So I tried building an apk, it seems to work except it got stuck on signing it. Probably a problem with certificates, probably easy fix.
Here is the new analysis :
Code:
Detailed report of suspicious malware actions:
Checked for debuggers
Checked for Microsoft Management Console software presence
Code injection in process: C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp
Code injection in process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe
Code injection in process: C:\Windows\System32\icacls.exe
Code injection in process: C:\Windows\SysWOW64\chcp.com
Code injection in process: C:\Windows\SysWOW64\cmd.exe
Code injection in process: C:\Windows\SysWOW64\WerFault.exe
Created a mutex named: .NET CLR Data_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET CLR Networking 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET CLR Networking_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET Data Provider for Oracle_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET Data Provider for SqlServer_Perf_Library_Lock_PID_6b8
Created a mutex named: .NET Memory Cache 4.0_Perf_Library_Lock_PID_6b8
Created a mutex named: .NETFramework_Perf_Library_Lock_PID_6b8
Created a mutex named: BITS_Perf_Library_Lock_PID_6b8
Created a mutex named: ESENT_Perf_Library_Lock_PID_6b8
Created a mutex named: Global\CLR_PerfMon_WrapMutex
Created a mutex named: Lsa_Perf_Library_Lock_PID_6b8
Created a mutex named: LSM_Perf_Library_Lock_PID_6b8
Created a mutex named: MSDTC Bridge 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: MSDTC Bridge 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: MSDTC_Perf_Library_Lock_PID_6b8
Created a mutex named: MSSCNTRS_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfDisk_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfNet_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfOS_Perf_Library_Lock_PID_6b8
Created a mutex named: PerfProc_Perf_Library_Lock_PID_6b8
Created a mutex named: rdyboost_Perf_Library_Lock_PID_6b8
Created a mutex named: RemoteAccess_Perf_Library_Lock_PID_6b8
Created a mutex named: ServiceModelEndpoint 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: ServiceModelOperation 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: ServiceModelService 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: SMSvcHost 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: SMSvcHost 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: Spooler_Perf_Library_Lock_PID_6b8
Created a mutex named: TapiSrv_Perf_Library_Lock_PID_6b8
Created a mutex named: Tcpip_Perf_Library_Lock_PID_6b8
Created a mutex named: TermService_Perf_Library_Lock_PID_6b8
Created a mutex named: UGatherer_Perf_Library_Lock_PID_6b8
Created a mutex named: UGTHRSVC_Perf_Library_Lock_PID_6b8
Created a mutex named: usbhub_Perf_Library_Lock_PID_6b8
Created a mutex named: Windows Workflow Foundation 3.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: Windows Workflow Foundation 4.0.0.0_Perf_Library_Lock_PID_6b8
Created a mutex named: WmiApRpl_Perf_Library_Lock_PID_6b8
Created a mutex named: WSearchIdxPi_Perf_Library_Lock_PID_6b8
Created an event named: Global\CLR_PerfMon_DoneEnumEvent
Created an event named: Global\CLR_PerfMon_StartEnumEvent
Created an event named: Global\CPFATE_1720_v4.0.30319
Created an event named: Global\CPFATE_5900_v4.0.30319
Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar" b -f -r app-release, C:\Building-6.4\apktool
Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java -jar -Duser.language=en -Dfile.encoding=UTF8 "C:\Building-6.4\apktool\apktool.jar" d app-release.apk, C:\Building-6.4\apktool
Created process: C:\Program Files (x86)\Common Files\Oracle\Java\javapath\java.exe, java -version, C:\Users\root\Downloads\AT
Created process: C:\Program Files\Java\jre1.8.0_261\bin\java.exe, java -jar C:\Building-6.4\apktool\SignApk.jar C:\Building-6.4\apktool\certificate.pem C:\Building-6.4\apktool\key.pk8 C:\Building-6.4\apktool\app-release\dist\app-release.apk C:\Building-6.4\apktool\out\client.apk, C:\Program Files\Java\jre1.8.0_261\bin
Created process: C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe, "C:\Users\root\Downloads\AT\Resources\Imports\Payload\BuildClient.exe"Â n -160, C:\Users\root\Downloads\AT
Created process: C:\Windows\system32\chcp.com, chcp 65001 , C:\Building-6.4\apktool
Created process: null, "C:\Windows\explorer.exe" "C:\Building-6.4\apktool\out", null
Created process: null, "cmd.exe", C:\Users\root\Downloads\AT
Created process: null, C:\Users\root\AppData\Local\Temp\brut_util_Jar_6119903276741999186.tmp p --forced-package-id 127 --min-sdk-version 10 --target-sdk-version 22 --version-code 1 --version-name 6.4.4 --no-version-vectors -F C:\Users\root\AppData\Local\Temp\APKTOOL8645836706554158331.tmp -0 arsc -0 png -0 res/drawable-hdpi/abc_ab_share_pack_mtrl_alpha.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00001.9.png -0 res/drawable-hdpi/abc_btn_switch_to_on_mtrl_00012.9.png -0 res/drawable-hdpi/abc_cab_background_top_mtrl_alpha.9.png -, null
Created process: null, C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant "everyone":(OI)(CI)M, null
Defined file type created: C:\Building-6.4\apktool\apktool.bat
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Data\Linkage\Export = .NET CLR Data
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET CLR Networking\Linkage\Export = .NET CLR Networking
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for Oracle\Linkage\Export = .NET Data Provider for Oracle
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\.NET Data Provider for SqlServer\Linkage\Export = .NET Data Provider for SqlServer
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Performance\1008 = A07730EF809AD601
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\BITS\Start = 00000003
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DcomLaunch = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\DPS = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\gpsvc = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\Lsa\Performance\1008 = C5AA7AEF809AD601
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\rdyboost\Performance\1023 = 2AD35EF0809AD601
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\RpcSs = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\SamSs = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrkWks = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\TrustedInstaller = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiServiceHost = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WdiSystemHost = created registry key
Defined registry AutoStart location created or modified: machine\System\CurrentControlSet\Services\WmiApRpl\Performance\1008 = 2FB07BF0809AD601
Detected keylogger functionality
Detected privilege modification
Detected process privilege elevation
Enumerated running processes
Error reporting dialog change: machine\software\microsoft\windows\windows error reporting\dontshowui = 00000001
Got computer name
Got input locale identifiers
Got system default language ID
Got volume information
Locked screen
Queried DNS: eafddirect.msedge.net
Queried DNS: encrypted-tbn0.gstatic.com
Queried DNS: fonts.gstatic.com
Queried DNS: k-ring.msedge.net
Queried DNS: virustotal.lan
Queried DNS: wpad.lan
Queried DNS: www.google.com
Queried DNS: www.virustotal.com
Slept over 2 minutes
Terminated process: C:\Windows\SysWOW64\cmd.exe
This executable was detected by an antivirus software: 8 vendors from virustotal.com (2020-09-27)
Traces of Max++
Used a pipe for inter-process communication
It looks pretty clean. I wonder about those Queries though, maybe that's a problem with BSA itself (I don't see why would this app call virustotal).
I just noticed the code injections though, that might not be normal, not really sure as JRE could be responsible ? I'd guess it's normal for cmd.exe at least.
And here is the VT of the APK generated :
https://www.virustotal.com/gui/file/c6c8.../detection
Next plan is to try it (I need a safe Android environnement first) and look at the connexions.