Apkscan
Apkscan
Apkscan
General information
Worker NVISO_API_KALI_01
Permissions
No permissions requested.
Services
No services registered.
Hardcoded URL's
No hardcoded URLs identified in source code.
Random artificial input is provided to the scanned applications during dynamic analysis, in order to mimic a human being using and interacting with the applica
can result in our report showing a different screen than the one you would see when starting the application.
Disk activity
Accessed files
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/StartappMetadata
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/StartappAdInfoMetadata
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/back_.png
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/StartappSplashMetadata
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/shared_prefs_sdk_ad_prefs
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/StartappAdsMetadata
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/forward_dark.png
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/forward_.png
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/StartappCacheMetadata
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/back_dark.png
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/half_star.png
Filename /dev/urandom
Filename /proc/1214/cmdline
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/x_dark.png
Filename /proc/692/cmdline
Filename /data/data/com.virtual.pro.dj.mixer.edm/shared_prefs/RunnerManager.xml
Filename /data/anr/traces.txt
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/StartappBannerMetadata
Filename /data/data/com.virtual.pro.dj.mixer.edm/cache/1521499837408.jar
Filename /proc/462/cmdline
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/browser_icon_dark.png
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/logo.png
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/empty_star.png
Filename /proc/630/cmdline
Filename pipe:[5225]
Filename /proc/511/cmdline
Filename /proc/1133/cmdline
Filename /proc/1301/cmdline
Filename pipe:[5074]
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/filled_star.png
Filename /proc/3/cmdline
Filename /proc/7/cmdline
Filename /proc/781/cmdline
Filename /proc/1080/cmdline
Filename pipe:[5238]
Filename /data/data/com.virtual.pro.dj.mixer.edm/shared_prefs/TruenetJobKey.xml
Filename /proc/45/cmdline
Filename /data/data/com.virtual.pro.dj.mixer.edm/shared_prefs/com.startapp.android.publish.CookiePrefsFile.xml
Filename /proc/29/cmdline
Filename /proc/271/cmdline
Filename /proc/490/cmdline
Filename /data/data/com.virtual.pro.dj.mixer.edm/shared_prefs/com.startapp.android.publish.xml
Filename /proc/11/cmdline
Filename /proc/35/cmdline
Filename /proc/meminfo
Filename /data/data/com.virtual.pro.dj.mixer.edm/shared_prefs/google_ads_flags_meta.xml
Filename /proc/8/cmdline
Filename /data/data/com.virtual.pro.dj.mixer.edm/files/close_button.png
Filename /data/data/com.virtual.pro.dj.mixer.edm/shared_prefs/inappprefads.xml
Filename /proc/4/cmdline
Filename /proc/14/cmdline
Filename /proc/12/cmdline
Filename /proc/24/cmdline
Filename /proc/350/cmdline
Filename /proc/1062/cmdline
Filename /proc/5/cmdline
Filename /proc/30/cmdline
Filename /proc/270/cmdline
Filename /proc/9/cmdline
Filename /data/data/com.virtual.pro.dj.mixer.edm/shared_prefs/_dis_play.xml
Filename /proc/37/cmdline
Filename /proc/1400/cmdline
Filename /proc/1176/cmdline
Filename /proc/1256/cmdline
Filename /proc/1230/cmdline
Filename /data/data/com.virtual.pro.dj.mixer.edm/shared_prefs/_dis_data.xml
Filename /proc/26/cmdline
Filename /proc/39/cmdline
Filename /proc/33/cmdline
Filename /proc/575/cmdline
Filename /proc/41/cmdline
Filename /proc/672/cmdline
Filename /data/data/com.virtual.pro.dj.mixer.edm/cache/1521499837408.tmp
Filename /proc/6/cmdline
Filename /proc/13/cmdline
Filename /proc/1297/cmdline
Filename /proc/40/cmdline
Filename /proc/1284/cmdline
Filename /proc/477/cmdline
Filename /proc/34/cmdline
Filename /proc/1242/cmdline
Filename /proc/1120/cmdline
Filename /proc/2/cmdline
Filename /proc/1299/cmdline
Filename /proc/25/cmdline
Filename /dev/input/event0
Filename /data/data/com.virtual.pro.dj.mixer.edm/cache/1521499837408.dex
Filename /data/data/com.virtual.pro.dj.mixer.edm/shared_prefs/multidex.version.xml
Filename /proc/1/cmdline
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /proc/272/cmdline
Filename /proc/28/cmdline
Filename /proc/802/cmdline
Filename /proc/46/cmdline
Filename /proc/824/cmdline
Filename /proc/42/cmdline
Filename /proc/658/cmdline
Filename /proc/596/cmdline
Filename /proc/734/cmdline
Filename /proc/10/cmdline
Filename /proc/27/cmdline
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Filename /data/data/com.virtual.pro.dj.mixer.edm/shared_prefs/admob.xml
Network activity
Cryptographic activity
Algorithm AES
Key -128, -99, -29, 97, 20, 39, 71, 116, -45, -12, 6, 57, -23, 91, 47, -29
Encryption operations
Decryption operations
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (RAW) a
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Information leakage
Miscellaneous
Started services
2002
General information
Worker NVISO_API_KALI_01
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
Allows an application to receive the ACTION_BOOT_COMPLETED that is broadcast after the system finishe
RECEIVE_BOOT_COMPLETED
booting.
WAKE_LOCK Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimming
Services
Class com.evernote.android.job.v14.PlatformAlarmServiceExact
Class com.evernote.android.job.v21.PlatformJobService
Class com.evernote.android.job.gcm.PlatformGcmService
Class com.evernote.android.job.v14.PlatformAlarmService
Class com.evernote.android.job.JobRescheduleService
Class com.ansca.corona.CoronaService
Hardcoded URL's
http://code.google.com/p/lowlatencyaudio
http://fsf.org/
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
https://maps.googleapis.com/maps/api/js?v=3.9&sensor=false
http://www.gphysics.com
Random artificial input is provided to the scanned applications during dynamic analysis, in order to mimic a human being using and interacting with the applica
can result in our report showing a different screen than the one you would see when starting the application.
Disk activity
Accessed files
Filename /data/data/com.diamond.triple.slots/code_cache/secondary-dexes/com.diamond.triple.slots-1.apk.classes1181854842.zip
Filename /data/data/com.diamond.triple.slots/code_cache/secondary-dexes/com.diamond.triple.slots-1.apk.classes-1499304223.zip
Filename /data/data/com.diamond.triple.slots/code_cache/secondary-dexes/com.diamond.triple.slots-1.apk.classes-1120502424.zip
Filename /proc/45/cmdline
Filename /data/data/com.diamond.triple.slots/code_cache/secondary-dexes/com.diamond.triple.slots-1.apk.classes4.zip
Filename pipe:[4979]
Filename /proc/1235/cmdline
Filename /proc/1144/cmdline
Filename /proc/3/cmdline
Filename /proc/30/cmdline
Filename /data/data/com.diamond.triple.slots/code_cache/secondary-dexes/com.diamond.triple.slots-1.apk.classes2.zip
Filename /proc/28/cmdline
Filename /data/data/com.diamond.triple.slots/code_cache/secondary-dexes/com.diamond.triple.slots-1.apk.classes3.zip
Filename /proc/1323/cmdline
Filename /proc/40/cmdline
Filename /proc/1306/cmdline
Filename /data/anr/traces.txt
Filename /proc/273/cmdline
Filename /proc/272/cmdline
Filename /proc/1131/cmdline
Filename /proc/1308/cmdline
Filename /proc/793/cmdline
Filename /proc/12/cmdline
Filename /proc/33/cmdline
Filename /proc/635/cmdline
Filename /proc/1/cmdline
Filename /proc/13/cmdline
Filename /proc/1262/cmdline
Filename /proc/10/cmdline
Filename /proc/8/cmdline
Filename /proc/1248/cmdline
Filename /proc/37/cmdline
Filename pipe:[4720]
Filename /proc/1219/cmdline
Filename /proc/738/cmdline
Filename /data/data/com.diamond.triple.slots/shared_prefs/Corona.xml
Filename /proc/26/cmdline
Filename /proc/576/cmdline
Filename /proc/1290/cmdline
Filename /proc/478/cmdline
Filename /proc/598/cmdline
Filename /proc/5/cmdline
Filename /proc/9/cmdline
Filename /proc/351/cmdline
Filename /proc/832/cmdline
Filename /proc/35/cmdline
Filename /proc/926/cmdline
Filename /proc/1303/cmdline
Filename /proc/34/cmdline
Filename /proc/47/cmdline
Filename /proc/6/cmdline
Filename /proc/514/cmdline
Filename /proc/24/cmdline
Filename /proc/29/cmdline
Filename /proc/1090/cmdline
Filename /proc/11/cmdline
Filename /data/data/com.android.music/shared_prefs/Music.xml
Filename pipe:[4984]
Filename /data/data/com.diamond.triple.slots/shared_prefs/multidex.version.xml
Filename /proc/41/cmdline
Filename /proc/42/cmdline
Filename /proc/809/cmdline
Filename /proc/14/cmdline
Filename /proc/39/cmdline
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /proc/1040/cmdline
Filename /proc/27/cmdline
Filename /proc/271/cmdline
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Filename /proc/2/cmdline
Filename /proc/497/cmdline
Filename /proc/655/cmdline
Filename /proc/463/cmdline
Filename /proc/7/cmdline
Filename /dev/input/event0
Filename /data/data/com.android.launcher/shared_prefs/com.android.launcher2.prefs.xml
Filename /proc/25/cmdline
Filename /proc/4/cmdline
Filename /proc/1358/cmdline
Filename /proc/695/cmdline
Filename /proc/1175/cmdline
Network activity
Cryptographic activity
Decryption operations
Information leakage
Miscellaneous
Started services
2003
Worker NVISO_API_KALI_01
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
Allows an application to initiate a phone call without going through the Dialer user interface for the us
CALL_PHONE
confirm the call being placed.
