Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.MobiDash.20.origin
Removes app icon from the screen.
File system changes:
Creates the following files:
- /data/data/####/1460683162801.jar
- /data/data/####/1460683162801.tmp
- /data/data/####/MultiDex.lock
- /data/data/####/YBEhvCzIW
- /data/data/####/com.freshtechnology.freshtasks20_migrationpreferences.xml
- /data/data/####/com.freshtechnology.freshtasks20_preferences.xml
- /data/data/####/freshtasks20.dat.jar
- /data/data/####/metrica_client_data.db
- /data/data/####/metrica_client_data.db-journal
- /data/data/####/metrica_client_data.db.lock
- /data/data/####/multidex.version.xml
- /data/data/####/webview.db-journal
- /data/data/####/webviewCookiesChromium.db-journal
Miscellaneous:
Loads the following dynamic libraries:
- YBEhvCzIW
Uses the following algorithms to encrypt data:
- AES-CBC-PKCS5Padding
Uses the following algorithms to decrypt data:
- AES-CBC-PKCS5Padding
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.