Technical information
Malicious functions:
Threat detection based on machine learning.
Contains typical locker code.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) hzy.x####.cn:80
- TCP(TLS/1.0) z.c####.com:443
- TCP(TLS/1.0) gm.mm####.com:443
- TCP(TLS/1.0) 2####.58.211.106:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) c.c####.com:443
- TCP(TLS/1.2) 1####.250.179.163:443
- TCP(TLS/1.2) 1####.217.168.206:443
- UDP 1####.250.179.170:443
DNS requests:
- android####.go####.com
- c####.mm####.com
- c.c####.com
- hzy.x####.cn
- s9.c####.com
- z12.c####.com
HTTP GET requests:
- hzy.x####.cn/favicon.ico
- hzy.x####.cn/index.html
File system changes:
Creates the following files:
- /data/data/####/.jgck
- /data/data/####/40b0ed8eeed0b60b_0
- /data/data/####/645869c41f3ac4f1_0
- /data/data/####/6e245bc38381148e_0
- /data/data/####/Cookies-journal
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/a3fea336a0b9e248_0
- /data/data/####/app.hyz.a_preferences.xml
- /data/data/####/cc37879383962c18_0
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.oat
- /data/data/####/f3e2f321dcd7fbdb_0
- /data/data/####/f3e2f321dcd7fbdb_1
- /data/data/####/index
- /data/data/####/libjiagu.so
- /data/data/####/metrics_guid
- /data/data/####/proc_auxv
- /data/data/####/the-real-index
- /data/media/####/hzy.ttf
Miscellaneous:
Uses the following algorithms to decrypt data:
- AES-CBC-PKCS5Padding
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about installed apps.
Displays its own windows over windows of other apps.