READ_HISTORY_BOOKMARKS Allows an application to read (but not write) the user's browsing history and bookmarks.
WAKE_LOCK Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimming
WRITE_CONTACTS Allows an application to write (but not read) the user's contacts data.
Class com.google.android.gms.measurement.AppMeasurementService
Hardcoded URL's
http://schemas.android.com/apk/res-auto
http://schemas.android.com/apk/res/android
Random artificial input is provided to the scanned applications during dynamic analysis, in order to mimic a human being using and interacting with the applica
can result in our report showing a different screen than the one you would see when starting the application.
Disk activity
Accessed files
Filename /data/data/com.fourarc.qr/files/.Fabric/com.crashlytics.sdk.android:answers/session_analytics.tap
Filename /dev/urandom
Filename /data/data/com.fourarc.qr/files/.Fabric/com.crashlytics.sdk.android:answers/session_analytics_to_send/sa_7cee1975-7faa-
Filename /data/data/com.fourarc.qr/shared_prefs/com.crashlytics.sdk.android.crashlytics-core:com.crashlytics.android.core.Crashl
Filename /data/data/com.fourarc.qr/files/.Fabric/com.crashlytics.sdk.android:answers/session_analytics_to_send/sa_7d92c416-7051-
Filename /data/data/com.fourarc.qr/cache/1460683162801.jar
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Filename /proc/meminfo
Filename /data/data/com.fourarc.qr/shared_prefs/com.google.android.gms.measurement.prefs.xml
Filename /proc/1323/cmdline
Filename /proc/1306/cmdline
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /data/data/com.fourarc.qr/files/.Fabric/com.crashlytics.sdk.android:answers/session_analytics.tap.tmp
Filename /data/data/com.android.browser/shared_prefs/com.android.browser_preferences.xml
Filename /data/data/com.fourarc.qr/shared_prefs/com.crashlytics.prefs.xml
Filename /data/data/com.fourarc.qr/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/5CF8E24100CF-0001-051A-7C983D280B3
Filename /proc/1278/cmdline
Filename /data/data/com.fourarc.qr/shared_prefs/TwitterAdvertisingInfoPreferences.xml
Filename /proc/1427/cmdline
Filename /proc/1263/cmdline
Filename /proc/1425/cmdline
Filename /data/data/com.fourarc.qr/shared_prefs/com.crashlytics.sdk.android:answers:settings.xml
Filename /proc/1325/cmdline
Filename /proc/1251/cmdline
Filename /data/data/com.android.music/shared_prefs/Music.xml
Filename /proc/1404/cmdline
Filename /data/data/com.fourarc.qr/cache/1460683162801.tmp
Filename /data/data/com.fourarc.qr/cache/1460683162801.dex
Filename /proc/1317/cmdline
Filename /data/data/com.fourarc.qr/shared_prefs/com.google.android.gms.appid.xml
Filename /dev/input/event0
Network activity
Cryptographic activity
Algorithm AES
Key 4, 103, -30, 65, -64, 8, 86, -111, 39, -2, 110, -18, 84, -7, 44, 1
Encryption operations
Decryption operations
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (RAW) com.google.android.ads.zxxz.m
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (RAW) a
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (RAW) com.google.android.ads.zxxz.g
Information leakage
Miscellaneous
Started services
2004
General information
File name 2004.apk
Worker NVISO_API_KALI_01
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
Allows an application to initiate a phone call without going through the Dialer user interface for the user to co
CALL_PHONE
the call being placed.
Services
No services registered.
Babable PUP.HighConfidence
Tencent a.gray.inventor.a
Hardcoded URL's
http://ai-mediaservice.appspot.com
http://androvote.appspot.com
http://api.yandex.com/translate/
http://appinvgameserver.appspot.com
http://appinvtinywebdb.appspot.com
http://appinvtinywebdb.appspot.com/
http://cloudinary.com/
http://commons.apache.org/logging/tech.html
http://commons.apache.org/logging/troubleshooting.html
http://developer.android.com/guide/appendix/media-formats.html
http://gnu.org/kawa/cached-collections
http://kawa.gnu.org/
http://kawa.gnu.org/unit
http://kawa.gnu.org/unknown-namespace/
http://plus.google.com/
http://qexo.gnu.org/
http://radio11.plathong.net
https://api.projectoxford.ai/emotion/v1.0/recognize
https://api.projectoxford.ai/vision/v1.0/describe
https://appload.ingest
https://auth.firebase.com/
http://schemas.android.com/apk/res/android
https://code.google.com/apis/console/
https://developers.google.com/fusiontables/docs/v2/getting_started
https://docs.google.com/spreadsheet/formResponse?formkey
https://docs.oracle.com/javase/7/docs/api/java/text/SimpleDateFormat.html
https://pagead2.googlesyndication.com/pagead/gen_204?id=gmob-apps
https://play.google.com/store/apps/developer?id=Thia+life
http://stackoverflow.com/questions/26273929/what-proguard-configuration-do-i-need-for-firebase-on-android
https://thunkable-application-firebase.firebaseio.com/
https://translate.yandex.net/api/v1.5/tr.json/translate?key
https://txn.ingest
https://web.facebook.com/92.50pattaya
https://www.cloudstitch.com/
https://www.facebook.com/thaithia
https://www.firebase.com
https://www.firebase.com/docs/android/guide/offline-capabilities.html#section-handling-transactions-offline fo...
https://www.googleapis.com/auth/appstate
https://www.googleapis.com/auth/datastoremobile
https://www.googleapis.com/auth/drive.appdata
https://www.googleapis.com/auth/drive.file
https://www.googleapis.com/auth/fitness.activity.read
https://www.googleapis.com/auth/fitness.activity.write
https://www.googleapis.com/auth/fitness.body.read
https://www.googleapis.com/auth/fitness.body.write
https://www.googleapis.com/auth/fitness.location.read
https://www.googleapis.com/auth/fitness.location.write
https://www.googleapis.com/auth/fitness.nutrition.read
https://www.googleapis.com/auth/fitness.nutrition.write
https://www.googleapis.com/auth/fusiontables
https://www.googleapis.com/auth/games
https://www.googleapis.com/auth/plus.login
https://www.googleapis.com/auth/plus.me
https://www.googleapis.com/fusiontables/v2/tables
https://www.googleapis.com/fusiontables/v2/tables?key
https://www.google.com/voice/b/0
https://www.google.com/voice/b/0/sms/send/
https://www.microsoft.com/cognitive-services/
http://twitter.com/oauth_clients/new
http://www.facebook.com
http://www.gnu.org/software/kawa/
http://www.google.com/fusiontables/v2/query
http://www.twitter.com
http://www.w3.org/1999/xhtml
http://www.w3.org/1999/XSL/Transform
http://www.w3.org/2000/xmlns/
http://www.w3.org/2001/XMLSchema
http://www.w3.org/2001/XMLSchema-instance
http://www.w3.org/2005/xpath-functions
http://www.w3.org/2005/xpath-functions/collation/codepoint
http://www.w3.org/2005/xqt-errors
http://www.w3.org/2005/xquery-local-functions
http://www.w3.org/XML/1998/namespace
Disk activity
Accessed files
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/code_cache/secondary-dexes/com.thunkable.android.thaithia.FM92Pat
Filename /proc/1270/cmdline
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/files/com.crittercism/app_loads_2/1.1559815112461.000000002
Filename /proc/1328/cmdline
Filename /proc/1316/cmdline
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/shared_prefs/com.crittercism.usersettings.xml
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/shared_prefs/com.crittercism.settings.936d0271f7f44f3284830bcf9ff
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/files/com.crittercism/network_statistics/1.1559815112461.00000000
Filename /proc/1309/cmdline
Filename /dev/input/event0
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/files/com.crittercism/breadcrumbs/1.1559815112461.000000010
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/files/com.crittercism/breadcrumbs/1.1559815112461.000000005
Filename /proc/1314/cmdline
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/files/com.crittercism/breadcrumbs/1.1559815112461.000000012
Filename /proc/meminfo
Filename /dev/urandom
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/files/com.crittercism/breadcrumbs/1.1559815112461.000000006
Filename /proc/1227/cmdline
Filename /proc/1254/cmdline
Filename /proc/1380/cmdline
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/files/com.crittercism/breadcrumbs/1.1559815112461.000000001
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/files/com.crittercism/finished_txns/1.1559815112461.000000003
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/files/com.crittercism/breadcrumbs/1.1559815112461.000000009
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/shared_prefs/com.firebase.authentication.credentials.xml
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/files/com.crittercism/breadcrumbs/1.1559815112461.000000011
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/files/com.crittercism/breadcrumbs/1.1559815112461.000000004
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/shared_prefs/com.crittercism.936d0271f7f44f3284830bcf9ffecb1b0055
Filename /proc/1242/cmdline
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /data/data/com.thunkable.android.thaithia.FM92Pattaya/shared_prefs/multidex.version.xml
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Filename /data/data/com.android.music/shared_prefs/Music.xml
Filename /proc/1298/cmdline
Network activity
Cryptographic activity
Encryption operations
Information leakage
Miscellaneous
Started services
2005
General information
File name 2005.apk
Worker NVISO_API_KALI_01
Permissions
ACCESS_COARSE_LOCATION Allows an app to access approximate location derived from network location sources such as cell towers and
ACCESS_FINE_LOCATION Allows an app to access precise location from location sources such as GPS, cell towers, and Wi-Fi.
