Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.DownLoader.3394
- Android.DownLoader.635.origin
Network activity:
Connecting to:
- UDP(DNS) <Google DNS>
- TCP(TLS/1.0) ssl.google-####.com:443
DNS requests:
- c.appj####.com
- ssl.google-####.com
Modified file system:
Creates the following files:
- <Package Folder>/.jiagu/libjiagu.so
- <Package Folder>/app_zs/<Package>.apk
- <Package Folder>/cache/ads-1253961947.jar
- <Package Folder>/databases/google_analytics_v2.db-journal
- <Package Folder>/databases/google_analytics_v4.db-journal
- <Package Folder>/files/####/.jg.ic
- <Package Folder>/files/gaClientId
- <Package Folder>/shared_prefs/ad_show_time.xml
- <Package Folder>/shared_prefs/jg_app_update_settings_random.xml
Miscellaneous:
Executes next shell scripts:
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
Loads the following dynamic libraries:
- libjiagu
Uses special library to hide executable bytecode.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Displays its own windows over windows of other applications.