File information

Scanner results
Scanner results:3%Scanner(s) (1/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2017-09-19 10:43:39 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 2.0 1970-01-01 Found nothing 7
asquared 2015-03-08 Found nothing 7
avast 170303-1 4.7.4 2017-03-03 Found nothing 60
avg 2109/14460 10.0.1405 2017-09-14 Found nothing 60
baidu Found nothing 6
baidusd 1.0 1.0 2017-03-22 Found nothing 1
bitdefender 7.58879 7.90123 2015-01-16 Found nothing 60
clamav 23845 0.97.5 2017-09-17 Found nothing 60
drweb 2017-09-11 Found nothing 60
fortinet 1.000, 51.740, 51.597, 51.621 5.4.247 2017-09-19 Found nothing 60
fprot 2016-02-05 Found nothing 60
fsecure 2015-08-01-02 9.13 2015-08-01 Found nothing 60
gdata 25.14236 25.14236 2017-09-18 Found nothing 17
ikarus 3.02.09 V1.32.31.0 2017-09-18 Found nothing 60
jiangmin 16.0.100 2017-09-18 Trojan.AndroidOS.bxpc 3
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 60
kingsoft 2.1 2.1 2017-09-18 Found nothing 60
mcafee 8620 5400.1158 2017-08-12 Found nothing 60
nod32 6095 3.0.21 2017-09-17 Found nothing 60
panda 9.05.01 9.05.01 2017-09-18 Found nothing 5
pcc 13.302.06 9.500-1005 2017-03-27 Found nothing 60
qh360 1.0.1 1.0.1 1.0.1 Found nothing 4
qqphone 2015-12-30 Found nothing 60
quickheal 14.00 14.00 2017-09-18 Found nothing 6
rising 2016-07-18 Found nothing 18
sophos 5.32 3.65.2 2016-10-10 Found nothing 60
symantec 20151230.005 2015-12-30 Found nothing 60
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 15
thehacker 2017-09-16 Found nothing 6
tws 17.47.17308 2017-09-18 Found nothing 19
vba beta beta 2017-09-18 Found nothing 60
virusbuster 15.0.985.0 2014-12-05 Found nothing 60
许可名称 信息
android.permission.KILL_BACKGROUND_PROCESSES 关闭后台进程
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.CHANGE_WIFI_STATE 改变WIFI连接状态
android.permission.CHANGE_NETWORK_STATE 变更网络状态
android.permission.INTERNET 连接网络(2G或3G)
android.permission.SET_WALLPAPER 设置桌面壁纸
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态 创建快捷方式 删除快捷方式
android.permission.BLUETOOTH 连接蓝牙设备
android.permission.BLUETOOTH_ADMIN 搜寻蓝牙设备
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.WAKE_LOCK 手机屏幕关闭后后台进程仍运行
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.VIBRATE 允许设备震动
android.permission.CHANGE_WIFI_MULTICAST_STATE 变更WIFI多播状态
android.permission.SYSTEM_ALERT_WINDOW 显示系统窗口
android.permission.GET_TASKS 获取有关当前或最近运行的任务信息
安全评分 :
上传时间: 2014-09-22 10:36:30 (CST)
最低运行环境:Android 2.3, 2.3.1, 2.3.2
行为描述: 修改硬盘引导扇区
详情信息: NtWriteFile
行为描述: 修改硬盘引导扇区
详情信息: NtWriteFile
行为描述: 创建文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\__tmp_rar_sfx_access_check_215906
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\msg.vbs
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\Win7.cmd
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootinst.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootrest.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\showdrive.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\w7ldr
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\Certificate.xrm-ms
行为描述: 创建可执行文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootinst.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootrest.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\showdrive.exe
行为描述: 查找文件
详情信息: FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\****.exe
FileName = C:\Documents and Settings
FileName = C:\Documents and Settings\Administrator
FileName = C:\Documents and Settings\Administrator\My Documents
FileName = C:\Documents and Settings\All Users
FileName = C:\Documents and Settings\All Users\Documents
FileName = C:\Documents and Settings\Administrator\桌面
FileName = C:\Documents and Settings\All Users\桌面
FileName = C:\DOCUME~1
FileName = C:\DOCUME~1\ADMINI~1
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\RarSFX0
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\RarSFX0\Win7.cmd
FileName = C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\RarSFX0\echo..*
行为描述: 删除文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\__tmp_rar_sfx_access_check_215906
行为描述: 修改BAT脚本文件
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\msg.vbs ---> Offset = 0
行为描述: 修改文件内容
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\Win7.cmd ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootinst.exe ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootinst.exe ---> Offset = 7168
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootinst.exe ---> Offset = 11008