WAKE_LOCK Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimming
Class com.yandex.metrica.ConfigurationService
Class com.yandex.metrica.MetricaService
Class com.adobe.phonegap.push.PushInstanceIDListenerService
Class com.adobe.phonegap.push.FCMService
Class com.google.android.gms.measurement.AppMeasurementService
Class com.google.android.gms.measurement.AppMeasurementJobService
Class com.google.firebase.iid.FirebaseInstanceIdService
Hardcoded URL's
http://angular-translate.github.io/docs/
http://cordova.apache.org/ns/1.0
http://creativecommons.org/licenses/by/4.0/
http://docs.angularjs.org/api/angular.element
http://docs.angularjs.org/api/ng
http://errors.angularjs.org/1.5.11/
http://fontawesome.com
http://fontawesome.com/license
http://fontawesome.io
http://fontawesome.io/license
http://fontforge.sf.net
http://ionicons.com/
http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewContentsUserReviews?pageNumber=0&sortOrdering=1&type=Pur...
http://jsperf.com/b64tests
http://maps.n
http://momentjs.com/guides/
http://opensource.org/licenses/Apache
https://api-maps.yandex.ru/2.1/
https://api.ok.ru/js/fapi5.js
https://api.vk.com/method/groups.getById
https://api.yclients.com/api/v
https://app-measurement.com/a
https://calendar.google.com/calendar/render
https://certificate.mobile.yandex.net/api/v1/pins
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
https://connect.facebook.net/en_US/fbevents.js
https://docs.angularjs.org/api/ngSanitize
http://server/myapp/index.html
https://fonts.gstatic.com/s/materialicons/v7/2fcrYFNaTjcS6g4U3t-Y5ZjZjT5FdEJ140U2DJYC3mY.woff
https://gist.github.com/triceam/4658021
https://github.com/angular/material
https://github.com/crypto-browserify/crypto-browserify
https://github.com/driftyco/ionicons
https://github.com/es-shims
https://github.com/google/material-design-icons
https://github.com/indutny/elliptic
https://github.com/indutny/elliptic/issues
https://github.com/puleos/object-hash/issues/26
https://github.com/zloirock/core-js/issues/86#issuecomment
https://goo.gl/NAOOOI
https://images.yclients.com
https://issues.apache.org/jira/browse/CB
https://maps.googleapis.com/maps/api/js?callback=yGoogleMapsInitCallback&key=AIzaSyDXdiemDvD0Id0YIR6EJhr-ZOgcY...
https://maps.googleapis.com/maps/api/staticmap
https://mc.yandex.ru/metrika/tag.js
https://mc.yandex.ru/watch/
https://ok.ru/appinstall/1251088128
https://packages.yclients.cloud/repository/ycl-npm/elliptic/
https://pagead2.googlesyndication.com/pagead/gen_204?id=gmob-apps
https://people.mozilla.org/
https://plus.google.com/
https://ssl.gstatic.com/accessibility/javascript/android/
https://startup.mobile.yandex.net/
https://static-maps.yandex.ru/1.x/
https://tech.yandex.com/appmetrica/doc/mobile-sdk-dg/concepts/mobilesdk-about-docpage/
https://tech.yandex.com/metrica-mobile-sdk/doc/mobile-sdk-dg/concepts/android-initialize-docpage/
https://twitter.com/benjsperry
https://twitter.com/ionicframework
https://vk.com/js/api/openapi.js
https://vk.com/rtrg?p
https://www.facebook.com/tr?id
https://www.googleapis.com/auth/appstate
https://www.googleapis.com/auth/datastoremobile
https://www.googleapis.com/auth/drive.appdata
https://www.googleapis.com/auth/drive.file
https://www.googleapis.com/auth/fitness.activity.read
https://www.googleapis.com/auth/fitness.activity.write
https://www.googleapis.com/auth/fitness.body.read
https://www.googleapis.com/auth/fitness.body.write
https://www.googleapis.com/auth/fitness.location.read
https://www.googleapis.com/auth/fitness.location.write
https://www.googleapis.com/auth/fitness.nutrition.read
https://www.googleapis.com/auth/fitness.nutrition.write
https://www.googleapis.com/auth/games
https://www.googleapis.com/auth/plus.login
https://www.googleapis.com/auth/plus.me
https://www.google.com
https://www.google.com/chrome/
https://www.google.com/maps/search/
https://www.googletagmanager.com/gtag/js?id
https://www.microsoft.com/software-download/windows
https://www.yclients.com/
https://www.yclients.com/info/pricing
https://yandex.com/legal/appmetrica_sdk_agreement/
https://yandex.ru/legal
https://yandex.ru/maps/
https://yclients-client-apps.firebaseio.com
https://yclients.com
https://yclients.com/
https://yclients.com/cabinet/info/
http://unicode.org/reports/tr35/tr35-4.html
http://www.apache.org/licenses/LICENSE
http://www.apple.com/osx/
http://www.mozilla.org/firefox/new/
http://www.opera.com/
http://www.w3.org/1999/xlink
http://www.w3.org/2000/svg
http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd
http://www.w3.org/html/wg/drafts/html/master/browsers.html#named-access-on-the-window-object
http://www.w3.org/ns/widgets
http://yclients.com
http://yclients.com/info/oferta
http://yclients.com/info/rules
This most likely means that your application did not run correctly on our test device.
Our test devices run Android 4.1 Jelly Bean (API level 16), and currently do not support hardware OpenGL acceleration.
Since the application did not run correctly, the results in the sections below could be incomplete!
Disk activity
Accessed files
Network activity
Cryptographic activity
Encryption operations
Decryption operations
Information leakage
Miscellaneous
Started services
2007
NVISO ApkScan malware analysis report
June 12, 2019
General information
Worker NVISO_API_KALI_01
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
Allows an application to receive the ACTION_BOOT_COMPLETED that is broadcast after the system finishe
RECEIVE_BOOT_COMPLETED
booting.
WAKE_LOCK Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimming
Services
Class net.hundredapps.kawaiicalc.model.logic.service.ReSetService
Class net.hundredapps.kawaiicalc.model.logic.service.GetVersionService
Class net.hundredapps.kawaiicalc.model.logic.service.jobScheduler.EasyCalcLaunchNotificationJobScheduler
Class net.hundredapps.kawaiicalc.model.logic.service.NotificationIfNotDisplayedService
Virus Total scan results
Hardcoded URL's
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
This most likely means that your application did not run correctly on our test device.
Our test devices run Android 4.1 Jelly Bean (API level 16), and currently do not support hardware OpenGL acceleration.
Since the application did not run correctly, the results in the sections below could be incomplete!
Disk activity
Accessed files
Network activity
Cryptographic activity
Used encryption keys
Encryption operations
Decryption operations
Information leakage
Miscellaneous
Started services
2008
Worker NVISO_API_KALI_01
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
Services
Class com.hayangkawin.dxsimulationfor_doublew.util.MyFirebaseMessagingService
Class com.hayangkawin.dxsimulationfor_doublew.util.MyFirebaseInstanceIDService
Class com.google.android.gms.analytics.AnalyticsService
Class com.google.android.gms.analytics.AnalyticsJobService
Class com.google.android.gms.measurement.AppMeasurementService
Class com.google.android.gms.measurement.AppMeasurementJobService
Class com.google.firebase.messaging.FirebaseMessagingService
Class com.google.firebase.iid.FirebaseInstanceIdService
Hardcoded URL's
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
Random artificial input is provided to the scanned applications during dynamic analysis, in order to mimic a human being using and interacting with the applica
can result in our report showing a different screen than the one you would see when starting the application.
