Technical information
Malicious functions:
Overlays the screen with its own window and blocks GUI access.
Removes app icon from the screen.
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) gmscomp####.google####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.2) www.google####.com:443
- TCP(TLS/1.2) 64.2####.164.100:443
- TCP(TLS/1.2) 1####.251.1.139:443
- TCP(TLS/1.2) 1####.194.222.94:443
- UDP www.google####.com:443
- UDP rr2---s####.g####.com:443
- UDP rr1---s####.g####.com:443
- UDP p####.google####.com:443
DNS requests:
- and####.a####.go####.com
- and####.google####.com
- gmscomp####.google####.com
- m####.go####.com
- p####.google####.com
- rr1---s####.g####.com
- rr2---s####.g####.com
- www.google####.com
File system changes:
Creates the following files:
- /data/misc/####/primary.prof
Miscellaneous:
Uses administrator priveleges.
Gets information about phone status (number, IMEI, etc.).
Gets information about active device administrators.
Gets information about installed apps.
Adds tasks to the system scheduler.
Parses information from SMS.
Gets information about sent/received SMS.
Requests the system alert window permission.