https://www.virustotal.com/gui/file/a64ef85085e7db98244dd2128b2674f02e7fd0dff3ba393525edeedcb5ad6044/detection

I downloaded it from androeed.ru, which is in the megathread. However, it has 16 detections, and it’s labled trojan, and I never used androeed.ru before, so idk how trustable it is.

Still I’m tempted to install it since sandbox found no Network comms. But I’m new to piracy so I think I should ask here first.

Thanks for replying! Edit to provide a bit more info:

  1. This is a mod apk file for a paid game called sproggiwood, so I thought it would be normal to drop files like /libandroeedru.so, you know, to unlock game or something.

  2. The site androeed.ru is in the 2nd place in “Android Cracked/Modded App Markets & Repos” list, right after mobilism, so I thought it was a famous piracy site as well. (I’m new to piracy, so idk. Is it famous?)

  3. This file was uploaded to androeed at 2020, which means if it is indeed malicious, the site is unsafe since 2020, so it should be removed from megathread long time ago. Is the megathread that outdated?

  4. Trojan means it steals info via internet. And virustotal said it only contacted 5 domains: 1: clientservices.googleapis.com 2: connectivitycheck.gstatic.com 3: gmscompliance-pa.googleapis.com 4: gstatic.com 5: infinitedata-pa.googleapis.com Does this mean the detections are false positives or am I missing something?

I’m at a loss. Please help! Thank you very much.

@OsrsNeedsF2P@lemmy.ml
link
fedilink
English
31Y

Malicious files can still be uploaded to trusted sites, but in general apks are well sendboxed so it’s difficult to get a trojan on a non-rooted, up to date Android phone.

What is the apk supposed to be for?

@Aresff@reddthat.com
creator
link
fedilink
English
11Y

It’s a mod apk file for the game sproggiwood 1.3.2. The file seems to be modded by the site itself though, so if it’s malicious I guess the site is not trustable.

Unruffled [they/them]
mod
link
fedilink
English
31Y

There’s a decent write up on how Android ‘dropper’ malware functions here. TLDR - while the APK may be clean, it tries to trick you into installing a malware infected APK later in the install process or during a fake update.

@Aresff@reddthat.com
creator
link
fedilink
English
11Y

Thanks. That dropper function looks dangerous. However, the first dropper campaign spotted by Threat Fabric at the beginning of October 2022, and this file was uploaded at 2020, so even if it’s indeed malicious, it’s probably a different bad guy I guess.

@thelonelyghost@infosec.pub
link
fedilink
English
22
edit-2
1Y

This reads the same as “hi, my friend saw my {dating app} date’s photo up at the post office with the note that they were wanted for the murder of 16 different {my demographic}. Should I still go on a date with them to that remote cabin in the woods?”

@Aresff@reddthat.com
creator
link
fedilink
English
1
edit-2
1Y

Yeah. It’s a lot safer to go on a date with someone who was wanted for the murder of just 1 or 2 different persons to that remote cabin in the woods, isn’t it? :D

@phx@lemmy.ca
link
fedilink
English
51Y

From a .RU site no less…

@Pulp@lemmy.dbzer0.com
link
fedilink
English
121Y

Find another source

@Aresff@reddthat.com
creator
link
fedilink
English
11Y

I searched the entire list of “Android Cracked/Modded App Markets & Repos” but unfortunately no other site has this 1.3.2 modded version.

They seem to drop a library file not existing in the original apk in the filesystem:
/data/app-lib/com.freeholdgames.sproggiwood-1/libandroeedru.so
I wonder what is its’ purpose…

@Aresff@reddthat.com
creator
link
fedilink
English
11Y

I’m curious too. Since it has the same name as the site and the site is in the megalist, could it be safe?

probably to inject ads or toast messages when you launch the game

A russian file labeled as a trojan? It must be perfectly safe. Or at least you’ll learn a valuable lesson.

@Aresff@reddthat.com
creator
link
fedilink
English
11Y

Are russian files more likely to be malicious? I’m curious.

@glad_cat@lemmy.sdf.org
link
fedilink
English
31Y

In the past (I.e. 90s to 2000), very yes. Nowadays I don’t know, but with the war and the spying stuff, I would still avoid such sources.

@jet@hackertalks.com
link
fedilink
English
141Y

This is clearly a trap. This hook is so shiny. Any idiot would know this. But I really want the bait! One bite won’t hurt

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ
!piracy@lemmy.dbzer0.com
Create a post
⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don’t request invites, trade, sell, or self-promote

3. Don’t request or link to specific pirated titles, including DMs

4. Don’t submit low-quality posts, be entitled, or harass others



Loot, Pillage, & Plunder

📜 c/Piracy Wiki (Community Edition):

🏴‍☠️ Other communities

Torrenting:

  • !seedboxes@lemmy.dbzer0.com
  • !trackers@lemmy.dbzer0.com
  • !qbittorrent@lemmy.dbzer0.com
  • !libretorrent@lemmy.dbzer0.com

Gaming:

  • !steamdeckpirates@lemmy.dbzer0.com
  • !newyuzupiracy@lemmy.dbzer0.com
  • !switchpirates@lemmy.dbzer0.com
  • !3dspiracy@lemmy.dbzer0.com
  • !retropirates@lemmy.dbzer0.com

💰 Please help cover server costs.

Ko-Fi Liberapay
Ko-fi Liberapay

  • 1 user online
  • 389 users / day
  • 565 users / week
  • 1.29K users / month
  • 3.43K users / 6 months
  • 1 subscriber
  • 3.79K Posts
  • 89.3K Comments
  • Modlog