Disk activity
Accessed files
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /data/data/com.hayangkawin.dxsimulationfor_doublew/shared_prefs/com.google.android.gms.measurement.prefs.xml
Filename /proc/meminfo
Filename /dev/urandom
Filename /data/data/com.hayangkawin.dxsimulationfor_doublew/shared_prefs/google_ads_flags_meta.xml
Filename /data/data/com.hayangkawin.dxsimulationfor_doublew/shared_prefs/com.google.android.gms.analytics.prefs.xml
Filename /data/data/com.hayangkawin.dxsimulationfor_doublew/cache/1505450608132.jar
Filename /proc/1395/cmdline
Filename /proc/1256/cmdline
Filename /data/data/com.android.music/shared_prefs/Music.xml
Filename /data/data/com.hayangkawin.dxsimulationfor_doublew/cache/1505450608132.tmp
Filename /proc/1242/cmdline
Filename /proc/1284/cmdline
Filename /data/data/com.hayangkawin.dxsimulationfor_doublew/files/gaClientId
Filename /dev/input/event0
Filename /proc/1299/cmdline
Filename /proc/1297/cmdline
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Filename /data/data/com.hayangkawin.dxsimulationfor_doublew/shared_prefs/admob.xml
Filename /data/data/com.hayangkawin.dxsimulationfor_doublew/cache/1505450608132.dex
Filename /proc/1301/cmdline
Network activity
Cryptographic activity
Algorithm AES
Key 120, -128, -66, -43, 10, 43, 37, 47, -49, 83, 16, 72, 27, -30, -80, 33
Encryption operations
Decryption operations
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (RAW) a
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (RAW) com.google.android.ads.zxxz.f
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (RAW) com.google.android.ads.zxxz.p
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Information leakage
Miscellaneous
Started services
2013
NVISO ApkScan malware analysis report
June 12, 2019
General information
Worker NVISO_API_KALI_01
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
WAKE_LOCK Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimm
Services
Class com.start.aplication.template.MyFirebaseMessagingService
Class com.google.firebase.messaging.FirebaseMessagingService
Class com.google.android.gms.measurement.AppMeasurementService
Class com.google.firebase.iid.FirebaseInstanceIdService
Class com.kpn.service.KPNFirebaseInstanceIDService
Hardcoded URL's
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
Random artificial input is provided to the scanned applications during dynamic analysis, in order to mimic a human being using and interacting with the applica
can result in our report showing a different screen than the one you would see when starting the application.
Disk activity
Accessed files
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/code_cache/secondary-dexes/tmp-com.VAD.Makeup.Beauty.Photo.Effects-1.ap
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/shared_prefs/com.applovin.sdk.1.xml
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/files/UnityAdsWebApp.html
Filename /proc/14/cmdline
Filename /proc/46/cmdline
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/shared_prefs/com.google.android.gms.measurement.prefs.xml
Filename /proc/1287/cmdline
Filename /proc/1097/cmdline
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/code_cache/secondary-dexes/com.VAD.Makeup.Beauty.Photo.Effects-1.apk.cla
Filename /proc/10/cmdline
Filename pipe:[5370]
Filename /proc/45/cmdline
Filename /proc/1228/cmdline
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/files/UnityAdsStorage-private-data.json
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/shared_prefs/com.applovin.sdk.preferences.aepd9tdSVxUyUmIcgHM19nAb4-Fo
Filename /proc/1289/cmdline
Filename /proc/34/cmdline
Filename /proc/3/cmdline
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/files/UnityAdsTest.txt
Filename /proc/273/cmdline
Filename /proc/28/cmdline
Filename /proc/35/cmdline
Filename /proc/352/cmdline
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/shared_prefs/admob.xml
Filename /proc/1271/cmdline
Filename /dev/urandom
Filename /proc/832/cmdline
Filename /proc/41/cmdline
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/shared_prefs/FBAdPrefs.xml
Filename pipe:[5177]
Filename /proc/579/cmdline
Filename pipe:[5406]
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/cache/1521499837408.jar
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/files/UnityAdsStorage-public-data.json
Filename /proc/272/cmdline
Filename /proc/1406/cmdline
Filename /proc/939/cmdline
Filename /proc/26/cmdline
Filename /proc/1028/cmdline
Filename /proc/42/cmdline
Filename /proc/1082/cmdline
Filename /proc/6/cmdline
Filename /proc/1146/cmdline
Filename /proc/463/cmdline
Filename /proc/1282/cmdline
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/shared_prefs/com.VAD.Makeup.Beauty.Photo.Effects_preferences.xml
Filename /proc/5/cmdline
Filename /proc/4/cmdline
Filename /proc/29/cmdline
Filename /proc/663/cmdline
Filename /proc/12/cmdline
Filename /proc/11/cmdline
Filename /proc/635/cmdline
Filename /proc/735/cmdline
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/shared_prefs/com.cms.kovacnica.xml
Filename /proc/39/cmdline
Filename /proc/24/cmdline
Filename /proc/2/cmdline
Filename /data/anr/traces.txt
Filename /proc/7/cmdline
Filename /proc/490/cmdline
Filename pipe:[5815]
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/shared_prefs/multidex.version.xml
Filename pipe:[5806]
Filename /proc/783/cmdline
Filename /proc/9/cmdline
Filename /proc/8/cmdline
Filename /proc/1351/cmdline
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Filename /proc/1243/cmdline
Filename /dev/input/event0
Filename /proc/586/cmdline
Filename /proc/33/cmdline
Filename /proc/478/cmdline
Filename /proc/40/cmdline
Filename /proc/1296/cmdline
Filename /proc/25/cmdline
Filename /proc/1/cmdline
Filename /proc/513/cmdline
Filename /data/data/com.android.musicfx/shared_prefs/musicfx.xml
Filename /proc/1313/cmdline
Filename /proc/27/cmdline
Filename /data/tombstones/tombstone_01
Filename /proc/1014/cmdline
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/shared_prefs/SDKIDFA.xml
Filename /proc/meminfo
Filename /proc/13/cmdline
Filename /proc/37/cmdline
Filename /proc/30/cmdline
Filename /proc/1430/cmdline
Filename /proc/274/cmdline
Filename /proc/1133/cmdline
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/cache/1521499837408.tmp
Filename /data/data/com.VAD.Makeup.Beauty.Photo.Effects/cache/1521499837408.dex
Filename /proc/1187/cmdline
Filename /data/tombstones/tombstone_02
Network activity
Opened network
connections
Cryptographic activity
Algorithm AES
Key -128, -99, -29, 97, 20, 39, 71, 116, -45, -12, 6, 57, -23, 91, 47, -29
Encryption operations
Decryption operations
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (RAW) a
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (ASCII)
Information leakage
Miscellaneous
Started services
2014
Worker NVISO_API_KALI_01
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
Services
No services registered.
Hardcoded URL's
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
This most likely means that your application did not run correctly on our test device.
Our test devices run Android 4.1 Jelly Bean (API level 16), and currently do not support hardware OpenGL acceleration.
Since the application did not run correctly, the results in the sections below could be incomplete!
Disk activity
Accessed files
Network activity
Cryptographic activity
Encryption operations
Decryption operations
Information leakage
Miscellaneous
Started services
2017
General information
Worker NVISO_API_KALI_01
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
Services
Class com.appsforall.bridew.ServiceManager
Class com.pandora.PandoraService
Class com.evernote.android.job.gcm.PlatformGcmService
Class com.evernote.android.job.v21.PlatformJobService
Class com.evernote.android.job.v14.PlatformAlarmService
Class com.evernote.android.job.JobRescheduleService
Hardcoded URL's
http://schemas.android.com/aapt
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
Disk activity
Accessed files
Filename /data/data/com.appsforall.bridew/cache/picasso-cache/e1301acda95139bb2a4d3de8477080a2.1.tmp
Filename /data/data/com.appsforall.bridew/cache/picasso-cache/0a92998d1c2e13ff7cbc58003004ef68.1.tmp
Filename /data/data/com.appsforall.bridew/shared_prefs/com.appsforall.bridew_preferences.xml
Filename /data/data/com.appsforall.bridew/cache/picasso-cache/journal.tmp
Filename /proc/meminfo
Filename /data/data/com.appsforall.bridew/cache/picasso-cache/journal
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /data/data/com.appsforall.bridew/cache/picasso-cache/0a92998d1c2e13ff7cbc58003004ef68.0.tmp
Filename /proc/1314/cmdline
Filename /proc/1309/cmdline
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Filename /data/data/com.android.music/shared_prefs/Music.xml
Filename /proc/1316/cmdline
Filename /proc/1298/cmdline
Filename /data/data/com.appsforall.bridew/cache/picasso-cache/e1301acda95139bb2a4d3de8477080a2.0.tmp
Filename /dev/input/event0
Filename /proc/1368/cmdline
Network activity
Opened network
connections
Cryptographic activity
Algorithm AES
16, 58, -35, 121, -41, -99, -64, 103, -35, 122, -9, 95, 122, 87, -99, 125, -21, 31, 108, 58, -35, 121, -41, -99, -64, 103, -61, -83, -41, -9
Key
-36
Encryption operations
Decryption operations
Information leakage
Miscellaneous
Started services
2022
General information
Worker NVISO_API_KALI_01
Static malware analysis
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
Services
No services registered.
