Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.DownLoader.192.origin
Gains access to the ITelephony private interface.
Modified file system:
Creates the following files:
- /data/data/####/Downloado
- /data/data/####/Downloado-journal
- /data/data/####/ads-689536943.jar
- /data/data/####/ads142183397.jar
- /data/data/####/configo.xml
- /data/data/####/iConfig.xml
- /data/data/####/iDownload-journal
- /data/data/####/webview.db-journal
- /data/media/####/com.qiang.linek.a.dex
- /data/media/####/com.qiang.linek.a.dex (deleted)
- /data/media/####/com.xineba.a.dex
- /data/media/####/com.yandong.a.dex
- /data/media/####/download.db
- /data/media/####/download.db-journal
- /data/media/####/id
- /data/media/####/logo.png
- /data/media/####/spot_in.png
Miscellaneous:
Uses the following algorithms to encrypt data:
- DES-CBC-PKCS5Padding
Uses the following algorithms to decrypt data:
- AES-CBC-PKCS5Padding
- AES-CFB-NoPadding
- DES-CBC-PKCS5Padding
Gains access to camera interface.
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.