VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

Language
Server load
Server Load

File information
File Name :三网选择.apk (File not down)
File Size :9244 byte
File Type :Zip archive data
MD5:a19c8dd5f19d4aedd1556ad60b099bcd
SHA1:7c9c3c79b88c3eec0e508b1643a5d9a4f2daeddf
SHA256:865ae29aa1c5df6d29e7d20153acf3776a87b1218ee36e0940a2e138b119ddb5
SSDEEP:192:ElwNy7KO957A9hTlImE3FOxClwTA6zG4OieIREnsH3Q4NqMsp:EGNyeO9Sf7iBwPy4Bl++qMe
  • 扫描结果
  • 权限
  • 文件行为分析
  • Scanner results
    Scanner results:3%Scanner(s) (1/32)found malware!
    Behavior analysis report:         Habo file analysis
    Time: 2016-12-10 21:52:55 (CST)
    VirSCANVirSCAN
    Scanner Engine Ver Sig Ver Sig Date Scan result Time
    antiy AVL SDK 2.0 1970-01-01 Found nothing 5
    asquared 9.0.0.4799 9.0.0.4799 2015-03-08 Found nothing 1
    avast 161208-3 4.7.4 2016-12-08 Found nothing 60
    avg 2109/13037 10.0.1405 2016-12-05 Found nothing 60
    baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 38
    baidusd 1.0 1.0 2014-04-02 Found nothing 1
    bitdefender 7.58879 7.90123 2015-01-16 Found nothing 60
    clamav 22685 0.97.5 2016-12-09 Found nothing 60
    drweb 5.0.2.3300 5.0.1.1 2016-12-09 Found nothing 60
    fortinet 41.300, 41.300, 41.300 5.4.233 2016-12-10 Found nothing 60
    fprot 4.6.2.117 6.5.1.5418 2016-02-05 Found nothing 60
    fsecure 2015-08-01-02 9.13 2015-08-01 Found nothing 60
    gdata 25.8610 25.8610 2016-10-12 Found nothing 9
    ikarus 1.06.01 V1.32.31.0 2016-11-28 Found nothing 60
    jiangmin 16.0.100 1.0.0.0 2016-12-01 Found nothing 40
    kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 60
    kingsoft 2.1 2.1 2013-09-22 Android.RISKWARE.luomao.cr.(kcloud) 7
    mcafee 8254 5400.1158 2016-08-11 Found nothing 60
    nod32 1777 3.0.21 2015-06-12 Found nothing 60
    panda 9.05.01 9.05.01 2016-12-09 Found nothing 4
    pcc 12.943.00 9.500-1005 2016-12-06 Found nothing 60
    qh360 1.0.1 1.0.1 1.0.1 Found nothing 3
    qqphone 1.0.0.0 1.0.0.0 2015-12-30 Found nothing 60
    quickheal 14.00 14.00 2016-12-08 Found nothing 2
    rising 26.28.00.01 26.28.00.01 2016-07-18 Found nothing 1
    sophos 5.32 3.65.2 2016-10-10 Found nothing 60
    symantec 20151230.005 1.3.0.24 2015-12-30 Found nothing 60
    tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
    thehacker 6.8.0.5 6.8.0.5 2016-11-29 Found nothing 1
    tws 17.47.17308 1.0.2.2108 2016-12-09 Found nothing 13
    vba 3.12.29.3 beta 3.12.29.3 beta 2016-12-05 Found nothing 60
    virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 60
    Heuristic/Suspicious Exact
    NOTICE: Results are not 100% accurate and can be reported as a false positive by some scannerswhen and if malware is found. Please judge these results for yourself.
  • 没有相关的权限信息

