Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Xiny.20
Network activity:
Connecting to:
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) a.sm####.cn:80
- TCP(HTTP/1.1) e.xiongj####.com.cn:80
- TCP(HTTP/1.1) d.weixu####.com.####.com:80
- TCP(HTTP/1.1) 2####.243.193.46:80
DNS requests:
- a.sm####.cn
- d.weixu####.com.cn
- e.xiongj####.com.cn
- mv.65####.com
HTTP GET requests:
- d.weixu####.com.####.com/2011/lvs.jar
HTTP POST requests:
- a.sm####.cn/cw/cp.action?requestId=####&g=####
- e.xiongj####.com.cn/cw/interface!u2.action?protocol=####&version=####&ci...
Modified file system:
Creates the following files:
- <Package Folder>/databases/data-journal
- <Package Folder>/databases/downloadswc
- <Package Folder>/databases/downloadswc-journal
- <Package Folder>/shared_prefs/<Package>_preferences.xml
- <Package Folder>/shared_prefs/W_Key.xml
- <Package Folder>/shared_prefs/a.xml
- <Package Folder>/shared_prefs/info.xml
- <Package Folder>/shared_prefs/st.xml
- <SD-Card>/Download/####/4.6_lvs.jar.t
- <SD-Card>/dt/restime.dat
Miscellaneous:
Loads the following dynamic libraries:
- omb
Gains access to telephone information (number, imei, etc.).
Displays its own windows over windows of other applications.