Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.DownLoader.455.origin
- Android.DownLoader.570.origin
Network activity:
Connecting to:
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) 1####.200.221.131:8080
- TCP(HTTP/1.1) 1####.57.218.214:8080
- TCP i2.jiz####.com:7702
- TCP p2.jz####.com:7803
- TCP p1.jz####.com:7801
- TCP i1.jiz####.com:7701
- TCP p2.jz####.com:7802
- TCP i3.jiz####.com:7703
DNS requests:
- i1.jiz####.com
- i2.jiz####.com
- i3.jiz####.com
- p1.jz####.com
- p2.jz####.com
- p3.jz####.com
HTTP GET requests:
- 1####.200.221.131:8080/spotService/a.jsp?k=####
- 1####.57.218.214:8080/jfservice/a.jsp?k=####
Modified file system:
Creates the following files:
- /data/data/####/01522498989691.jar
- /data/data/####/01522499016612.jar
- /data/data/####/1000.xml
- /data/data/####/E_ID356507059351895.db-journal
- /data/data/####/a1.db-journal
- /data/data/####/a1.xml
- /data/data/####/a1356507059351895.xml
- /data/data/####/b.xml
- /data/data/####/b1356507059351895.xml
- /data/data/####/c1356507059351895.xml
- /data/data/####/i.xml
- /data/data/####/i_fionf_pre356507059351895.xml
Miscellaneous:
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.