Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Locker.1328.origin
- Android.Locker.1364.origin
Removes app icon from the screen.
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) 1####.67.131.128:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) 1####.67.131.128:443
- TCP(TLS/1.0) 1####.217.168.234:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.2) 1####.250.179.206:443
- TCP(TLS/1.2) 1####.250.179.195:443
- TCP(TLS/1.2) 1####.250.179.202:443
- TCP(TLS/1.2) md####.google####.com:443
- UDP md####.google####.com:443
DNS requests:
- android####.go####.com
- m####.go####.com
- md####.google####.com
- zip####.ru
HTTP POST requests:
- 1####.67.131.128:443/app/v1
File system changes:
Creates the following files:
- /data/data/####/FnRnBGfj.dex
- /data/data/####/FnRnBGfj.dex.flock (deleted)
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/com.jPwqvOgAYYJxxH.xml
- /data/data/####/com.jPwqvOgAYYJxxH_preferences.xml
- /data/data/####/index
- /data/data/####/metrics_guid
- /data/data/####/oLOOfNLFIvkuxJ.dex
- /data/data/####/oLOOfNLFIvkuxJ.dex.flock (deleted)
- /data/data/####/the-real-index
Miscellaneous:
Gets information about network.
Displays its own windows over windows of other apps.
Requests the system alert window permission.