Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Xiny.73.origin
Network activity:
Connecting to:
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) www.okyes####.com:8081
- TCP(HTTP/1.1) www.koapk####.com:8081
DNS requests:
- www.koapk####.com
- www.okyes####.com
HTTP POST requests:
- www.koapk####.com:8081/sm/sr/rt/ry
- www.okyes####.com:8081/sdk/nsd.action?b=####
Modified file system:
Creates the following files:
- <Package Folder>/databases/bdownloaders.db-journal
- <Package Folder>/databases/swith1014.db-journal
- <Package Folder>/files/201803061950.apk
- <Package Folder>/files/c201803061950.apk
- <Package Folder>/shared_prefs/20160121.xml
- <Package Folder>/shared_prefs/Q2hhbm5lbElES2V5MjAxNjEyMjcxODU3.xml
- <Package Folder>/shared_prefs/ag.xml
- <Package Folder>/shared_prefs/duspf6030945.xml
Miscellaneous:
Executes next shell scripts:
- c201803061950.apk -c <Package>:oat
- chmod 6777 <Package Folder>/files/c201803061950.apk
- logcat -d -v time
- sh
Loads the following dynamic libraries:
- com.awa.baw
Uses the following algorithms to encrypt data:
- AES-CBC-PKCS5Padding
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Adds tasks to the system scheduler.