  • 文件信息
    安全评分 :84
    基本信息
    MD5:a19c8dd5f19d4aedd1556ad60b099bcd
    包名:myc.phone.PhoneInfo
    最低运行环境:Android 1.5
    版权:
    关键行为
    行为描述:修改注册表_启动项
    详情信息:\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Run\c:\monitor\sample.exe
    进程行为
    行为描述:隐藏窗口创建进程
    详情信息:ImagePath = c:\windows\system32\taskmgr.exe, CmdLine = "c:\windows\system32\taskmgr.exe"
    行为描述:创建进程
    详情信息:ImagePath = C:\WINDOWS\system32\taskmgr.exe, CmdLine = "C:\WINDOWS\system32\taskmgr.exe"
    文件行为
    行为描述:写权限映射文件
    详情信息:Global\Cor_Private_IPCBlock_v4_300
    Global\Cor_SxSPublic_IPCBlock_300
    \Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    \WINDOWS\system32\zh-cn\ieframe.dll.mui
    Local\UrlZonesSM_Administrator
    注册表行为
    行为描述:修改注册表
    详情信息:\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\GDIPlus\FontCachePath
    \REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X\BaseClass
    行为描述:修改注册表_启动项
    详情信息:\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Run\c:\monitor\sample.exe
    其他行为
    行为描述:创建互斥体
    详情信息:Local\ZonesCounterMutex
    Local\ZoneAttributeCacheCounterMutex
    Local\ZonesCacheCounterMutex
    Local\ZonesLockedCacheCounterMutex
    SHIMLIB_LOG_MUTEX
    NTShell Taskman Startup Mutex
    行为描述:查找指定窗口
    详情信息:NtUserFindWindowEx: [Class,Window] = [,Windows 任务管理器]
    行为描述:窗口信息
    详情信息:Pid = 300, Hwnd=0xb0184, Text = ->, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
    Pid = 300, Hwnd=0xa01aa, Text = 9, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
    Pid = 300, Hwnd=0xb01b0, Text = 8, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
    Pid = 300, Hwnd=0xa018c, Text = 7, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
    Pid = 300, Hwnd=0xe016e, Text = 6, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
    Pid = 300, Hwnd=0xa0198, Text = 5, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
    Pid = 300, Hwnd=0xd01a4, Text = 4, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
    Pid = 300, Hwnd=0xc01e8, Text = 3, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
    Pid = 300, Hwnd=0xa0196, Text = 2, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
    Pid = 300, Hwnd=0xb01be, Text = 1, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
    Pid = 300, Hwnd=0xc01b4, Text = No micro:, ClassName = WindowsForms10.STATIC.app.0.2bf8098_r21_ad1.
    Pid = 300, Hwnd=0xb0164, Text = Unlock, ClassName = WindowsForms10.BUTTON.app.0.2bf8098_r21_ad1.
    Pid = 300, Hwnd=0xd01c8, Text = Multi.Lock.1 by aswen001, ClassName = WindowsForms10.Window.8.app.0.2bf8098_r21_ad1.
    行为描述:获取系统权限
    详情信息:SE_LOAD_DRIVER_PRIVILEGE
    动态列表行为
    行为描述:启动服务
    详情信息:com.android.musicfx.Compatibility$Service
    com.android.mms.transaction.SmsReceiverService
    行为描述:读取文件
    详情信息:path:/proc/758/cmdline length:105
    path:/proc/760/cmdline length:105
    path:/proc/772/cmdline length:105
    path:/proc/774/cmdline length:105
    path:/proc/783/cmdline length:105
    path:/proc/798/cmdline length:105
    path:/proc/810/cmdline length:105
    path:/proc/840/cmdline length:105
    path:/proc/851/cmdline length:105
    行为描述:类加载
    详情信息:path:/system/app/PicoTts.apk
    path:/system/app/MusicFX.apk
    path:/system/framework/am.jar
    path:/data/app/myc.phone.PhoneInfo-1.apk
    行为描述:初始化Intent
    详情信息:Ljava/lang/String;=android.intent.action.VIEW
    行为描述:激活Activity
    详情信息:act=android.intent.action.VIEW cmp=com.android.settings/.TestingSettings
    行为描述:写入文件
    详情信息:path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
    path:/data/data/com.android.musicfx/shared_prefs/musicfx.xml length:105
    path:/data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml length:105
    Activities
    活动名类型
    .PhoneInfoActivityandroid.intent.action.MAIN
    .PhoneInfoActivityandroid.intent.category.LAUNCHER
    文件列表
    文件名 校验码
    res/drawable/icon.png 0xcdefa6c3
    AndroidManifest.xml 0xc69b78e3
    resources.arsc 0xc736b7d
    classes.dex 0xa44fe60e
    META-INF/MANIFEST.MF 0xeb773e64
    META-INF/CERT.SF 0x8eff5d7a
    META-INF/CERT.RSA 0x7e49d36
    运行截图
    VirSCAN

About VirSCAN | Privacy Policy | Contact us | Links | Help VirSCAN
Powered By CentOSpol

京ICP备11007605号-12

pol

京公网安备 11010802020746号