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootinst.exe ---> Offset = 83968
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootinst.exe ---> Offset = 86272
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootrest.exe ---> Offset = 7168
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootrest.exe ---> Offset = 11008
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootrest.exe ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootrest.exe ---> Offset = 4096
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\showdrive.exe ---> Offset = 0
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\showdrive.exe ---> Offset = 4096
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\showdrive.exe ---> Offset = 8192
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\showdrive.exe ---> Offset = 12288
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\w7ldr ---> Offset = 0
行为描述: 修改注册表
详情信息: \REGISTRY\USER\S-*\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\RarSFX0\Win7.cmd
行为描述: 创建互斥体
详情信息: CTF.LBES.MutexDefaultS-*
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,ComboLBox]
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [EDIT,]
NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
行为描述: 修改硬盘引导扇区
详情信息: NtWriteFile
行为描述: 调整进程token权限
行为描述: 打开事件
详情信息: HookSwitchHookEnabledEvent
行为描述: 直接操作物理设备
详情信息: \??\PhysicalDrive0
行为描述: 可执行文件签名信息
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootinst.exe(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootrest.exe(签名验证: 未通过)
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\showdrive.exe(签名验证: 未通过)
行为描述: 可执行文件MD5
详情信息: C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootinst.exe ---> a841800dbc71eb00bf7b841738c48b92
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\bootrest.exe ---> e1921dea226b244f83ac5f59681d48a2
C:\Documents and Settings\Administrator\Local Settings\Temp\RarSFX0\files\showdrive.exe ---> 23bee4b5b4d117c63d8650080c690d2e
行为描述: 打开互斥体
详情信息: ShimCacheMutex
活动名 类型 android.intent.action.MAIN android.intent.action.VIEW org.openintents.action.VIEW_DIRECTORY android.hardware.usb.action.USB_DEVICE_ATTACHED android.hardware.usb.action.USB_DEVICE_DETACHED android.intent.category.LEANBACK_LAUNCHER android.intent.category.LAUNCHER android.intent.category.DEFAULT android.intent.action.VIEW android.intent.category.DEFAULT android.intent.action.VIEW android.intent.category.DEFAULT android.intent.action.VIEW android.intent.action.SEND android.intent.action.SEND_MULTIPLE android.intent.category.DEFAULT android.intent.action.VIEW android.intent.action.SEND android.intent.action.SEND_MULTIPLE android.intent.category.DEFAULT android.intent.action.VIEW android.intent.category.DEFAULT android.intent.action.VIEW android.intent.category.DEFAULT android.intent.action.VIEW android.intent.category.DEFAULT android.intent.action.VIEW android.intent.category.DEFAULT android.intent.action.VIEW android.intent.action.EDIT android.intent.category.DEFAULT com.estrongs.action.PICK_FILE com.estrongs.action.PICK_DIRECTORY android.intent.action.CREATE_SHORTCUT android.intent.category.DEFAULT android.intent.action.GET_CONTENT android.intent.category.OPENABLE android.intent.category.DEFAULT android.intent.action.RINGTONE_PICKER android.intent.category.DEFAULT android.intent.action.SET_WALLPAPER android.intent.category.DEFAULT android.intent.action.VIEW android.intent.category.BROWSABLE android.intent.category.DEFAULT android.intent.action.VIEW android.intent.category.BROWSABLE android.intent.category.DEFAULT android.intent.action.VIEW android.intent.category.DEFAULT android.intent.action.MAIN android.intent.category.DEFAULT android.hardware.usb.action.USB_DEVICE_ATTACHED android.hardware.usb.action.USB_DEVICE_DETACHED android.intent.category.DEFAULT
函数名称 信息
android/app/NotificationManager;->notify 信息通知栏
ContentResolver;->query 读取联系人、短信等数据库
HttpClient;->execute 请求远程服务器
TelephonyManager;->getDeviceId 搜集用户手机IMEI码、电话号码、系统版本号等信息
java/net/HttpURLConnection;->connect 连接URL
java/net/URL;->openConnection 连接URL
LocationManager;->getLastKnownLocation 获取地址位置
TelephonyManager;->getLine1Number 获取手机号
SmsManager;->sendTextMessage 发送普通短信
getRuntime 获取命令行环境
java/lang/Runtime;->exec 执行字符串命令
WifiManager;->setWifiEnabled 变更WIFI状态
ContentResolver;->delete 删除短信、联系人
java/net/URLConnection;->connect 连接URL
名称 信息$MediaButtonReceiver 应用安装时启动服务 应用卸载时启动服务 屏幕解锁启动服务
名称 信息 百度
名称 信息
