https://www.virustotal.com/gui/file/a64ef85085e7db98244dd2128b2674f02e7fd0dff3ba393525edeedcb5ad6044/detection

I downloaded it from androeed.ru, which is in the megathread. However, it has 16 detections, and it’s labled trojan, and I never used androeed.ru before, so idk how trustable it is.

Still I’m tempted to install it since sandbox found no Network comms. But I’m new to piracy so I think I should ask here first.

Thanks for replying! Edit to provide a bit more info:

  1. This is a mod apk file for a paid game called sproggiwood, so I thought it would be normal to drop files like /libandroeedru.so, you know, to unlock game or something.

  2. The site androeed.ru is in the 2nd place in “Android Cracked/Modded App Markets & Repos” list, right after mobilism, so I thought it was a famous piracy site as well. (I’m new to piracy, so idk. Is it famous?)

  3. This file was uploaded to androeed at 2020, which means if it is indeed malicious, the site is unsafe since 2020, so it should be removed from megathread long time ago. Is the megathread that outdated?

  4. Trojan means it steals info via internet. And virustotal said it only contacted 5 domains: 1: clientservices.googleapis.com 2: connectivitycheck.gstatic.com 3: gmscompliance-pa.googleapis.com 4: gstatic.com 5: infinitedata-pa.googleapis.com Does this mean the detections are false positives or am I missing something?

I’m at a loss. Please help! Thank you very much.

  • OsrsNeedsF2P
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    10 months ago

    Malicious files can still be uploaded to trusted sites, but in general apks are well sendboxed so it’s difficult to get a trojan on a non-rooted, up to date Android phone.

    What is the apk supposed to be for?

    • Aresff@reddthat.comOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      10 months ago

      It’s a mod apk file for the game sproggiwood 1.3.2. The file seems to be modded by the site itself though, so if it’s malicious I guess the site is not trustable.