Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Backdoor.371.origin
Downloads the following detected threats from the Web:
- Android.Backdoor.371.origin
Network activity:
Connecting to:
- doud####.com
- h####.####.com
- a####.####.com
- p####.####.com
HTTP GET requests:
- p####.####.com/s/18E2tH
- doud####.com/update.html?version=####
- a####.####.com/a4d7bfeed0556e351450428584122.dex
HTTP POST requests:
- doud####.com/adCenter/app/get
- a####.####.com/app_logs
- doud####.com/adCenter/ad/get
- doud####.com/adCenter/seo/get
- h####.####.com/app.gif
Modified file system:
Creates the following files:
- /data/data/####/shared_prefs/resetDB1023.xml
- /data/data/####/files/umeng_it.cache
- /data/data/####/databases/dbname
- /data/data/####/shared_prefs/ddspname.xml
- /data/data/####/databases/dbname-journal
- /sdcard/a/####/b.dex
- /data/data/####/shared_prefs/d.xml
- /data/data/####/shared_prefs/umeng_general_config.xml
- /data/data/####/shared_prefs/__Baidu_Stat_SDK_SendRem.xml
- /data/data/####/databases/superwrite.db
- /data/data/####/databases/superwrite.db-journal
- /sdcard/backups/.SystemConfig/.cuid
- /data/data/####/files/.imprint
- /data/data/####/cache/d.dex
- /data/data/####/files/__local_stat_cache.json
- /data/data/####/files/__local_last_session.json
Miscellaneous:
Contains functionality to send SMS messages automatically.