Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.BankBot.745.origin
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) 1####.67.189.217:443
- TCP(TLS/1.0) and####.cli####.go####.com:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) 1####.250.179.170:443
- TCP(TLS/1.0) 1####.217.17.42:443
- TCP(TLS/1.0) 1####.67.189.217:443
- TCP(TLS/1.2) 1####.251.36.3:443
- TCP(TLS/1.2) 1####.217.17.42:443
- UDP 1####.250.179.170:443
- UDP 1####.217.17.42:443
DNS requests:
- and####.cli####.go####.com
- jsonpla####.typi####.com
- md####.google####.com
HTTP POST requests:
- 1####.67.189.217:443/posts
File system changes:
Creates the following files:
- /data/data/####/nbOOH.dex
- /data/data/####/nbOOH.dex.flock (deleted)
- /data/data/####/nbOOH.json
- /data/data/####/ring0.xml
- /data/data/####/ring0.xml.bak
- /data/misc/####/primary.prof
Miscellaneous:
Uses administrator priveleges.
Gets information about active device administrators.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.
Gets information about sent/received SMS.
Intercepts notifications.