Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.DownLoader.122.origin
Modified file system:
Creates the following files:
- <Package Folder>/app_oknf/classes.jar
- <Package Folder>/cache/ads-500711733.jar
- <Package Folder>/cache/ads1982757040.jar
- <Package Folder>/databases/dbcmak-journal
- <Package Folder>/databases/webview.db-journal
- <Package Folder>/files/txRes_1.4
- <Package Folder>/files/txRes_1.4_Exec
Miscellaneous:
Executes next shell scripts:
- chmod 700 <Package Folder>/files/txRes_1.4
- chmod 700 <Package Folder>/files/txRes_1.4_Exec
- getprop ro.product.cpu.abi
Loads the following dynamic libraries:
- txRes_1
Gains access to camera interface.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about running applications.