Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Locker.1328.origin
- Android.Locker.1360.origin
Removes app icon from the screen.
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(TLS/1.0) 2####.58.214.10:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) safebro####.google####.com:443
- TCP(TLS/1.0) zip####.ru:443
- TCP(TLS/1.2) 1####.250.179.163:443
- TCP(TLS/1.2) 1####.250.179.206:443
- TCP(TLS/1.2) 2####.58.214.10:443
- UDP 2####.58.214.10:443
DNS requests:
- m####.go####.com
- md####.google####.com
- safebro####.google####.com
- zip####.ru
File system changes:
Creates the following files:
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/com.hlcogwKRbrUHuG.xml
- /data/data/####/com.hlcogwKRbrUHuG_preferences.xml
- /data/data/####/index
- /data/data/####/mTlpMCTiqiwkfk.dex
- /data/data/####/mTlpMCTiqiwkfk.dex.flock (deleted)
- /data/data/####/metrics_guid
- /data/data/####/oSKHhxHl.dex
- /data/data/####/oSKHhxHl.dex.flock (deleted)
- /data/data/####/the-real-index
- /data/misc/####/primary.prof
Miscellaneous:
Gets information about network.
Displays its own windows over windows of other apps.
Requests the system alert window permission.