Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.RemoteCode.907
Network activity:
Connecting to:
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) www.gst####.com:80
- TCP(HTTP/1.1) t0.gst####.com:80
- TCP(HTTP/1.1) www.go####.com:80
- TCP(TLS/1.0) 1####.217.17.142:443
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) t0.gst####.com:443
- TCP(TLS/1.0) www.go####.nl:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) adser####.go####.com:443
DNS requests:
- adser####.go####.com
- ssl.gst####.com
- t0.gst####.com
- www.go####.com
- www.go####.nl
- www.gst####.com
HTTP GET requests:
- t0.gst####.com/images?q=####
- www.go####.com/
- www.go####.com/async/promos?ei=####&yv=####&async=####
- www.go####.com/complete/search?hl=####&client=####&q=####
- www.go####.com/complete/search?q####&cp=####&client=####&xssi=####&hl=##...
- www.go####.com/complete/search?q=####&cp=####&client=####&xssi=####&hl=#...
- www.go####.com/favicon.ico
- www.go####.com/fp_204?atyp=####&ct=####&cad=####&ptt=####&ptid=####&clie...
- www.go####.com/gen_204?atyp=####&ct=####&cad=####&ogsr=####&id=####&ic=#...
- www.go####.com/gen_204?atyp=####&ct=####&cad=####&tt=####&ei=####&zx=####
- www.go####.com/gen_204?atyp=####&ei=####&s=####&jsi=####&zx=####
- www.go####.com/gen_204?atyp=####&ei=####&s=####&t=####&imn=####&adh=####...
- www.go####.com/gen_204?s=####&t=####&atyp=####&ei=####&rt=####
- www.go####.com/images/branding/googlelogo/2x/googlelogo_color_160x56dp.png
- www.go####.com/images/hpp/gsa_super_g-64.gif
- www.go####.com/images/nav_logo242.png
- www.go####.com/images/searchbox_sprites283_hr.webp
- www.go####.com/xjs/_/js/k=xjs.qs.nl.09eXwR686S8.O/am=BIBFsgMgCCDgUIICECX...
- www.go####.com/xjs/_/js/k=xjs.qs.nl.LR-XX5dXrHY.O/m=sx,ByqdBd,CiVnBc,Fkg...
- www.gst####.com/gb/images/qi1_36e7b564.png
Modified file system:
Creates the following files:
- /data/data/####/.edata
- /data/data/####/classes.dex
- /data/data/####/classes.dex (deleted)
- /data/data/####/classes.dve
- /data/data/####/classes.jar
- /data/data/####/com.SecShell.tmp2290
- /data/data/####/com.SecShell.tmp2573
- /data/data/####/com.SecShell.tmp2597
Miscellaneous:
Loads the following dynamic libraries:
- SecShell
Uses special library to hide executable bytecode.