreadID = 2468, StartAddress = 792A741C, Parameter = 00000000
    TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2456, ThreadID = 2472, StartAddress = 791F59C0, Parameter = 001B01D0
    TargetProcess: %temp%\****.exe, InheritedFromPID = 2000, ProcessID = 2456, ThreadID = 2508, StartAddress = 77DC845A, Parameter = 00000000
    文件行为
    行为描述:查找文件
    详情信息:FileName = C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
    FileName = C:\WINDOWS\Microsoft.NET\Framework\\*
    FileName = C:\WINDOWS\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.INI
    FileName = C:\Documents and Settings\Administrator\Local Settings\Temp
    FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%
    FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe
    FileName = C:\Documents and Settings
    FileName = C:\Documents and Settings\Administrator
    FileName = C:\Documents and Settings\Administrator\Local Settings
    FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.INI
    FileName = C:\WINDOWS\Microsoft.Net\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.INI
    FileName = C:\WINDOWS\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.INI
    FileName = C:\WINDOWS\Microsoft.Net\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI
    FileName = C:\WINDOWS\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.INI
    其他行为
    行为描述:检测自身是否被调试
    详情信息:IsDebuggerPresent
    行为描述:创建互斥体
    详情信息:CTF.LBES.MutexDefaultS-*
    CTF.Compart.MutexDefaultS-*
    CTF.Asm.MutexDefaultS-*
    CTF.Layouts.MutexDefaultS-*
    CTF.TMD.MutexDefaultS-*
    CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
    行为描述:创建事件对象
    详情信息:EventName = Global\CPFATE_2456_v4.0.30319
    行为描述:打开互斥体
    详情信息:ShimCacheMutex
    行为描述:打开事件
    详情信息:Global\CLR_PerfMon_StartEnumEvent
    \KernelObjects\LowMemoryCondition
    HookSwitchHookEnabledEvent
    行为描述:直接获取CPU时钟
    详情信息:EAX = 0xd5d4de7a, EDX = 0x000000b3
    EAX = 0xd5d4dec6, EDX = 0x000000b3
    EAX = 0xf0261726, EDX = 0x000000b3
    EAX = 0xf0261772, EDX = 0x000000b3
    EAX = 0x769a5f45, EDX = 0x000000b4
    EAX = 0x769a5f91, EDX = 0x000000b4
    Activities
    活动名类型
    .WeatherForecastandroid.intent.action.MAIN
    .WeatherForecastandroid.intent.category.LAUNCHER
    危险函数
    函数名称信息
    TelephonyManager;->getDeviceId搜集用户手机IMEI码、电话号码、系统版本号等信息
    HttpClient;->execute请求远程服务器
    LocationManager;->getLastKnownLocation获取地址位置
    TelephonyManager;->getLine1Number获取手机号
    java/net/URL;->openConnection连接URL
    java/net/HttpURLConnection;->connect连接URL
    TelephonyManager;->getSimSerialNumber获取SIM序列号
    android/app/NotificationManager;->notify信息通知栏
    java/net/URLConnection;->connect连接URL
    DefaultHttpClient;->execute发送HTTP请求
    WifiManager;->setWifiEnabled变更WIFI状态
    getRuntime获取命令行环境
    java/lang/Runtime;->exec执行字符串命令
    ContentResolver;->query读取联系人、短信等数据库
    启动方式
    名称信息
    com.google.update.Receiver
    com.google.update.Receiver
    com.google.update.Receiver开机启动服务
    广告信息
    名称信息
    com.google.adsAdMob
    com.vpon.adonVpon
    com.adwo.adsdk安沃
    权限列表
    许可名称信息
    android.permission.INTERNET连接网络(2G或3G)
    android.permission.READ_EXTERNAL_STORAGE读外部存储器(如:SD卡)
    android.permission.READ_PHONE_STATE读取电话状态
    android.permission.ACCESS_COARSE_LOCATION获取粗略的位置(通过wifi、基站)
    android.permission.ACCESS_FINE_LOCATION获取精确的位置(通过GPS)
    android.permission.ACCESS_NETWORK_STATE读取网络状态(2G或3G)
    android.permission.ACCESS_LOCATION_EXTRA_COMMANDS访问额外的定位指令
    android.permission.WRITE_EXTERNAL_STORAGE写外部存储器(如:SD卡)
    android.permission.ACCESS_WIFI_STATE读取wifi网络状态
    android.permission.CHANGE_WIFI_STATE改变WIFI连接状态
    android.permission.INSTALL_PACKAGES安装应用
    android.permission.READ_SMS读取短信
    android.permission.WRITE_SMS写短信
    android.permission.GET_TASKS获取有关当前或最近运行的任务信息
    服务列表
    名称
    com.google.update.UpdateService
    文件列表
    文件名 校验码
    res/drawable/bg360.jpg 0xc0f06ce4
    res/drawable/down360.gif 0xeeaa86d9
    res/drawable/icon360.jpg 0x4042d4d4
    res/drawable/sunny.gif 0x7fbcee1e
    res/drawable/yubao72.jpg 0x37dedc90
    res/layout/main.xml 0xac582d56
    res/layout/main_listview_item.xml 0xcca8825f
