Technical information
Malicious functions:
Sends SMS:
- +4915706100047: A:48o2'N.2o20'E
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(TLS/1.0) 64.2####.161.95:443
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) rr1---s####.g####.com:443
- TCP(TLS/1.0) 1####.251.1.139:443
- TCP(TLS/1.0) md####.google####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) 1####.177.14.95:443
- TCP(TLS/1.2) 1####.177.14.95:443
- TCP(TLS/1.2) 64.2####.165.94:443
- UDP 1####.177.14.95:443
- UDP rr3---s####.g####.com:443
- UDP rr5---s####.g####.com:443
- UDP rr1---s####.g####.com:443
- UDP p####.google####.com:443
DNS requests:
- and####.a####.go####.com
- and####.google####.com
- m####.go####.com
- md####.google####.com
- p####.google####.com
- rr1---s####.g####.com
- rr3---s####.g####.com
- rr5---s####.g####.com
File system changes:
Creates the following files:
- /data/data/####/SecurityService.xml
Miscellaneous:
Contains functionality for automatic SMS sending.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.
Parses information from SMS.
Gets information about sent/received SMS.