Hardcoded URL's
http://hostname/
http://plus.google.com/
https://accounts.google.com
https://app-measurement.com/a
http://schema.org/ActivateAction
http://schema.org/ActiveActionStatus
http://schema.org/AddAction
http://schema.org/BookmarkAction
http://schema.org/CommunicateAction
http://schema.org/CompletedActionStatus
http://schema.org/FailedActionStatus
http://schema.org/FilmAction
http://schema.org/LikeAction
http://schema.org/ListenAction
http://schema.org/PhotographAction
http://schema.org/ReserveAction
http://schema.org/SearchAction
http://schema.org/ViewAction
http://schema.org/WantAction
http://schema.org/WatchAction
http://schemas.android.com/apk/lib/com.google.android.gms.plus
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
https://csi.gstatic.com/csi
https://googleads.g.doubleclick.net/mads/static/mad/sdk/native/mraid/v2/mraid_app_banner.js
https://googleads.g.doubleclick.net/mads/static/mad/sdk/native/mraid/v2/mraid_app_expanded_banner.js
https://googleads.g.doubleclick.net/mads/static/mad/sdk/native/mraid/v2/mraid_app_interstitial.js
https://googleads.g.doubleclick.net/mads/static/mad/sdk/native/sdk-core-v40.html
https://login.live.com
https://login.yahoo.com
https://ssl.google-analytics.com
https://twitter.com
https://www.facebook.com
https://www.googleapis.com/auth/appstate
https://www.googleapis.com/auth/datastoremobile
https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/drive.appdata
https://www.googleapis.com/auth/drive.apps
https://www.googleapis.com/auth/drive.file
https://www.googleapis.com/auth/fitness.activity.read
https://www.googleapis.com/auth/fitness.activity.write
https://www.googleapis.com/auth/fitness.body.read
https://www.googleapis.com/auth/fitness.body.write
https://www.googleapis.com/auth/fitness.location.read
https://www.googleapis.com/auth/fitness.location.write
https://www.googleapis.com/auth/fitness.nutrition.read
https://www.googleapis.com/auth/fitness.nutrition.write
https://www.googleapis.com/auth/games
https://www.googleapis.com/auth/games.firstparty
https://www.googleapis.com/auth/plus.login
https://www.googleapis.com/auth/plus.me
https://www.googleapis.com/auth/plus.moments.write
https://www.googletagmanager.com
https://www.linkedin.com
https://www.paypal.com
http://www.google-analytics.com
http://www.google.com
This most likely means that your application did not run correctly on our test device.
Our test devices run Android 4.1 Jelly Bean (API level 16), and currently do not support hardware OpenGL acceleration.
Since the application did not run correctly, the results in the sections below could be incomplete!
Disk activity
Accessed files
Network activity
Cryptographic activity
Encryption operations
Decryption operations
Information leakage
Miscellaneous
Started services
2023
General information
Worker NVISO_API_KALI_01
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
WAKE_LOCK Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimming
Services
Class com.sabilistudio.brunomarsnewsongs.AudioService
Class com.sabilistudio.brunomarsnewsongs.Audio245379_PlaylistManager
Class com.sabilistudio.brunomarsnewsongs.SetRingtoneService
Hardcoded URL's
http://schemas.android.com/aapt
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
Disk activity
Accessed files
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/image_manager_disk_cache/d1aef840371ecdb969c286eda7c66d55c2602f3
Filename /proc/1299/cmdline
Filename /data/data/com.sabilistudio.brunomarsnewsongs/shared_prefs/multidex.version.xml
Filename /proc/meminfo
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/image_manager_disk_cache/68884a175f1c63ff3fff24a2a608400fae65706bb
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/image_manager_disk_cache/8cdf8c8da1292296042f98b1280b15b55609c0
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/1521499837408.dex
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/image_manager_disk_cache/journal
Filename /dev/input/event0
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/image_manager_disk_cache/a6e4376bd62947c152431e44ca35ff3e0ad5f7c
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/image_manager_disk_cache/aaf8f6b421d7a95008a81b31ad4c50fe971df55
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/image_manager_disk_cache/fabdf7efe32c74a4b24bb4fcd6f8698e5e5245c3
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/1521499837408.jar
Filename /dev/urandom
Filename /data/data/com.sabilistudio.brunomarsnewsongs/shared_prefs/Audio245379.xml
Filename /data/data/com.sabilistudio.brunomarsnewsongs/shared_prefs/admob.xml
Filename /proc/1474/cmdline
Filename /proc/1316/cmdline
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/1521499837408.tmp
Filename /data/data/com.android.music/shared_prefs/Music.xml
Filename /data/data/com.sabilistudio.brunomarsnewsongs/shared_prefs/google_ads_flags_meta.xml
Filename /proc/1407/cmdline
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/image_manager_disk_cache/95374a526d6289e9999e5dea65909c95ac3fed
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Filename /data/data/com.sabilistudio.brunomarsnewsongs/shared_prefs/com.sabilistudio.brunomarsnewsongs_preferences.xml
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/image_manager_disk_cache/d34afcaf6fc7f2401b8d1693b0b5c47fc9c612f03
Filename /proc/1243/cmdline
Filename /data/data/com.sabilistudio.brunomarsnewsongs/cache/image_manager_disk_cache/journal.tmp
Filename /proc/1270/cmdline
Filename /proc/1313/cmdline
Filename /proc/1310/cmdline
Filename /proc/1256/cmdline
Network activity
Cryptographic activity
Algorithm AES
Key -128, -99, -29, 97, 20, 39, 71, 116, -45, -12, 6, 57, -23, 91, 47, -29
Encryption operations
Decryption operations
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (RAW) a
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Information leakage
Miscellaneous
Started services
2024
General information
Worker NVISO_API_KALI_01
Static malware analysis
Permissions
ACCESS_FINE_LOCATION Allows an app to access precise location from location sources such as GPS, cell towers, and Wi-Fi.
Allows an application to receive the ACTION_BOOT_COMPLETED that is broadcast after the system finishe
RECEIVE_BOOT_COMPLETED
booting.
WAKE_LOCK Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimming
Services
Class com.google.android.gms.analytics.AnalyticsService
Class com.google.android.gms.analytics.CampaignTrackingService
Class com.google.android.gms.analytics.AnalyticsJobService
Class com.onesignal.GcmIntentService
Class com.onesignal.GcmIntentJobService
Class com.onesignal.RestoreJobService
Class com.onesignal.RestoreKickoffJobService
Class com.onesignal.SyncService
Class com.onesignal.SyncJobService
Class com.onesignal.NotificationRestoreService
Hardcoded URL's
http://schemas.android.com/aapt
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
http://schemas.android.com/tools
Disk activity
Accessed files
Filename /data/data/com.doogle.taiwannews/cache/1521499837408.jar
Filename /data/data/com.android.music/shared_prefs/Music.xml
Filename /proc/meminfo
Filename /data/data/com.doogle.taiwannews/shared_prefs/OneSignal.xml
Filename /proc/1313/cmdline
Filename /proc/1285/cmdline
Filename /data/data/com.doogle.taiwannews/shared_prefs/com.google.android.gms.analytics.prefs.xml
Filename /proc/1326/cmdline
Filename /data/data/com.doogle.taiwannews/files/gaClientId
Filename /proc/1370/cmdline
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /dev/urandom
Filename /proc/1331/cmdline
Filename /data/data/com.doogle.taiwannews/shared_prefs/admob.xml
Filename /dev/input/event0
Filename /data/data/com.doogle.taiwannews/shared_prefs/google_ads_flags_meta.xml
Filename /data/data/com.doogle.taiwannews/shared_prefs/GTPlayerPurchases.xml
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Filename /data/data/com.doogle.taiwannews/shared_prefs/apprate_prefs.xml
Filename /proc/1329/cmdline
Filename /proc/1415/cmdline
Filename /data/data/com.doogle.taiwannews/cache/1521499837408.dex
Filename /data/data/com.doogle.taiwannews/cache/1521499837408.tmp
Network activity
Cryptographic activity
Algorithm AES
Key -128, -99, -29, 97, 20, 39, 71, 116, -45, -12, 6, 57, -23, 91, 47, -29
Encryption operations
Decryption operations
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (RAW) a
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Information leakage
Miscellaneous
Started services
2025
Worker NVISO_API_KALI_01
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
GET_TASKS Allows an application to get information about the currently or recently running tasks.
SYSTEM_ALERT_WINDOW Allows an application to open windows using the type TYPE_SYSTEM_ALERT, shown on top of all other applic
Services
No services registered.