    AndroidManifest.xml 0xeab81a5f
    resources.arsc 0x5c9a3bcb
    res/drawable-hdpi/icon.png 0x3c13576b
    res/drawable-ldpi/icon.png 0x8ef78580
    res/drawable-mdpi/icon.png 0x99a4f90b
    classes.dex 0x74796c6b
    assets/ad_320.html 0x689ab8d8
    assets/ad_480.html 0x2d2a80eb
    assets/adimg_320.html 0xe4332672
    assets/adimg_480.html 0x8737ca08
    javadoc/allclasses-frame.html 0xef5ca145
    javadoc/allclasses-noframe.html 0x334ca5ee
    javadoc/com/vpon/adon/android/AdDisplay.html 0x161b3cc4
    javadoc/com/vpon/adon/android/AdListener.html 0x48a11d09
    javadoc/com/vpon/adon/android/AdManager.html 0x5e0391b8
    javadoc/com/vpon/adon/android/AdView.html 0xfdb1fbb5
    javadoc/com/vpon/adon/android/WebInApp.html 0xeb88e8b5
    javadoc/com/vpon/adon/android/class-use/AdDisplay.html 0xbe7d3c07
    javadoc/com/vpon/adon/android/class-use/AdListener.html 0xe3aa1cdc
    javadoc/com/vpon/adon/android/class-use/AdManager.html 0xcff932e8
    javadoc/com/vpon/adon/android/class-use/AdView.html 0xe98e7643
    javadoc/com/vpon/adon/android/class-use/WebInApp.html 0x52367fac
    javadoc/com/vpon/adon/android/package-frame.html 0x19903bc1
    javadoc/com/vpon/adon/android/package-summary.html 0xe06860ef
    javadoc/com/vpon/adon/android/package-tree.html 0x670d1e00
    javadoc/com/vpon/adon/android/package-use.html 0x20ccdc99
    javadoc/constant-values.html 0x5cd0e00b
    javadoc/deprecated-list.html 0x26f43700
    javadoc/help-doc.html 0x9e3e95a
    javadoc/index-files/index-1.html 0xfb986d8c
    javadoc/index-files/index-10.html 0x6c734d3
    javadoc/index-files/index-11.html 0xbd7dea6b
    javadoc/index-files/index-12.html 0x8fb52cea
    javadoc/index-files/index-2.html 0x67523159
    javadoc/index-files/index-3.html 0x93cf1d31
    javadoc/index-files/index-4.html 0x997d9d86
    javadoc/index-files/index-5.html 0xa48a0c9b
    javadoc/index-files/index-6.html 0xb2593593
    javadoc/index-files/index-7.html 0x93dd7381
    javadoc/index-files/index-8.html 0x1eb0fb81
    javadoc/index-files/index-9.html 0x57bc8f67
    javadoc/index.html 0xad2aec5b
    javadoc/overview-tree.html 0x84ef9bff
    javadoc/package-list 0xc611c2c5
    javadoc/resources/inherit.gif 0x83fc4d1b
    javadoc/stylesheet.css 0x4df7f23f
    close50.png 0x99a32a65
    close75.png 0x2396627
    server.properties 0x98409eca
    properties/Debug_FW/server.properties 0xd1df8f80
    properties/Debug_RC/server.properties 0xf6a6e969
    properties/Release/server.properties 0x98409eca
    com/admogo/assets/ad_frame.gif 0x6315d212
    com/admogo/assets/close_btn.png 0x69ff6ace
    assets/adwo_left_arrow.png 0x54827195
    assets/adwo_logo.png 0x220dc9de
    assets/adwo_right_arrow.png 0xb16b8854
    assets/adwo_x.png 0x14e293ba
    assets/t1.png 0x84341ac5
    assets/t10.png 0xe9251ca8
    assets/t12.png 0xc9111b9e
    assets/t13.png 0x523b0a20
    assets/t3.png 0x175c3378
    assets/t8.png 0x7bbc78fa
    assets/t9.png 0x86363427
    I/I.gif 0xce4fd68b
    net/youmi/android/a1.png 0x649540ce
    net/youmi/android/a10.png 0xadf16fa7
    net/youmi/android/a11.png 0x28eee3d
    net/youmi/android/a12.png 0x81f4fef1
    net/youmi/android/a13.png 0xdc5cb88f
    net/youmi/android/a14.png 0x4ec1d1d8
    net/youmi/android/a15.png 0x608873ca
    net/youmi/android/a16.png 0xc6c191d6
    net/youmi/android/a17.png 0xc4d8ce3c
    net/youmi/android/a18.png 0x8613ca91
    net/youmi/android/a19.png 0xd8d7bcb0
    net/youmi/android/a2.png 0x27b6c6e7
    net/youmi/android/a3.png 0xb4918afe
    net/youmi/android/a4.png 0x88379562
    net/youmi/android/a5.png 0x3567227e
    net/youmi/android/a6.png 0x97eaea74
    net/youmi/android/a7.png 0x66c38487
    net/youmi/android/a8.png 0x48136912
    net/youmi/android/a9.png 0x7e3a7259
    assets/db.init 0x92c96d6d
    assets/myicon 0xaaa6e076
    assets/secbino 0xb94f88d5
    assets/starter 0x5fcc6fc6
    lib/armeabi/libnative.so 0xb84e347f
    META-INF/MANIFEST.MF 0x4eeeedd4
    META-INF/CERT.SF 0x34d09baa
    META-INF/CERT.RSA 0x1bad45ce
    运行截图
    VirSCAN

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
Translated by Keith Miller, United States
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号