Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.DownLoader.405.origin
Downloads the following detected threats from the Web:
- Android.DownLoader.405.origin
Network activity:
Connecting to:
- 1####.####.188
- ad####.####.com
- a####.####.com
HTTP GET requests:
- ad####.####.com/dev/tempone
- ad####.####.com/dev/xxx.png
HTTP POST requests:
- a####.####.com/app_logs
- 1####.####.188/qijiad/phonead/PhoneAdvert!getAdvert.action
- 1####.####.188/qijiad/phonead/PhoneRequest!getSDKInfo.action
- 1####.####.188/qijiad/phonead/PhoneRequest!getDevProductConfig.action
Modified file system:
Creates the following files:
- /data/data/####/files/umeng_it.cache
- /data/data/####/shared_prefs/umeng_general_config.xml.bak
- /sdcard/.wkh/tempone
- /data/data/####/shared_prefs/preference_file.xml.bak
- /data/data/####/app_ree/classes.jar
- /data/data/####/shared_prefs/####_preferences.xml
- /data/data/####/shared_prefs/umeng_general_config.xml
- /data/data/####/shared_prefs/####_preferences.xml.bak
- /data/data/####/shared_prefs/preference_file.xml
- /data/data/####/shared_prefs/IsLoaded.xml
- /data/data/####/files/.imprint
- /data/data/####/shared_prefs/apprate_prefs.xml
Miscellaneous:
Contains functionality to send SMS messages automatically.