Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Xiny.73.origin
Network activity:
Connecting to:
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) www.okyes####.com:8081
- TCP(HTTP/1.1) www.koapk####.com:8081
DNS requests:
- www.koapk####.com
- www.okyes####.com
HTTP POST requests:
- www.koapk####.com:8081/sm/sr/rt/ry
- www.okyes####.com:8081/sdk/nsd.action?b=####
Modified file system:
Creates the following files:
- <Package Folder>/databases/bdownloaders.db-journal
- <Package Folder>/databases/swith1014.db-journal
- <Package Folder>/files/201803071150.apk
- <Package Folder>/files/c201803071150.apk
- <Package Folder>/shared_prefs/20160121.xml
- <Package Folder>/shared_prefs/Q2hhbm5lbElES2V5MjAxNjEyMjcxODU3.xml
- <Package Folder>/shared_prefs/ag.xml
- <Package Folder>/shared_prefs/duspf6030945.xml
Miscellaneous:
Executes next shell scripts:
- c201803071150.apk -c <Package>:zewa
- logcat -d -v time
- ps
- sh
Loads the following dynamic libraries:
- cn.omoz.czowm
Uses the following algorithms to encrypt data:
- AES-CBC-PKCS5Padding
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Adds tasks to the system scheduler.