Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Backdoor.371.origin
- Android.DownLoader.57.origin
Downloads the following detected threats from the Web:
- Android.Backdoor.371.origin
Network activity:
Connecting to:
- doud####.com
- p####.####.com
- a####.####.com
HTTP GET requests:
- p####.####.com/s/18E2tH
- doud####.com/update.html?version=####
- a####.####.com/a4d7bfeed0556e351450428584122.dex
HTTP POST requests:
- doud####.com/adCenter/app/get
- a####.####.com/app_logs
- doud####.com/adCenter/ad/get
- doud####.com/adCenter/seo/get
Modified file system:
Creates the following files:
- /data/data/####/shared_prefs/iad_unkit.xml
- /data/data/####/databases/iad.db-journal
- /data/data/####/databases/iad_frame.db-journal
- /data/data/####/databases/Iad_lock.db
- /data/data/####/shared_prefs/ipssp.xml
- /data/data/####/shared_prefs/ddspname.xml
- /data/data/####/shared_prefs/umeng_general_config.xml
- /data/data/####/files/.imprint
- /data/data/####/cache/d.dex
- /data/data/####/databases/dbname
- /data/data/####/databases/dbname-journal
- /data/data/####/shared_prefs/d.xml
- /data/data/####/shared_prefs/iad_frame_pre.xml
- /data/data/####/files/x531nitest.zip
- /sdcard/Android/data/xxh/XH.txt
- /data/data/####/files/x531ni
- /data/data/####/files/umeng_it.cache
- /data/data/####/files/x531i
- /sdcard/a/####/baidumap.dex
- /data/data/####/shared_prefs/ipssp.xml.bak
- /data/data/####/shared_prefs/PencilCameraPrefs.xml
- /data/data/####/databases/Iad_lock.db-journal
Miscellaneous:
Contains functionality to send SMS messages automatically.