Technical information
Malicious functions:
Sends SMS:
- +1280: DA MOGA
- +1280: MOGA
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) rr1---s####.g####.com:443
- TCP(TLS/1.0) connect####.gst####.com:443
- TCP(TLS/1.0) onesi####.com:443
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.2) connect####.gst####.com:443
- TCP(TLS/1.2) www.google####.com:443
- TCP www.google####.com:443
DNS requests:
- and####.a####.go####.com
- connect####.gst####.com
- m####.go####.com
- onesi####.com
- rr1---s####.g####.com
- www.google####.com
HTTP GET requests:
- onesi####.com:443/api/v1/apps/036d0e5b-6616-40fa-8c3c-5c68d1e05032/andro...
File system changes:
Creates the following files:
- /data/data/####/GTPlayerPurchases.xml
- /data/data/####/OneSignal.db-journal
- /data/data/####/h0.xml
- /data/data/####/isSMS.xml
- /data/misc/####/primary.prof
Miscellaneous:
Contains functionality for automatic SMS sending.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Displays its own windows over windows of other apps.
Parses information from SMS.