VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load

VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

File information

File Name :wifi.apk (File not down)
File Size :8829 byte
File Type : application/zip
MD5:4209183ba558623ab17a3f0f182048ed
SHA1:e87bb322affed205675862708b6a213a21ad57ac
Scanner results
Scanner results:3%Antivirus software(1/32)found malware!
Behavior analysis report:         Habo file analysis
Time: 2016-05-25 11:14:43 (CST)
Scanner Engine Ver Sig Ver Sig Date Scan result Time
antiy AVL SDK 3.0 1970-01-01 Found nothing 5
asquared 9.0.0.4324 9.0.0.4324 2014-07-03 Found nothing 1
avast 150725-1 4.7.4 2015-07-25 Found nothing 60
avg 2109/8133 10.0.1405 2014-11-26 Found nothing 60
baidu 2.0.1.0 4.1.3.52192 2.0.1.0 Found nothing 4
baidusd 1.0 1.0 2014-04-02 Found nothing 1
bitdefender 7.58469 7.90123 2014-12-25 Found nothing 60
clamav 19861 0.97.5 2014-12-31 Found nothing 60
drweb 5.0.2.3300 5.0.1.1 2014-12-31 Found nothing 60
fortinet 23.345, 23.345 5.1.158 2014-12-08 Found nothing 60
fprot 4.6.2.117 6.5.1.5418 2014-12-31 Found nothing 60
fsecure 2014-04-02-01 9.13 2014-04-02 Found nothing 60
gdata 25.6694 25.6694 2016-05-25 Android.Trojan.FakeInst.AP 8
ikarus 1.06.01 V1.32.31.0 2014-12-08 Found nothing 60
jiangmin 16.0.100 1.0.0.0 2015-07-25 Found nothing 40
kaspersky 5.5.33 5.5.33 2014-04-01 Found nothing 60
kingsoft 2.1 2.1 2013-09-22 Found nothing 5
mcafee 7638 5400.1158 2014-11-30 Found nothing 60
nod32 0920 3.0.21 2014-12-23 Found nothing 60
panda 9.05.01 9.05.01 2015-07-26 Found nothing 4
pcc 11.380.07 9.500-1005 2014-12-31 Found nothing 60
qh360 1.0.1 1.0.1 1.0.1 Found nothing 3
qqphone 1.0.0.0 1.0.0.0 2014-12-09 Found nothing 60
quickheal 14.00 14.00 2015-07-25 Found nothing 2
rising 25.76.04.01 25.76.04.01 2015-07-24 Found nothing 1
sophos 5.08 3.55.0 2014-12-01 Found nothing 60
symantec 20141230.001 1.3.0.24 2014-12-30 Found nothing 60
tachyon 9.9.9 9.9.9 2013-12-27 Found nothing 3
thehacker 6.8.0.5 6.8.0.5 2015-07-23 Found nothing 1
tws 17.47.17308 1.0.2.2108 2014-12-08 Found nothing 13
vba 3.12.26.3 3.12.26.3 2014-12-31 Found nothing 60
virusbuster 15.0.985.0 5.5.2.13 2014-12-05 Found nothing 60
权限列表
许可名称 信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.CHANGE_WIFI_STATE 改变WIFI连接状态
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_COURSE_LOCATION
android.permission.ACCESS_FINE_LOCATION 获取精确的位置(通过GPS)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.SEND_SMS 发送短信
android.permission.RECEIVE_SMS 监控接收短信
android.permission.RECORD_AUDIO 录音(使用AudioRecord)
android.permission.CALL_PHONE 拨打电话
android.permission.READ_CONTACTS 读取联系人信息
android.permission.WRITE_CONTACTS 写入联系人信息
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.CAMERA 访问照相机设备
android.permission.READ_SMS 读取短信
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
文件信息
VirSCANVirSCAN
安全评分 :
基本信息
VirSCANVirSCAN
MD5:4209183ba558623ab17a3f0f182048ed
文件大小:5.58MB
上传时间: 2014-09-22 10:36:30 (CST)
包名:com.metasploit.stage
最低运行环境:Android 2.3.3, 2.3.4
版权:Unknown
关键行为
VirSCANVirSCAN
行为描述: 查询注册表_检测虚拟机相关
详情信息: \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
文件行为
VirSCANVirSCAN
行为描述: 查找文件
详情信息: FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.zh-CN
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.zh-Hans
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.zh
