Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Mobifun.11.origin
Network activity:
Connects to:
- UDP(DNS) <Google DNS>
- TCP(TLS/1.0) api.a####.com:443
DNS requests:
- api.a####.com
File system changes:
Creates the following files:
- /data/data/####/a.xml
- /data/data/####/com.test.pay_preferences.xml
- /data/data/####/gmpclasses.jar
- /data/data/####/gpay_jquery_1_3.ap
- /data/data/####/gpay_jquery_3_1_classes.jar
- /data/data/####/gpay_pay_event_2_3.ap
- /data/data/####/gpay_pay_event_3_2_classes.jar
- /data/data/####/gpay_pay_sms_2_3.ap
- /data/data/####/gpay_pay_sms_3_2_classes.jar
- /data/data/####/gpay_pay_wap_2_3.ap
- /data/data/####/gpay_pay_wap_3_2_classes.jar
- /data/data/####/jquery_1_3.applet
- /data/data/####/la.so
- /data/data/####/pay_event_2_3.applet
- /data/data/####/pay_sms_2_3.applet
- /data/data/####/pay_wap_2_3.applet
Miscellaneous:
Executes the following shell scripts:
- cat /proc/cpuinfo
- ps adbd
- ps logcat
Loads the following dynamic libraries:
- la
- pay
Uses the following algorithms to encrypt data:
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
- AES
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-CFB-NoPadding
- RSA-ECB-PKCS1Padding
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.