Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Mobifun.11.origin
Network activity:
Connects to:
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) st####.a####.com:80
- TCP(TLS/1.0) 1####.217.17.110:443
- TCP(TLS/1.0) api.higam####.com:443
DNS requests:
- api.higam####.com
- sn####.iapp####.com
- st####.a####.com
HTTP GET requests:
- st####.a####.com/sdk/276/5b207dcd883b0.zip
File system changes:
Creates the following files:
- /data/data/####/a.xml
- /data/data/####/c0004105.xml
- /data/data/####/cbsp.jar
- /data/data/####/com.sfeehha.bubble419_preferences.xml
- /data/data/####/frozenbubble.xml
- /data/data/####/gpay_jquery_1_6.ap
- /data/data/####/gpay_jquery_6_1_classes.jar
- /data/data/####/gpay_pay_event_5_6.ap
- /data/data/####/gpay_pay_event_6_5_classes.jar
- /data/data/####/gpay_pay_sms_4_6.ap
- /data/data/####/gpay_pay_sms_6_4_classes.jar
- /data/data/####/gpay_res.apk
- /data/data/####/jquery_1_6.applet
- /data/data/####/la.so
- /data/data/####/pay_event_5_6.applet
- /data/data/####/pay_sms_4_6.applet
- /data/data/####/snowplowEvents.sqlite
- /data/data/####/snowplowEvents.sqlite-journal
- /data/data/####/unsent_requests
- /data/media/####/5b207dcd883b0.zip.tmp
- /data/media/####/R4GE1dRibjZZ1S
- /data/media/####/gptrxsn.bak
- /data/media/####/gptrxsn.lock
- /data/media/####/gptrxsn.rlck
- /data/media/####/gptrxsn.wlck
Miscellaneous:
Executes the following shell scripts:
- cat /proc/cpuinfo
Loads the following dynamic libraries:
- bsport
- la
Uses the following algorithms to encrypt data:
- AES
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-CFB-NoPadding
- RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
- AES
- AES-CBC-NoPadding
- AES-CBC-PKCS5Padding
- AES-CFB-NoPadding
- RSA-ECB-PKCS1Padding
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.