Technical information
Malicious functions:
Sends SMS:
- 0046769438867: 1654737130
Removes app icon from the screen.
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(HTTP/1.1) www.miakhal####.com:80
- TCP(TLS/1.0) 1####.251.36.46:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.2) 1####.251.36.3:443
- UDP rr5---s####.g####.com:443
- UDP rr4---s####.g####.com:443
- UDP rr2---s####.g####.com:443
- UDP www.google####.com:443
DNS requests:
- and####.google####.com
- gmscomp####.google####.com
- m####.go####.com
- miakhal####.com
- p####.google####.com
- rr2---s####.g####.com
- rr4---s####.g####.com
- rr5---s####.g####.com
- www.google####.com
- www.miakhal####.com
HTTP GET requests:
- www.miakhal####.com/upload2.php?getnull=####&name=####
- www.miakhal####.com/upload2.php?init=####&name=####
- www.miakhal####.com/upload2.php?rename=####&name=####
HTTP POST requests:
- www.miakhal####.com/upload2.php?name=####
File system changes:
Creates the following files:
- /data/anr/traces.txt
- /data/data/####/myPrefsKey.xml
- /data/media/####/PhoneNumber.txt
- /data/media/####/accounts.txt
- /data/media/####/contacts.csv
- /data/media/####/installed_apps.txt
- /data/media/####/msgdata.csv
- /data/media/####/msgdatasent.csv
Miscellaneous:
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.
Gets information about sent/received SMS.