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.CHS
FileName = C:\Documents and Settings\Administrator\Local Settings\%temp%\996E.CH
注册表行为
VirSCANVirSCAN
行为描述: 查询注册表_检测虚拟机相关
详情信息: \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion
其他行为
VirSCANVirSCAN
行为描述: 创建互斥体
详情信息: CTF.LBES.MutexDefaultS-*
CTF.Compart.MutexDefaultS-*
CTF.Asm.MutexDefaultS-*
CTF.Layouts.MutexDefaultS-*
CTF.TMD.MutexDefaultS-*
CTF.TimListCache.FMPDefaultS-*MUTEX.DefaultS-*
MSCTF.Shared.MUTEX.ELH
MSCTF.Shared.MUTEX.AEI
行为描述: 创建事件对象
详情信息: EventName = DINPUTWINMM
EventName = MSCTF.SendReceive.Event.AEI.IC
EventName = MSCTF.SendReceiveConection.Event.AEI.IC
行为描述: 查找指定窗口
详情信息: NtUserFindWindowEx: [Class,Window] = [Shell_TrayWnd,]
NtUserFindWindowEx: [Class,Window] = [CicLoaderWndClass,]
NtUserFindWindowEx: [Class,Window] = [OleMainThreadWndClass,]
行为描述: 窗口信息
详情信息: Pid = 2108, Hwnd=0x90320, Text = 确定, ClassName = Button.
Pid = 2108, Hwnd=0x60362, Text = 您的系统非NT6以上版本,无法使用本激活!, ClassName = Static.
Pid = 2108, Hwnd=0x80324, Text = Oem7, ClassName = #32770.
Pid = 2108, Hwnd=0x10378, Text = 使用我的密钥和证书:, ClassName = TGroupBox.
Pid = 2108, Hwnd=0x1038a, Text = 导入我的证书, ClassName = TButton.
Pid = 2108, Hwnd=0x10388, Text = 浏览文件..., ClassName = TButton.
Pid = 2108, Hwnd=0x10386, Text = 导入我的密钥, ClassName = TButton.
Pid = 2108, Hwnd=0x10376, Text = 卸载, ClassName = TButton.
Pid = 2108, Hwnd=0x10374, Text = 修复引导(可PE下), ClassName = TButton.
Pid = 2108, Hwnd=0xe031e, Text = 引导文件设置:, ClassName = TGroupBox.
Pid = 2108, Hwnd=0x7032a, Text = 引导保护, ClassName = TCheckBox.
Pid = 2108, Hwnd=0x6035e, Text = F, ClassName = TComboBox.
Pid = 2108, Hwnd=0xa030a, Text = U, ClassName = TComboBox.
Pid = 2108, Hwnd=0xa0300, Text = T, ClassName = TComboBox.
Pid = 2108, Hwnd=0x80326, Text = S, ClassName = TComboBox.
行为描述: 枚举窗口
详情信息: N/A
行为描述: 隐藏指定窗口
详情信息: [Window,Class] = [,ComboLBox]
Activities
VirSCANVirSCAN
活动名 类型
.MainActivity android.intent.action.MAIN
.MainActivity android.intent.action.VIEW
.MainActivity android.intent.category.LAUNCHER
.MainActivity android.intent.category.DEFAULT
.MainActivity android.intent.category.BROWSABLE
危险函数
VirSCANVirSCAN
函数名称 信息
java/net/URL;->openConnection 连接URL
启动方式
VirSCANVirSCAN
名称 信息
com.metasploit.stage.MainBroadcastReceiver 开机启动服务
权限列表
VirSCANVirSCAN
许可名称 信息
android.permission.INTERNET 连接网络(2G或3G)
android.permission.ACCESS_WIFI_STATE 读取wifi网络状态
android.permission.CHANGE_WIFI_STATE 改变WIFI连接状态
android.permission.ACCESS_NETWORK_STATE 读取网络状态(2G或3G)
android.permission.ACCESS_COURSE_LOCATION
android.permission.ACCESS_FINE_LOCATION 获取精确的位置(通过GPS)
android.permission.READ_PHONE_STATE 读取电话状态
android.permission.SEND_SMS 发送短信
android.permission.RECEIVE_SMS 监控接收短信
android.permission.RECORD_AUDIO 录音(使用AudioRecord)
android.permission.CALL_PHONE 拨打电话
android.permission.READ_CONTACTS 读取联系人信息
android.permission.WRITE_CONTACTS 写入联系人信息
android.permission.WRITE_SETTINGS 读写系统设置项
android.permission.CAMERA 访问照相机设备
android.permission.READ_SMS 读取短信
android.permission.WRITE_EXTERNAL_STORAGE 写外部存储器(如:SD卡)
android.permission.RECEIVE_BOOT_COMPLETED 接收开机启动广播
文件列表
VirSCANVirSCAN
文件名 校验码
classes.dex 0x2f7bc918
AndroidManifest.xml 0xb9a35aa1
resources.arsc 0x287e42d
META-INF/ 0x0
META-INF/MANIFEST.MF 0x216140b0
META-INF/SIGNFILE.SF 0xf437544a
META-INF/SIGNFILE.RSA 0xacbf01a8
运行截图
VirSCANVirSCAN
VirSCAN