Technical information
Malicious functions:
Removes its shortcut from the home screen.
Intercepts incoming SMS messages and terminates the process of their transmission to handlers of other applications.
Network activity:
Connecting to:
- UDP(DNS) <Google DNS>
- TCP(TLS/1.0) 1####.217.17.142:443
- TCP(TLS/1.0) api.tele####.org:443
DNS requests:
- api.tele####.org
Modified file system:
Creates the following files:
- <Package Folder>/cache/1
- <Package Folder>/cache/2
- <Package Folder>/cache/3
- <Package Folder>/cache/4
- <Package Folder>/cache/5
- <Package Folder>/cache/6
- <Package Folder>/cache/7
- <Package Folder>/cache/8
- <Package Folder>/no_backup/com.google.android.gms.appid-no-backup
- <Package Folder>/shared_prefs/com.google.android.gms.appid.xml
- <Package Folder>/shared_prefs/com.google.android.gms.measurement.prefs.xml
Miscellaneous:
Uses administrator priveleges.
Gains access to interfaces of audio/video data writing.
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.
Parses information from SMS messages.
Gains access to information about sent/received SMS messages.