Technical information
Malicious functions:
Sends SMS messages:
- 17721967513: 2&<SMS Address>&<SMS Content>&
Executes code of the following detected threats:
- Android.SmsBot.439.origin
Intercepts incoming SMS messages and terminates the process of their transmission to handlers of other applications.
Network activity:
Connecting to:
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(SMTP) s####.al####.com:25
DNS requests:
- and####.b####.qq.com
- s####.al####.com
HTTP POST requests:
- and####.b####.qq.com/rqd/async
Modified file system:
Creates the following files:
- <Package Folder>/databases/bugly_db_lejiagu-journal
- <Package Folder>/files/local_crash_lock
- <Package Folder>/files/native_record_lock
- <Package Folder>/files/security_info
- <Package Folder>/mix.dex
- <Package Folder>/shared_prefs/legu_900015015.xml
- <Package Folder>/shared_prefs/zzxx.xml
- <Package Folder>/tx_shell/libshella-2.4.2.so
Miscellaneous:
Executes next shell scripts:
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c type su
- chmod 700 <Package Folder>/tx_shell/libshella-2.4.2.so
- getprop ro.board.platform
- getprop ro.yunos.version
Loads the following dynamic libraries:
- Bugly
- libshella-2.4.2
Uses special library to hide executable bytecode.
Gains access to telephone information (number, imei, etc.).
Displays its own windows over windows of other applications.
Parses information from SMS messages.
Gains access to information about contacts from the Contact list.