Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.RemoteCode.178.origin
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
- UDP(DNS) <Google DNS>
- TCP(TLS/1.0) api.s####.1####.com:443
- TCP(TLS/1.0) 1####.217.17.78:443
DNS requests:
- api.unm####.u17888####.com
Modified file system:
Creates the following files:
- /data/data/####/external.apk
- /data/data/####/external.so
- /data/data/####/external_dex.apk
- /data/data/####/external_dex.so
- /data/data/####/mid.dex
- /data/data/####/moduleinfos
- /data/data/####/not-virus-test-appidb7db56a93ae44c5f15e119091c9...sp.xml
- /data/data/####/u3kmid.db-journal
- /data/media/####/sub_imei.txt
Miscellaneous:
Executes next shell scripts:
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
Uses the following algorithms to encrypt data:
- AES-ECB-PKCS5Padding
Uses the following algorithms to decrypt data:
- AES-CBC-PKCS5Padding
- AES-ECB-PKCS5Padding
Gains access to geolocation.
Gains access to telephone information (number, IMEI, etc.).
Displays its own windows over windows of other applications.