newkingrootv4.50_c120_b220_xda_release_2015_09_02_105243.zip

The file newkingrootv4.50_c120_b220_xda_release_2015_09_02_105243.zip has been detected as a potentially unwanted program by 6 anti-malware scanners. The file has been seen being downloaded from dl-1.va.us.xda-developers.com and multiple other hosts.
MD5:
19be91bde9c7ba09471a123e0495b7ea

SHA-1:
02cd19e05038f09906f78b1676592eb22f921cca

SHA-256:
cdff6bb4596dfa5bdc340097d758b8159d1a3b4047185bd5128d992c2ce83983

Scanner detections:
6 / 68

Status:
Potentially unwanted

Analysis date:
11/5/2024 11:38:02 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

AhnLab V3 Security
Android-Exploit/Rootor.4a9f
2015.09.02

AVG
Android/KingRoot
2016.0.2998

ESET NOD32
Android/DroidRooter.AG potentially unsafe application
7.0.302.0

NANO AntiVirus
Trojan.Android.Rooter.drlftw
0.30.24.3283

Quick Heal
Android.Rooter.E (PUP)
9.15.14.00

Sophos
PUA 'Android KingRoot' (of type Hacktool)
5.15

File size:
5.3 MB (5,522,875 bytes)

Common path:
C:\users\{user}\downloads\newkingrootv4.50_c120_b220_xda_release_2015_09_02_105243.zip

The file newkingrootv4.50_c120_b220_xda_release_2015_09_02_105243.zip has been seen being distributed by the following 8 URLs.

http://dl-1.va.us.xda-developers.com/3/.../6/6/1/2/.../NewKingrootV4.50.apk?key=dbYkHNEf37Ur7c8gVyEsMg&ts=1458061845

http://serv3.dailyuploads.net:182/d/.../KingRoot.apk