Hardcoded URL's
http://plus.google.com/
https://accounts.google.com
https://app-measurement.com/a
http://schema.org/ActivateAction
http://schema.org/ActiveActionStatus
http://schema.org/AddAction
http://schema.org/BookmarkAction
http://schema.org/CommunicateAction
http://schema.org/CompletedActionStatus
http://schema.org/FailedActionStatus
http://schema.org/FilmAction
http://schema.org/LikeAction
http://schema.org/ListenAction
http://schema.org/PhotographAction
http://schema.org/ReserveAction
http://schema.org/SearchAction
http://schema.org/ViewAction
http://schema.org/WantAction
http://schema.org/WatchAction
http://schemas.android.com/apk/lib/com.google.android.gms.plus
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
http://schemas.android.com/apk/res/com.infomenarikapps.lagufiveminutes
https://csi.gstatic.com/csi
https://googleads.g.doubleclick.net/mads/static/mad/sdk/native/mraid/v2/mraid_app_banner.js
https://googleads.g.doubleclick.net/mads/static/mad/sdk/native/mraid/v2/mraid_app_expanded_banner.js
https://googleads.g.doubleclick.net/mads/static/mad/sdk/native/mraid/v2/mraid_app_interstitial.js
https://googleads.g.doubleclick.net/mads/static/mad/sdk/native/sdk-core-v40.html
https://login.live.com
https://login.yahoo.com
https://play.google.com/store/apps/details?id=com.infomenarikapps.lagudmasiv
https://play.google.com/store/apps/details?id=com.infomenarikapps.lagufatin
https://play.google.com/store/apps/details?id=com.infomenarikapps.lagugeisha
https://play.google.com/store/apps/details?id=com.infomenarikapps.lagujrocks
https://ssl.google-analytics.com
https://twitter.com
https://www.facebook.com
https://www.googleapis.com/auth/appstate
https://www.googleapis.com/auth/datastoremobile
https://www.googleapis.com/auth/drive
https://www.googleapis.com/auth/drive.appdata
https://www.googleapis.com/auth/drive.apps
https://www.googleapis.com/auth/drive.file
https://www.googleapis.com/auth/fitness.activity.read
https://www.googleapis.com/auth/fitness.activity.write
https://www.googleapis.com/auth/fitness.body.read
https://www.googleapis.com/auth/fitness.body.write
https://www.googleapis.com/auth/fitness.location.read
https://www.googleapis.com/auth/fitness.location.write
https://www.googleapis.com/auth/fitness.nutrition.read
https://www.googleapis.com/auth/fitness.nutrition.write
https://www.googleapis.com/auth/games
https://www.googleapis.com/auth/games.firstparty
https://www.googleapis.com/auth/plus.login
https://www.googleapis.com/auth/plus.me
https://www.googleapis.com/auth/plus.moments.write
https://www.googletagmanager.com
https://www.linkedin.com
https://www.paypal.com
http://www.google-analytics.com
http://www.google.com
http://www.w3.org/1999/xhtml
http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd
Disk activity
Accessed files
Filename /proc/meminfo
Filename /proc/1296/cmdline
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /dev/urandom
Filename /data/data/com.infomenarikapps.lagufiveminutes/cache/ads1482185665.jar
Filename /data/data/com.infomenarikapps.lagufiveminutes/shared_prefs/admob.xml
Filename /dev/input/event0
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Filename /proc/1298/cmdline
Filename /data/data/com.android.music/shared_prefs/Music.xml
Filename /proc/1253/cmdline
Filename /proc/1239/cmdline
Filename /data/data/com.infomenarikapps.lagufiveminutes/shared_prefs/com.vappsvn.chioianhyeuem.sharedpreference.xml
Filename /proc/1226/cmdline
Filename /proc/1356/cmdline
Filename /proc/1294/cmdline
Filename /proc/1281/cmdline
Network activity
Cryptographic activity
Algorithm AES
Key -120, 70, 86, 73, -27, -67, -69, -79, 99, -127, 66, -34, 104, -117, 65, 84
Encryption operations
Decryption operations
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (RAW) a
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Algorithm AES/CBC/PKCS5Padding
Data (ASCII)
Information leakage
Miscellaneous
Started services
2026
General information
Worker NVISO_API_KALI_01
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
Services
No services registered.
Hardcoded URL's
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
This most likely means that your application did not run correctly on our test device.
Our test devices run Android 4.1 Jelly Bean (API level 16), and currently do not support hardware OpenGL acceleration.
Since the application did not run correctly, the results in the sections below could be incomplete!
Disk activity
Accessed files
Cryptographic activity
Encryption operations
Decryption operations
Information leakage
Miscellaneous
Started services
No services were started.
2027
General information
Worker NVISO_API_KALI_01
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
CALL_PHONE Allows an application to initiate a phone call without going through the Dialer user interface for the user
MOUNT_UNMOUNT_FILESYSTEMS Allows mounting and unmounting file systems for removable storage.
RECEIVE_BOOT_COMPLETED Allows an application to receive the ACTION_BOOT_COMPLETED that is broadcast after the system fi
WAKE_LOCK Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimming
Services
Class com.tencent.android.tpush.service.XGPushService
Class com.tencent.android.tpush.rpc.XGRemoteService
Class com.jingdong.jdmanew.service.JDMAService
SymantecMobileInsight AppRisk:Generisk
Hardcoded URL's
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
http://wqs.jd.com/my/agreement/ebay_agree.shtml
http://wqs.jd.com/my/agreement/enter_agree.shtml
http://wqs.jd.com/my/agreement/global_agree.shtml
Dynamic malware anal
Random artificial input is provided to the scanned applications during dynamic analysis, in order to mimic a human being using and interacting with the ap
Disk activity
Accessed files
Filename pipe:[3724]
Filename /data/data/com.jd.wxsq.app/code_cache/secondary-dexes/com.jd.wxsq.app-1.apk.classes960624856.zip
Filename /proc/1344/cmdline
Filename /data/data/com.jd.wxsq.app/shared_prefs/umeng_general_config.xml
Filename /proc/1295/cmdline
Filename /data/data/com.jd.wxsq.app/files/nuwa/hack.apk
Filename /data/data/com.jd.wxsq.app/shared_prefs/share_data.xml
Filename /data/data/com.jd.wxsq.app/code_cache/secondary-dexes/com.jd.wxsq.app-1.apk.classes2.zip
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Filename /proc/meminfo
Filename /data/data/com.android.music/shared_prefs/Music.xml
Filename /proc/1410/cmdline
Filename /data/data/com.android.launcher/shared_prefs/com.android.launcher2.prefs.xml
Filename /proc/1342/cmdline
Filename pipe:[3719]
Filename /data/data/com.jd.wxsq.app/shared_prefs/multidex.version.xml
Filename pipe:[3670]
Filename /data/data/com.jd.wxsq.app/shared_prefs/com.jd.wxsq.app_preferences.xml
Filename /data/data/com.jd.wxsq.app/shared_prefs/bugly_data.xml
Filename /proc/1337/cmdline
Filename /proc/1281/cmdline
Filename /proc/cpuinfo
Filename /proc/1324/cmdline
Filename /dev/input/event0
Filename /proc/1269/cmdline
Filename pipe:[3671]
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /dev/urandom
Network activity
Cryptographic activity
Algorithm DES
Algorithm DES
Encryption operations
No cryptographic activity detected.
Decryption operations
Information leakage
Destination 203.205.146.45:80
Data
POST /rqd/sync HTTP/1.1 wup_version: 3.0 pver: 4.0.95 bid: com.jd.wxsq.app pid: 900002438 A37:
(ASCII)
Data
504f5354202f7271642f73796e6320485454502f312e310d0a7775705f76657273696f6e3a20332e300d0a707665723a20342e302e
(RAW)
Operation send
Destination 203.205.146.45:80
Data
POST /rqd/sync HTTP/1.1 wup_version: 3.0 pver: 4.0.95 bid: com.jd.wxsq.app pid: 900002438 A37:
(ASCII)
Data
504f5354202f7271642f73796e6320485454502f312e310d0a7775705f76657273696f6e3a20332e300d0a707665723a20342e302e
(RAW)
Operation send
Path /data/data/com.jd.wxsq.app/shared_prefs/com.jd.wxsq.app_preferen
Operation write
Tag TAINT_IMEI
Data (ASCII) <?xml version='1.0' encoding='utf-8' standalone='yes' ?> <map> <long name="mta.qq.com.checktime" val
Path /data/data/com.jd.wxsq.app/shared_prefs/com.jd.wxsq.app_preferen
Operation write
Tag TAINT_IMEI
Data (ASCII) <?xml version='1.0' encoding='utf-8' standalone='yes' ?> <map> <string name="__MTA_DEVICE_INFO__">xj
Operation write
Tag TAINT_IMEI
Data (ASCII) <?xml version='1.0' encoding='utf-8' standalone='yes' ?> <map> <int name="MTA_EVENT_INDEX" value="10
Miscellaneous
Started services
2029
General information
Worker NVISO_API_KALI_01
Static malware analysis
Permissions
ACCESS_NETWORK_STATE Allows applications to access information about networks
WAKE_LOCK Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimming
Services
