Technical information
Malicious functions:
Overlays the screen with its own window and blocks GUI access.
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(TLS/1.0) 1####.217.168.202:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.2) p####.google####.com:443
- TCP(TLS/1.2) 1####.251.36.46:443
- UDP p####.google####.com:443
DNS requests:
- m####.go####.com
- p####.google####.com
File system changes:
Creates the following files:
- /data/data/####/installed.xml
- /data/data/####/installed.xml.bak
Miscellaneous:
Changes volume and vibration settings.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.
Gets information about sent/received SMS.
Requests the system alert window permission.