Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.BankBot.745.origin
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) 1####.21.10.8:443
- TCP(TLS/1.0) 1####.21.10.8:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) 1####.217.168.202:443
- TCP(TLS/1.0) 1####.251.36.10:443
- TCP(TLS/1.2) 1####.250.179.195:443
- TCP(TLS/1.2) 1####.217.168.202:443
- TCP(TLS/1.2) 1####.217.17.42:443
- TCP(TLS/1.2) 1####.217.17.46:443
- TCP(TLS/1.2) 1####.250.153.139:443
- UDP 1####.217.168.202:443
- UDP 1####.217.17.42:443
DNS requests:
- and####.google####.com
- jsonpla####.typi####.com
- m####.go####.com
HTTP POST requests:
- 1####.21.10.8:443/posts
File system changes:
Creates the following files:
- /data/data/####/cPVRA.dex
- /data/data/####/cPVRA.dex.flock (deleted)
- /data/data/####/cPVRA.json
- /data/data/####/ring0.xml
- /data/data/####/ring0.xml.bak
- /data/data/####/ring0.xml.bak (deleted)
- /data/misc/####/primary.prof
Miscellaneous:
Uses administrator priveleges.
Gets information about active device administrators.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.
Gets information about sent/received SMS.
Intercepts notifications.