Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.BankBot.678.origin
Overlays the screen with its own window and blocks GUI access.
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.0) rr2---s####.g####.com:443
- TCP(TLS/1.0) gmscomp####.google####.com:443
- TCP(TLS/1.0) 64.2####.161.113:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) app-mea####.com:443
- TCP(TLS/1.2) 64.2####.165.95:443
- TCP(TLS/1.2) 64.2####.165.94:443
- UDP rr1---s####.g####.com:443
- UDP 64.2####.165.95:443
- UDP p####.google####.com:443
- UDP rr2---s####.g####.com:443
DNS requests:
- and####.a####.go####.com
- and####.google####.com
- app-mea####.com
- gmscomp####.google####.com
- p####.google####.com
- rr1---s####.g####.com
- rr2---s####.g####.com
File system changes:
Creates the following files:
- /data/data/####/lbvclefiqx.dex
- /data/data/####/lbvclefiqx.dex.flock (deleted)
- /data/data/####/lbvclefiqx.jar
- /data/misc/####/primary.prof
Miscellaneous:
Uses administrator priveleges.
Gets information about phone status (number, IMEI, etc.).
Gets information about active device administrators.
Gets information about installed apps.
Adds tasks to the system scheduler.
Parses information from SMS.
Gets information about sent/received SMS.
Requests the system alert window permission.