Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Locker.1274.origin
Threat detection based on machine learning.
Contains typical locker code.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) o####.cn:80
- TCP(HTTP/1.1) t####.s####.cn:80
- TCP(HTTP/1.1) s####.jom####.com:80
- TCP(HTTP/1.1) sdk.51.la.####.com:80
- TCP(HTTP/1.1) api.s####.b####.com:80
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) instant####.google####.com:443
- TCP(TLS/1.0) 2####.58.214.10:443
- TCP(TLS/1.0) 2####.58.208.106:443
- TCP(TLS/1.0) img.al####.com:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.2) www.google####.com:443
- TCP(TLS/1.2) 1####.217.17.142:443
- TCP(TLS/1.2) 1####.250.179.163:443
- TCP(TLS/1.2) 2####.58.214.10:443
DNS requests:
- android####.go####.com
- api.s####.b####.com
- cdn.boo####.net
- collec####.51.la
- img.al####.com
- instant####.google####.com
- m####.go####.com
- md####.google####.com
- o####.cn
- p####.google####.com
- p####.zhanz####.b####.com
- s####.51.la
- t####.s####.cn
- www.google####.com
HTTP GET requests:
- api.s####.b####.com/s.gif?l=/oeps.cn/?up####
- o####.cn/?up####
- o####.cn/css/animate.css
- o####.cn/css/homepage.weui.extra.css
- o####.cn/css/weui.min.css
- o####.cn/js/weui.js
- s####.jom####.com/push.js
- sdk.51.la.####.com/js-sdk-pro.min.js
- t####.s####.cn/index/index/config?id=####
- t####.s####.cn/index/index/notice?id=####
- t####.s####.cn/index/index/version?id=####
- t####.s####.cn/index/task/text?id=####
File system changes:
Creates the following files:
- /data/data/####/.jgck
- /data/data/####/classes.dex
- /data/data/####/classes.dex.flock (deleted)
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.oat
- /data/data/####/libjiagu.so
- /data/data/####/picasso
- /data/data/####/picasso.dex
- /data/data/####/picasso.dex.flock (deleted)
- /data/data/####/proc_auxv
- /data/data/####/util
- /data/data/####/util.dex
- /data/data/####/util.dex.flock (deleted)
- /data/data/####/zip
- /data/data/####/zip.dex
- /data/data/####/zip.dex.flock (deleted)
Miscellaneous:
Executes the following shell scripts:
- /system/bin/dex2oat --instruction-set=x86 --dex-file=<Package Folder>/.jiagu/classes.dex --dex-file=<Package Folder>/.jiagu/classes.dex:classes2.dex --oat-file=<Package Folder>/.jiagu/classes.oat --inline-depth-limit=0 --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/app_iapp_dex/classes.dex --oat-fd=36 --oat-location=/data/user/0/<Package>/app_iapp_odex/classes.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/_RunDex_/picasso --oat-fd=48 --oat-location=/data/user/0/<Package>/files/_RunDex/picasso.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/_RunDex_/util --oat-fd=48 --oat-location=/data/user/0/<Package>/files/_RunDex/util.dex --compiler-filter=speed
- /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/_RunDex_/zip --oat-fd=48 --oat-location=/data/user/0/<Package>/files/_RunDex/zip.dex --compiler-filter=speed
Uses the following algorithms to decrypt data:
- AES-CBC-PKCS5Padding
Uses special library to hide executable bytecode.
Displays its own windows over windows of other apps.