Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.Locker.1328.origin
- Android.Locker.1364.origin
Removes app icon from the screen.
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) 1####.21.10.142:443
- TCP(TLS/1.0) 1####.251.36.42:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) 1####.251.36.10:443
- TCP(TLS/1.0) android####.go####.com:443
- TCP(TLS/1.0) 1####.21.10.142:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.2) 1####.251.36.10:443
- TCP(TLS/1.2) 1####.250.179.206:443
- TCP(TLS/1.2) 1####.250.179.195:443
- TCP(TLS/1.2) 1####.251.36.42:443
- UDP 1####.251.36.42:443
DNS requests:
- and####.google####.com
- android####.go####.com
- m####.go####.com
- md####.google####.com
- www.google####.com
- zip####.ru
HTTP POST requests:
- 1####.21.10.142:443/app/v1
File system changes:
Creates the following files:
- /data/data/####/WIMDtFWbA.dex
- /data/data/####/WIMDtFWbA.dex.flock (deleted)
- /data/data/####/WebViewChromiumPrefs.xml
- /data/data/####/com.nsImWBSkvJhtII.xml
- /data/data/####/com.nsImWBSkvJhtII_preferences.xml
- /data/data/####/fPDHEYbCMszdSUf.dex
- /data/data/####/fPDHEYbCMszdSUf.dex.flock (deleted)
- /data/data/####/index
- /data/data/####/metrics_guid
- /data/data/####/the-real-index
Miscellaneous:
Gets information about network.
Displays its own windows over windows of other apps.
Requests the system alert window permission.