Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Click.995
Network activity:
Connects to:
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) rq####.sp####.mig.####.net:80
- TCP(HTTP/1.1) 4####.96.49.164:10000
- TCP(HTTP/1.1) pi####.qq.com:80
DNS requests:
- and####.b####.qq.com
- pi####.qq.com
HTTP POST requests:
- pi####.qq.com/mstat/report/?index=####
- rq####.sp####.mig.####.net/rqd/async?aid=####
File system changes:
Creates the following files:
- /data/data/####/.cl
- /data/data/####/.jg.ic
- /data/data/####/1004
- /data/data/####/20201023002316.v1.crash
- /data/data/####/202010230023685.v1.crash
- /data/data/####/bugly_db_-journal
- /data/data/####/com.tgry.j7yr.rqtko.mid.world.ro.xml
- /data/data/####/com.tgry.j7yr.rqtko_preferences.xml
- /data/data/####/crashrecord.xml
- /data/data/####/libjiagu1356313224.so
- /data/data/####/local_crash_lock
- /data/data/####/native_record_lock
- /data/data/####/preferences.xml
- /data/data/####/pri_tencent_analysis.db_com.tgry.j7yr.rqtko-journal
- /data/data/####/security_info
- /data/data/####/tencent_analysis.db_com.tgry.j7yr.rqtko-journal
- /data/media/####/.nomedia
Miscellaneous:
Executes the following shell scripts:
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
- /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
- /system/bin/sh -c getprop
- getprop
- logcat -c
- logcat -d -v threadtime
- logcat -d -v time
Loads the following dynamic libraries:
- Bugly
- MtaNativeCrash_v2
- X86Bridge
- libjiagu1356313224
- realm-jni
Uses the following algorithms to encrypt data:
- AES-GCM-NoPadding
- RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
- AES-GCM-NoPadding
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.