Technical information
Malicious functions:
Executes code of the following detected threats:
- Adware.Dowgin.3.origin
- Android.DownLoader.540.origin
Network activity:
Connects to:
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) bi.ji.bj####.com:80
DNS requests:
- bi.ji.bj####.com
HTTP POST requests:
- bi.ji.bj####.com/7148l
- bi.ji.bj####.com/e1e5/g91
File system changes:
Creates the following files:
- /data/data/####/613e7564.xml
- /data/data/####/_w1032862130.xml
- /data/data/####/ads2042149746.jar
- /data/data/####/com.asdfjoas.dfkjasdi.zmh.jar
- /data/data/####/comasdfjoasdfkjasdignpqc.jar
- /data/data/####/data_0
- /data/data/####/data_1
- /data/data/####/data_2
- /data/data/####/data_3
- /data/data/####/index
- /data/data/####/spaceware.flux.camwqqqlvvtofplkwvqmn_preferences.xml
- /data/data/####/ultracam-journal
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
Miscellaneous:
Uses the following algorithms to encrypt data:
- DES
Uses the following algorithms to decrypt data:
- AES-CBC-PKCS5Padding
- DES
Accesses camera interface.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Displays its own windows over windows of other apps.