Technical information
Malicious functions:
Sends SMS:
- 123456: <SMS Address><SMS Content>
- 123456: <SMS Address>VISA5191 Баланс: 4833.98р. Подробности в мобильном приложении ht
- 123456: Install Success!
- 123456: tp://sberbank.ru/sms/h1
- 123456: 设备管理器激活成功!
- 13051752235: <SMS Address><SMS Content>
- 13051752235: <SMS Address>VISA5191 Баланс: 4833.98р. Подробности в мобильном приложении ht
- 13051752235: Install Success!
- 13051752235: tp://sberbank.ru/sms/h1
- 13051752235: 设备管理器激活成功!
Removes app icon from the screen.
Intercepts incoming SMS and terminates the process of their transmission to handlers of other apps.
File system changes:
Creates the following files:
- /data/data/####/.md5
- /data/data/####/.sec_version
- /data/data/####/classes.dex
- /data/data/####/classes.jar
- /data/data/####/cn.newjobe6.msgfge6
- /data/data/####/cn.newjobe6.msgfge6.art
- /data/data/####/container.dex
- /data/data/####/container.pre_global_config
- /data/data/####/device_id.xml.xml
- /data/data/####/libsecexe.x86.so
- /data/data/####/libsecmain.x86.so
Miscellaneous:
Executes the following shell scripts:
- <Package> <Package> -1828795208 0 /data/app/<Package>-1.apk 41 <Package> 50 51
- chmod 755 <Package Folder>/.cache/<Package>
- chmod 755 <Package Folder>/.cache/<Package>.art
Loads the following dynamic libraries:
- libsecexe.x86
Uses administrator priveleges.
Uses special library to hide executable bytecode.
Gets information about phone status (number, IMEI, etc.).
Gets information about active device administrators.
Displays its own windows over windows of other apps.
Parses information from SMS.