Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.MobiDash.20.origin
Removes app icon from the screen.
File system changes:
Creates the following files:
- /data/data/####/1460683162801.jar
- /data/data/####/1460683162801.tmp
- /data/data/####/MultiDex.lock
- /data/data/####/multidex.version.xml
- /data/data/####/sky.dat.jar
- /data/data/####/twcEkskbw
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
Miscellaneous:
Loads the following dynamic libraries:
- twcEkskbw
Uses the following algorithms to encrypt data:
- AES-CBC-PKCS5Padding
Uses the following algorithms to decrypt data:
- AES-CBC-PKCS5Padding
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.