Class com.google.android.gms.analytics.CampaignTrackingService
Class com.clevertap.android.sdk.FcmTokenListenerService
Class com.traderumors.push.TradeRumorFireBaseReceiver
Class com.google.firebase.messaging.FirebaseMessagingService
Class com.google.android.gms.measurement.AppMeasurementService
Class com.google.firebase.iid.FirebaseInstanceIdService
Hardcoded URL's
http://schemas.android.com/apk/res-auto
http://schemas.android.com/apk/res/android
https://www.facebook.com
Disk activity
Accessed files
Filename /data/data/com.google.android.backup/shared_prefs/BackupTransport.backupScheduler.xml
Filename /data/data/com.google.android.inputmethod.latin.dictionarypack/shared_prefs/metadata_download_id.xml
Filename /proc/1293/stat
Filename /proc/stat
Filename /data/data/com.traderumors/shared_prefs/branch_referral_shared_pref.xml
Filename /proc/45/cmdline
Filename /proc/1554/cmdline
Filename /data/backup/pending/journal2002843486.tmp
Filename /proc/25/cmdline
Filename /data/data/com.android.launcher/files/launcher.preferences
Filename /data/data/com.traderumors/shared_prefs/com.google.android.gms.measurement.prefs.xml
Filename /proc/1708/cmdline
Filename /proc/1967/cmdline
Filename /proc/8/cmdline
Filename /data/data/com.traderumors/shared_prefs/com.newrelic.android.agent.v1_com.traderumors.xml
Filename /data/data/com.google.android.apps.maps/files/DATA_Preferences
Filename /proc/meminfo
Filename /proc/26/cmdline
Filename /data/data/com.traderumors/shared_prefs/TwitterAdvertisingInfoPreferences.xml
Filename /data/data/com.android.providers.telephony/shared_prefs/preferred-apn.xml
Filename /proc/1250/cmdline
Filename /proc/1/cmdline
Filename /data/backup/pending/journal749067769.tmp
Filename /dev/input/event0
Filename /data/data/com.traderumors/files/.Fabric/com.crashlytics.sdk.android:answers/session_analytics_to_send/sa_8c9da725-c6cb
Filename /data/data/com.google.android.googlequicksearchbox/shared_prefs/SearchSettings.xml
Filename /data/tombstones/tombstone_00
Filename /proc/1304/cmdline
Filename /proc/1923/cmdline
Filename /proc/1568/cmdline
Filename /sys/module/lowmemorykiller/parameters/adj
Filename /proc/41/cmdline
Filename /dev/urandom
Filename /data/data/com.google.android.backup/shared_prefs/BackupTransport.restoreScheduler.xml
Filename /proc/1774/cmdline
Filename /proc/1380/cmdline
Filename /data/data/com.traderumors/shared_prefs/NRAnalyticAttributeStore.xml
Filename /proc/42/cmdline
Filename /proc/1609/cmdline
Filename /proc/1309/cmdline
Filename /data/data/com.traderumors/files/.Fabric/com.crashlytics.sdk.android.crashlytics-core/5CFAAF6A00DE-0001-050D-0774579ADB
Filename /proc/29/cmdline
Filename /data/data/com.android.email/files/deviceName
Filename /proc/46/cmdline
Filename /data/data/com.google.android.apps.genie.geniewidget/files/DATA_Preferences
Filename /data/data/com.traderumors/files/.Fabric/com.crashlytics.sdk.android:answers/session_analytics.tap
Filename /data/data/com.traderumors/shared_prefs/com.google.android.gms.analytics.prefs.xml
Filename /proc/cmdline
Filename /proc/5/cmdline
Filename /proc/1630/cmdline
Filename /proc/33/cmdline
Filename /proc/9/cmdline
Filename /proc/1311/cmdline
Filename /data/data/com.android.launcher/shared_prefs/com.android.launcher2.prefs.xml
Filename /data/data/com.traderumors/shared_prefs/WizRocket.xml
Filename /proc/28/cmdline
Filename /proc/1184/cmdline
Filename /data/data/com.android.mms/shared_prefs/_has_set_default_values.xml
Filename /proc/7/cmdline
Filename /proc/1237/cmdline
Filename /data/data/com.android.calendar/shared_prefs/_has_set_default_values.xml
Filename /proc/1848/cmdline
Filename /proc/1953/cmdline
Filename /data/data/com.google.android.talk/shared_prefs/deviceCapabilities.xml
Filename /proc/35/cmdline
Filename /data/data/com.traderumors/files/nr_installation
Filename /proc/wakelocks
Filename /proc/1536/cmdline
Filename /proc/1523/cmdline
Filename /proc/1906/cmdline
Filename /proc/1379/cmdline
Filename /proc/1670/cmdline
Filename /proc/2004/cmdline
Filename /proc/cpuinfo
Filename /proc/10/cmdline
Filename /proc/14/cmdline
Filename /proc/30/cmdline
Filename /proc/2018/cmdline
Filename /proc/6/cmdline
Filename /proc/1643/cmdline
Filename /proc/27/cmdline
Filename /data/data/com.google.android.onetimeinitializer/shared_prefs/oti.xml
Filename /proc/40/cmdline
Filename /proc/1293/cmdline
Filename /data/data/com.traderumors/shared_prefs/com.crashlytics.prefs.xml
Filename /data/data/com.traderumors/shared_prefs/prefs.xml
Filename /data/data/com.android.providers.contacts/shared_prefs/com.android.providers.contacts_preferences.xml
Filename /data/data/com.google.android.googlequicksearchbox/shared_prefs/com.google.android.googlequicksearchbox_preferences.xml
Filename /proc/12/cmdline
Filename /proc/39/cmdline
Filename /proc/1892/cmdline
Filename /proc/2/cmdline
Filename /proc/1654/cmdline
Filename /data/data/com.traderumors/shared_prefs/com.crashlytics.sdk.android:answers:settings.xml
Filename /data/data/com.android.email/shared_prefs/AndroidMail.Main.xml
Filename /proc/34/cmdline
Filename /proc/1831/cmdline
Filename /proc/version
Filename /data/data/com.android.calendar/shared_prefs/com.android.calendar_preferences.xml
Filename /data/data/com.android.mms/shared_prefs/com.android.mms_preferences.xml
Filename /proc/24/cmdline
Filename /data/data/com.android.phone/shared_prefs/_has_set_default_values.xml
Filename /proc/1936/cmdline
Filename /proc/4/cmdline
Filename /proc/13/cmdline
Filename /data/data/com.android.deskclock/shared_prefs/AlarmClock.xml
Filename /sys/module/lowmemorykiller/parameters/minfree
Filename /proc/37/cmdline
Filename /proc/1222/cmdline
Filename /data/data/com.traderumors/shared_prefs/BNC_Server_Request_Queue.xml
Filename /proc/1264/cmdline
Filename /proc/1563/cmdline
Filename /data/misc/wifi/softap.conf
Filename /proc/11/cmdline
Filename /data/data/com.google.android.apps.uploader/shared_prefs/com.google.android.apps.uploader_preferences.xml
Filename /proc/1741/cmdline
Filename /proc/1797/cmdline
Filename /proc/1691/cmdline
Filename /data/data/com.traderumors/files/.Fabric/com.crashlytics.sdk.android:answers/session_analytics.tap.tmp
Filename /proc/1381/cmdline
Filename /proc/3/cmdline
Filename /proc/1460/cmdline
Filename /data/data/com.traderumors/cache/tmp1559932777635.raw
Filename /proc/1880/cmdline
Network activity
Cryptographic activity
Key 76, 50, -39, -9, -50, 16, -11, -83, 76, 50, -39, -9, -50, 16, -11, -83, 76, 50, -39, -9, -50, 16, -11, -83, 76, 50, -39, -9, -50, 16, -11, -83
Algorithm HmacSHA1
Key -35, 19, -86, 84, 17, -108, 74, 102, -72, -4, -73, 31, -16, -36, -94, -64, -4, 87, -68, 87, 97, 3, -82, -116, -56, 64, -67, 121, -123, -109,
Algorithm AES
Key 72, -40, -121, 12, -54, -83, 76, 96, -48, -38, -48, 97, 70, 44, -118, -128, -38, 81, 124, 120, 82, -29, 67, 15, -93, 48, 86, 99, -59, 4, -62
Encryption operations
Decryption operations
Information leakage
Miscellaneous
Started services
2500
General information
Worker NVISO_API_KALI_01
Permissions
BLUETOOTH Allows applications to connect to paired bluetooth devices
Allows an application to receive the ACTION_BOOT_COMPLETED that is broadcast after the system finishe
RECEIVE_BOOT_COMPLETED
booting.
Services
Class com.one.speakify.listener.NotificationListener
Class com.one.speakify.TTS
Class com.one.speakify.listener.SwitchTileService
Hardcoded URL's
http://schemas.android.com/aapt
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
This most likely means that your application did not run correctly on our test device.
Our test devices run Android 4.1 Jelly Bean (API level 16), and currently do not support hardware OpenGL acceleration.
Since the application did not run correctly, the results in the sections below could be incomplete!
Disk activity
Accessed files
Cryptographic activity
Encryption operations
Decryption operations
Information leakage
Miscellaneous
Started services
No services were started.
2509
General information
Worker NVISO_API_KALI_01
Permissions
Allows an app to access approximate location derived from network location sources such as c
ACCESS_COARSE_LOCATION
towers and Wi-Fi.
ACCESS_FINE_LOCATION Allows an app to access precise location from location sources such as GPS, cell towers, and W
ACCESS_NETWORK_STATE Allows applications to access information about networks
GET_TASKS Allows an application to get information about the currently or recently running tasks.
SET_ALARM Allows an application to broadcast an Intent to set an alarm for the user.
Allows an application to open windows using the type TYPE_SYSTEM_ALERT, shown on top o
SYSTEM_ALERT_WINDOW
other applications.
