Android games adware and trojan flase negative

Here is some android adware and trojan games not detected by avast (submitted a few days ago). All downloaded from the domain hxxp://sj.img4399.com/ (not blocked by avast).
The link will directly download the application

URL: hxxp://sj.img4399.com/game_list/com.petKing/com.petKing_7.apk
trojan agent
https://www.virustotal.com/zh-tw/file/3734999d4d42d12144566087d6c64f1a2d91b59a349e57bf3dcf6e46b8a118da/analysis/1401077957/

URL: hxxp://sj.img4399.com/game_list/com.androidemu.neststd/com.androidemu.neststd.apk
adware domob
https://www.virustotal.com/zh-tw/file/3c9cd2e71f20d6f5fd65cbfecd312dd3a43531bca7041dc9c94e8a369d132c0f/analysis/

URL: hxxp://sj.img4399.com/game_list/com.androidemu.gbakdygvbs/com.androidemu.gbakdygvbs.apk
adware adwo
https://www.virustotal.com/zh-tw/file/f774398a4d3d51422355ec79df03e958f5d0f895572ecf19e18cad08381a2c55/analysis/

URL: hxxp://sj.img4399.com/game_list/yc.mhls.appmm2/mhls.appmm2.v36266.apk
adware secAPK
https://www.virustotal.com/zh-tw/file/b77b2a2d14bd610601b7ca30efabd56097c10dc19e1e0f5f8b4144cec04842d3/analysis/1402977418/
Note: cracked game.

URL: hxxp://sj.img4399.com/game_list/com.cwa.game.src/game.src_1.apk
PUP smsreg
https://www.virustotal.com/zh-tw/file/0cc086a7169cbf500868c89f0d52a0c7ebaf989cbdd674a95de747a13b7d122c/analysis/1403361896/
Note: There are comments in the site report that the game need extra charge in web connection when “a.4399.cn” test it and say that the game doesn’t need internet connection

URL: hxxp://sj.img4399.com/game_list/288/cn.easymobi.entertainment.chickdefencemod/entertainment.chickdefencemod.v43466.apk
PUP smsreg / trojan nandrobox
https://www.virustotal.com/zh-tw/file/02e0493c5c68e5e51b5f7201d7d471fb138094b4f320894a60a7c878a01fae43/analysis/
Note: cracked game.

URL: hxxp://sj.img4399.com/game_list/349/com.activ8.uucun_FKYSRmod/activ8.uucun_FKYSRmod.v43464.apk
PUP smsreg / trojan nandrobox
https://www.virustotal.com/zh-tw/file/3e5d225e024e7ffb084bd32c153558ee031f1765a3a948404b91f1a794037058/analysis/1403950115/
Note: cracked game.

URL: hxxp://sj.img4399.com/game_list/374/com.sxiaoao.android.farmTD2/android.farmTD2.v43352.apk
PUP airpush / PUP smsreg
https://www.virustotal.com/zh-tw/file/d93e46bdc3b4ef4c16969ff65897633c35a8819cdee123522e23aa32ee34947a/analysis/1403950449/

URL: hxxp://sj.img4399.com/game_list/361/com.snailfighter.game.bigtower/game.bigtower.v39652.apk
adware youmi
https://www.virustotal.com/zh-tw/file/5dcc40f2e64917d56bb566ac3e8e6efdc2dd02ead224fb3a65c36a2edfa1e556/analysis/1408777696/
Note: adware not in classes.dex when scan in virscan.org

URL: hxxp://sj.img4399.com/game_list/177/com.qcplay.son/qcplay.son.v47477.apk
PUP SpyBubble / PUP smsreg
https://www.virustotal.com/zh-tw/file/064091e9becbff158f895f4e3abf7c69339f2e3e5a153e821ad7f95b9d32ce1f/analysis/1408810537/

URL: hxxp://sj.img4399.com/game_list/225/com.catmario/com.catmario.v42181.apk
adware revmob
https://www.virustotal.com/zh-tw/file/77bad545806af5bfaa44923185678e48a1914310c0b956bb4b6de6b7b43fbdf1/analysis/1406457678/
Note: “no ads” is stated in the game description page.

URL: hxxp://sj.img4399.com/game_list/205/com.catmario2.hd/catmario2.hd.v42188.apk
adware revmob
https://www.virustotal.com/zh-tw/file/0232d03a3cf0b88e81e6ccc2835b2a32249f89d419cd321a5a9f397ee64590f0/analysis/1406457285/

URL: hxxp://sj.img4399.com/game_list/408/com.shayort.herobrine3/shayort.herobrine3.v45479.apk
adware revmob
https://www.virustotal.com/zh-tw/file/5d63249b5d2ff54b31d9bf7a9cb63a31b7c2667537d9d0bc604bcd33ccf37523/analysis/1406457191/

One Flase Positive
URL: http://sj.img4399.com/game_list/com.Nexon.DunfightENGF360/Nexon.DunfightENGF360_7.apk
game name: 地下城与勇士 (DNF)
https://www.virustotal.com/zh-tw/file/ce471da01ca5a97f8d4a99c7119019e51d6660c796ac3709887a859a0db3c82e/analysis/1409200938/
This game is updated and smsreg is removed from it.

One suspicious game
URL: hxxp://sj.img4399.com/game_list/296/net.crimoon.pm.a4399/pm.a4399.v47046.apk
game name: 去吧皮卡丘
malware: android trojan agent
https://www.virustotal.com/zh-tw/file/550e2170abe98666df17ccfadc255acd89212c001dfc683cc0a31b34bb45950c/analysis/
[b]Low detection ratio. But using official source here http://t.cn/RPLM16S, I get total clean result https://www.virustotal.com/zh-tw/file/1db241f0ad35ce86b063a610cd357f78b6cb7bdd3fc8aa60ee28b690280ac392/analysis/[/b]

Hi, thank you for pointing this out. We will check those apk and decide if they are really malicious or not. Some of them seems to be only advertisement kits which are clean on first look.