Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Locker.1328.origin
- Android.Locker.1352.origin
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) 2####.107.219.160:1081
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) mmd####.ru:443
- TCP(TLS/1.0) 74.1####.131.95:443
- TCP(TLS/1.0) cou####.y####.ru:443
- TCP(TLS/1.0) bom####.ru:443
- TCP(TLS/1.0) 1####.217.168.234:443
- TCP(TLS/1.0) instant####.google####.com:443
- TCP(TLS/1.2) and####.google####.com:443
- TCP(TLS/1.2) 1####.217.168.234:443
- TCP(TLS/1.2) 64.2####.162.94:443
- TCP(TLS/1.2) 2####.85.233.102:443
DNS requests:
- and####.google####.com
- bom####.ru
- cou####.y####.ru
- instant####.google####.com
- mmd####.ru
File system changes:
Creates the following files:
- /data/data/####/2b0b3b561c0ba7c1_0
- /data/data/####/2cd68813aa5e80fc_0
- /data/data/####/331ef2d6a69b9873_0
- /data/data/####/415a3c2f1118935b_0
- /data/data/####/749cbbe99006f267_0
- /data/data/####/7aae68096ec898e5_0
- /data/data/####/CCEokXuoF.dex
- /data/data/####/CCEokXuoF.dex.flock (deleted)
- /data/data/####/Cookies-journal
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/bTtGCCECxAtF.dex
- /data/data/####/bTtGCCECxAtF.dex.flock (deleted)
- /data/data/####/com.kQocgUdpOR.xml
- /data/data/####/com.kQocgUdpOR_preferences.xml
- /data/data/####/f10d74c0f86155c5_0
- /data/data/####/https_mmdemka.ru_0.localstorage-journal
- /data/data/####/index
- /data/data/####/metrics_guid
- /data/data/####/the-real-index
- /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86_64 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86_64 --instruction-set-features=default --dex-file=/data/user/0/<Package>/app_tmp/CCEokXuoF.dex --oat-fd=33 --oat-location=/data/user/0/<Package>/app_outDex/CCEokXuoF.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86_64 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86_64 --instruction-set-features=default --dex-file=/data/user/0/<Package>/app_tmp/bTtGCCECxAtF.dex --oat-fd=33 --oat-location=/data/user/0/<Package>/app_outDex/bTtGCCECxAtF.dex --compiler-filter=speed
Gets information about network.
Displays its own windows over windows of other apps.
Requests the system alert window permission.