WAKE_LOCK Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimm
Services
Class com.startapp.android.publish.common.metaData.PeriodicMetaDataService
Class com.startapp.android.publish.common.metaData.InfoEventService
Class com.startapp.android.publish.common.metaData.PeriodicJobService
Hardcoded URL's
http://schemas.android.com/aapt
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
https://play.google.com/store/apps/details?id=com.darshitdave.deliciousrecipesoup
https://play.google.com/store/apps/developer?id=Darshit+Dave
Disk activity
Accessed files
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/StartappSplashMetadata
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/StartappAdInfoMetadata
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/StartappAdsMetadata
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/StartappCacheMetadata
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/StartappMetadata
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/StartappBannerMetadata
Filename /proc/1188/cmdline
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/shared_prefs_sdk_ad_prefs
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/x_dark.png
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/logo.png
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/half_star.png
Filename /proc/270/cmdline
Filename /dev/input/event0
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/filled_star.png
Filename /proc/meminfo
Filename /proc/37/cmdline
Filename pipe:[5155]
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/empty_star.png
Filename /data/data/com.darshitdave.deliciousrecipesoup/shared_prefs/com.startapp.android.publish.CookiePrefsFile.xml
Filename /data/anr/traces.txt
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/back_dark.png
Filename /proc/40/cmdline
Filename /data/data/com.darshitdave.deliciousrecipesoup/shared_prefs/com.startapp.android.publish.xml
Filename /proc/1/cmdline
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/close_button.png
Filename /proc/350/cmdline
Filename /proc/691/cmdline
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/back_.png
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/forward_.png
Filename /proc/1309/cmdline
Filename /proc/14/cmdline
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/browser_icon_dark.png
Filename /proc/271/cmdline
Filename pipe:[5164]
Filename /proc/34/cmdline
Filename /proc/10/cmdline
Filename /proc/272/cmdline
Filename /proc/11/cmdline
Filename /proc/1269/cmdline
Filename /proc/30/cmdline
Filename /proc/463/cmdline
Filename pipe:[4990]
Filename /proc/1314/cmdline
Filename /proc/5/cmdline
Filename /proc/39/cmdline
Filename /proc/1242/cmdline
Filename /data/data/com.darshitdave.deliciousrecipesoup/shared_prefs/RunnerManager.xml
Filename /proc/576/cmdline
Filename /proc/783/cmdline
Filename /data/data/com.darshitdave.deliciousrecipesoup/shared_prefs/TruenetJobKey.xml
Filename /data/data/com.darshitdave.deliciousrecipesoup/files/forward_dark.png
Filename /proc/13/cmdline
Filename /proc/1226/cmdline
Filename /proc/1403/cmdline
Filename /proc/491/cmdline
Filename /proc/733/cmdline
Filename /proc/1312/cmdline
Filename /proc/598/cmdline
Filename /proc/9/cmdline
Filename /proc/27/cmdline
Filename /proc/1255/cmdline
Filename /proc/627/cmdline
Filename /proc/25/cmdline
Filename /proc/660/cmdline
Filename /dev/urandom
Filename /proc/1298/cmdline
Filename /proc/2/cmdline
Filename /proc/24/cmdline
Filename /proc/3/cmdline
Filename /proc/6/cmdline
Filename /proc/28/cmdline
Filename /proc/8/cmdline
Filename /proc/1097/cmdline
Filename /proc/478/cmdline
Filename /proc/45/cmdline
Filename /proc/33/cmdline
Filename /proc/12/cmdline
Filename /proc/1081/cmdline
Filename /proc/4/cmdline
Filename /proc/42/cmdline
Filename /proc/46/cmdline
Filename /proc/29/cmdline
Filename /proc/26/cmdline
Filename /proc/41/cmdline
Filename /proc/674/cmdline
Filename /proc/7/cmdline
Filename /proc/825/cmdline
Filename /proc/516/cmdline
Filename /proc/1022/cmdline
Filename /proc/1134/cmdline
Filename /proc/35/cmdline
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /proc/1147/cmdline
Network activity
Cryptographic activity
Decryption operations
Information leakage
Miscellaneous
Started services
2514
Worker NVISO_API_KALI_01
Permissions
ACCESS_FINE_LOCATION Allows an app to access precise location from location sources such as GPS, cell towers, and Wi-Fi.
Services
No services registered.
Hardcoded URL's
http://rate.ws.trsproxy.whbhk.com
http://rate.ws.trsproxy.whbhk.com/fetchRate
http://schemas.android.com/apk/res/android
http://schemas.xmlsoap.org/soap/envelope/
http://services1.aastocks.com/web/whbl/AAFN.aspx?whbllanguage=chi
http://services1.aastocks.com/web/whbl/AAFN.aspx?whbllanguage=chn
http://services1.aastocks.com/web/whbl/AAFN.aspx?whbllanguage=eng
http://services1.aastocks.com/web/whbl/indices.aspx?whbllanguage=chi
http://services1.aastocks.com/web/whbl/indices.aspx?whbllanguage=chn
http://services1.aastocks.com/web/whbl/indices.aspx?whbllanguage=eng
http://services1.aastocks.com/web/whbl/Quote.aspx?WHBLLanguage=chi
http://services1.aastocks.com/web/whbl/Quote.aspx?WHBLLanguage=chn
http://services1.aastocks.com/web/whbl/Quote.aspx?WHBLLanguage=eng
https://s3-ap-southeast-1.amazonaws.com/ocbcmobileappcontent/Submission.xml
http://www.ocbcwhmac.com/applications/cms/chi/mobile_apps/modDepositRates.html
http://www.ocbcwhmac.com/applications/cms/chi/mobile_apps/promo.html
http://www.ocbcwhmac.com/applications/cms/eng/mobile_apps/modDepositRates.html
http://www.ocbcwhmac.com/applications/cms/eng/mobile_apps/promo.html
http://www.ocbcwhmac.com/applications/cms/schi/mobile_apps/modDepositRates.html
http://www.ocbcwhmac.com/applications/cms/schi/mobile_apps/promo.html
http://www.ocbcwhmac.com/chi/personal_ibanking/security_tips.html
http://www.ocbcwhmac.com/chi/privacy_
<="" td="" style="margin: 0px;">
http://www.ocbcwhmac.com/eng/personal_ibanking/security_tips.html
http://www.ocbcwhmac.com/xml/branch.xml
http://www.ocbcwhmac.com/xml/hotline.xml
http://www.w3.org/2001/XMLSchema-instance
http://www.w3.org/TR/html4/strict.dtd
Dynamic malware analysis
This most likely means that your application did not run correctly on our test device.
Our test devices run Android 4.1 Jelly Bean (API level 16), and currently do not support hardware OpenGL acceleration.
Since the application did not run correctly, the results in the sections below could be incomplete!
Disk activity
Accessed files
Network activity
Cryptographic activity
Encryption operations
Decryption operations
Miscellaneous
Started services
3012
General information
Worker NVISO_API_KALI_01
Permissions
ACCESS_COARSE_LOCATION Allows an app to access approximate location derived from network location sources such as cell towers and
ACCESS_FINE_LOCATION Allows an app to access precise location from location sources such as GPS, cell towers, and Wi-Fi.
RECEIVE_MMS Allows an application to monitor incoming MMS messages, to record or perform processing on them.
RECEIVE_SMS Allows an application to monitor incoming SMS messages, to record or perform processing on them.
WAKE_LOCK Allows using PowerManager WakeLocks to keep processor from sleeping or screen from dimming
Services
Class com.google.android.gms.cast.framework.media.MediaNotificationService
Class com.google.android.gms.auth.api.signin.RevocationBoundService
Class com.google.android.gms.cast.framework.ReconnectionService
Class com.google.firebase.messaging.FirebaseMessagingService
Class com.google.android.gms.tagmanager.TagManagerService
Class com.google.android.gms.measurement.AppMeasurementService
Class com.google.android.gms.measurement.AppMeasurementJobService
Class com.google.firebase.iid.FirebaseInstanceIdService
Virus Total scan results
Hardcoded URL's
http://schemas.android.com/apk/res-auto
http://schemas.android.com/apk/res/android
This most likely means that your application did not run correctly on our test device.
Our test devices run Android 4.1 Jelly Bean (API level 16), and currently do not support hardware OpenGL acceleration.
Since the application did not run correctly, the results in the sections below could be incomplete!
Disk activity
Accessed files
Network activity
Cryptographic activity
Used encryption keys
Encryption operations
Decryption operations
Information leakage
Miscellaneous
Started services
2047
Worker NVISO_API_KALI_01
Permissions
INTERNET Allows applications to open network sockets.
Services
No services registered.
Hardcoded URL's
http://schemas.android.com/aapt
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res-auto
Dynamic malware analysis
Random artificial input is provided to the scanned applications during dynamic analysis, in order to mimic a human being using and interacting with the applica
can result in our report showing a different screen than the one you would see when starting the application.
Disk activity
Accessed files
Filename /proc/1251/cmdline
Filename /data/data/com.android.music/shared_prefs/Music.xml
Filename /proc/1237/cmdline
Filename /proc/1334/cmdline
Filename /proc/1295/cmdline
Filename /dev/input/event0
Filename /proc/meminfo
Filename /data/data/com.android.launcher/shared_prefs/com.android.launcher2.prefs.xml
Filename /proc/1224/cmdline
Filename /proc/1297/cmdline
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /proc/1293/cmdline
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Network activity
Cryptographic activity
Encryption operations
Decryption operations
Information leakage
Miscellaneous
Started services
Service name com.android.music.MediaPlaybackService
3501
General information
Worker NVISO_API_KALI_01
Permissions
No permissions requested.
Services
Class fr.gjandot.LWP.equalizer.simple.EqualizerLWP
Hardcoded URL's
http://schemas.android.com/apk/res/android
http://schemas.android.com/apk/res/fr.gjandot.LWP.equalizer.simple
https://play.google.com/store/apps/details?id=fr.gjandot.LWP.equalizer
Random artificial input is provided to the scanned applications during dynamic analysis, in order to mimic a human being using and interacting with the applica
can result in our report showing a different screen than the one you would see when starting the application.
Disk activity
Accessed files
Filename /proc/1266/cmdline
Filename /proc/meminfo
Filename /proc/1240/cmdline
Filename /proc/1312/cmdline
Filename /data/data/com.android.vending/shared_prefs/finsky.xml
Filename /proc/1313/cmdline
Filename /proc/1307/cmdline
Filename /dev/input/event0
Filename /data/data/com.android.gallery3d/shared_prefs/com.android.gallery3d_preferences.xml
Filename /proc/1294/cmdline
Filename /proc/1252/cmdline
Filename /data/data/com.android.music/shared_prefs/Music.xml
Filename /proc/1336/cmdline
Filename /proc/1310/cmdline
Filename /proc/1225/cmdline
Network activity
Cryptographic activity
Encryption operations
Decryption operations
No cryptographic activity detected.
Information leakage
Miscellaneous
Started services