Technical information
Malicious functions:
Sends SMS:
- 18317120553: <SMS Address>向你监控的手机发来了信息,内容为:<SMS Content>
- 18317120553: 汗血宝马提示:已安装成功,请及时监控!祝您料多多!~
Executes code of the following detected threats:
- Android.SmsSpy.220.origin
Removes app icon from the screen.
Intercepts incoming SMS and terminates the process of their transmission to handlers of other apps.
Network activity:
Connects to:
- UDP(DNS) <Google DNS>
- TCP(SMTP) s####.163.com:25
- TCP(TLS/1.0) 1####.217.19.206:443
DNS requests:
- s####.163.com
File system changes:
Creates the following files:
- /data/data/####/.md5
- /data/data/####/.sec_version
- /data/data/####/classes.dex
- /data/data/####/classes.jar
- /data/data/####/com.keeper.manage
- /data/data/####/com.keeper.manage.art
- /data/data/####/libsecexe.x86.so
- /data/data/####/libsecmain.x86.so
Miscellaneous:
Executes the following shell scripts:
- <Package> <Package> -1829196616 0 /data/app/<Package>-1.apk 41 <Package> 49 50
- chmod 755 <Package Folder>/.cache/<Package>
- chmod 755 <Package Folder>/.cache/<Package>.art
Loads the following dynamic libraries:
- libsecexe.x86
Uses administrator priveleges.
Uses special library to hide executable bytecode.
Gets information about phone status (number, IMEI, etc.).
Gets information about active device administrators.
Parses information from SMS.
Gets information about sent/received SMS.