Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.DownLoader.3394
- Android.DownLoader.635.origin
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) c.appj####.com:80
- TCP(HTTP/1.1) a.appj####.com:80
DNS requests:
- a.appj####.com
- c.appj####.com
HTTP POST requests:
- a.appj####.com/jiagu/check/upgrade
- c.appj####.com/ad/splash/stats.html
Modified file system:
Creates the following files:
- <Package Folder>/.jiagu/libjiagu.so
- <Package Folder>/app_zq/<Package>.apk
- <Package Folder>/files/####/.jg.ic
- <Package Folder>/files/temp_photo.jpg
- <Package Folder>/shared_prefs/ad_show_time.xml
- <Package Folder>/shared_prefs/jg_app_update_settings_random.xml
Miscellaneous:
Executes next shell scripts:
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
Loads the following dynamic libraries:
- libjiagu
Uses special library to hide executable bytecode.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Displays its own windows over windows of other applications.