Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Mobifun.11.origin
Network activity:
Connecting to:
- UDP(DNS) <Google DNS>
- TCP(TLS/1.0) 1####.217.17.142:443
- TCP(TLS/1.0) ssl.google-####.com:443
- TCP(TLS/1.0) api.al1c####.com:443
DNS requests:
- api.al1c####.com
- ssl.google-####.com
Modified file system:
Creates the following files:
- /data/data/####/a.xml
- /data/data/####/api-plugin_1_104_.jar
- /data/data/####/com.mobile.sound_recorder_preferences.xml
- /data/data/####/gaClientId
- /data/data/####/gmpclasses.jar
- /data/data/####/google_analytics_v2.db-journal
- /data/data/####/gpay_jquery_1_4.ap
- /data/data/####/gpay_jquery_4_1_classes.jar
- /data/data/####/jquery_1_4.applet
- /data/data/####/la.so
Miscellaneous:
Executes next shell scripts:
- cat /proc/cpuinfo
- ps adbd
- ps logcat
Loads the following dynamic libraries:
- gamesCore
- la
Uses the following algorithms to encrypt data:
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
- AES
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-CFB-NoPadding
- RSA-ECB-PKCS1Padding
Gains access to network information.
Gains access to telephone information (number, imei, etc.).