Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.DownLoader.3394
- Android.DownLoader.635.origin
Modified file system:
Creates the following files:
- <Package Folder>/.jiagu/libjiagu.so
- <Package Folder>/app_xfrcdfsk/<Package>.apk
- <Package Folder>/files/####/.jg.ic
- <Package Folder>/shared_prefs/ad_show_time.xml
- <Package Folder>/shared_prefs/jg_app_update_settings_random.xml
- <Package Folder>/shared_prefs/jg_app_update_settings_random.xml.bak
- <Package Folder>/shared_prefs/quit.xml
- <SD-Card>/Users/image1637.jpg
Miscellaneous:
Executes next shell scripts:
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
Loads the following dynamic libraries:
- libjiagu
Uses special library to hide executable bytecode.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Displays its own windows over windows of other applications.