Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Mobifun.11.origin
Accesses the ITelephony private interface.
Network activity:
Connects to:
- UDP(DNS) <Google DNS>
- TCP(TLS/1.0) ssl.gst####.com:443
- TCP(TLS/1.0) www.go####.nl:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) www.gst####.com:443
- TCP(TLS/1.0) adser####.go####.com:443
DNS requests:
- adser####.go####.com
- ssl.gst####.com
- www.go####.com
- www.go####.nl
- www.gst####.com
File system changes:
Creates the following files:
- /data/data/####/AdIdsFile.rlck
- /data/data/####/PluginFile.rlck
- /data/data/####/SharedPayFile.bak
- /data/data/####/SharedPayFile.rlck
- /data/data/####/SharedPayFile.wlck
- /data/data/####/a000312.xml
- /data/data/####/db2.jar
- /data/data/####/gaClientId
- /data/data/####/google_analytics_v2.db-journal
- /data/data/####/gpmpclasses.jar
- /data/data/####/gpmpsdk.so
- /data/data/####/gpsetting.xml
- /data/data/####/gsetting.xml
- /data/data/####/item.xml
- /data/data/####/mpsetting.xml
- /data/data/####/payitem_2.xml
Miscellaneous:
Executes the following shell scripts:
- cat /proc/cpuinfo
- ps adbd
- ps logcat
Loads the following dynamic libraries:
- gpmpsdk
Uses the following algorithms to encrypt data:
- AES-CBC-PKCS5Padding
- AES-CFB-NoPadding
- AES-ECB-PKCS5Padding
Uses the following algorithms to decrypt data:
- AES
- AES-CBC-PKCS5Padding
- AES-CFB-NoPadding
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.