Technical information
Malicious functions:
Sends SMS:
- 13457150492: <Phone Number> had installed!!!
- 13457150492: f: <SMS Address> n: <SMS Content>
Executes code of the following detected threats:
- Android.SmsSpy.125.origin
Intercepts incoming SMS and terminates the process of their transmission to handlers of other apps.
Network activity:
Connects to:
- UDP(DNS) <Google DNS>
- TCP(SMTP) s####.126.com:25
DNS requests:
- mt####.go####.com
- s####.126.com
File system changes:
Creates the following files:
- /data/data/####/.md5
- /data/data/####/.sec_version
- /data/data/####/Sender.xml
- /data/data/####/classes.dex
- /data/data/####/classes.jar
- /data/data/####/com.message.send
- /data/data/####/libsecexe.x86.so
- /data/data/####/libsecmain.x86.so
Miscellaneous:
Executes the following shell scripts:
- <Package> <Package> -1828737832 0 /data/app/<Package>-1.apk 41 <Package> 47 48
- <Package> <Package> -1836061480 0 /data/app/<Package>-1.apk 39 <Package> 46 47
- chmod 755 <Package Folder>/.cache/<Package>
Loads the following dynamic libraries:
- libsecexe.x86
Uses administrator priveleges.
Uses special library to hide executable bytecode.
Gets information about phone status (number, IMEI, etc.).
Gets information about active device administrators.
Displays its own windows over windows of other apps.
Parses information from SMS.