Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.SmsBot.439.origin
Gains access to the ITelephony private interface.
Intercepts incoming SMS messages and terminates the process of their transmission to handlers of other applications.
Network activity:
Connecting to:
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) and####.b####.qq.com:80
- TCP(TLS/1.0) www.go####.com:443
DNS requests:
- and####.b####.qq.com
- www.go####.com
HTTP POST requests:
- and####.b####.qq.com/rqd/async
Modified file system:
Creates the following files:
- <Package Folder>/databases/bugly_db_lejiagu-journal
- <Package Folder>/files/local_crash_lock
- <Package Folder>/files/native_record_lock
- <Package Folder>/files/security_info
- <Package Folder>/mix.dex
- <Package Folder>/shared_prefs/legu_900015015.xml
- <Package Folder>/shared_prefs/zzxx.xml
- <Package Folder>/tx_shell/libshella-2.4.2.so
Miscellaneous:
Executes next shell scripts:
- /system/bin/sh -c getprop ro.board.platform
- /system/bin/sh -c type su
- chmod 700 <Package Folder>/tx_shell/libshella-2.4.2.so
- getprop ro.board.platform
- getprop ro.yunos.version
Loads the following dynamic libraries:
- Bugly
- libshella-2.4.2
Uses the following algorithms to encrypt data:
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
- AES-GCM-NoPadding
Uses special library to hide executable bytecode.
Gains access to telephone information (number, imei, etc.).
Displays its own windows over windows of other applications.
Parses information from SMS messages.