Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.BankBot.677.origin
Overlays the screen with its own window and blocks GUI access.
Removes app icon from the screen.
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) gmscomp####.google####.com:443
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) rr5---s####.g####.com:443
- TCP(TLS/1.0) 1####.250.150.102:443
- TCP(TLS/1.2) gmscomp####.google####.com:443
- TCP(TLS/1.2) 1####.194.222.113:443
- TCP(TLS/1.2) 1####.250.150.94:443
- UDP gmscomp####.google####.com:443
- UDP p####.google####.com:443
- UDP rr5---s####.g####.com:443
- UDP rr1---s####.g####.com:443
DNS requests:
- and####.a####.go####.com
- and####.google####.com
- gmscomp####.google####.com
- m####.go####.com
- p####.google####.com
- rr1---s####.g####.com
- rr5---s####.g####.com
File system changes:
Creates the following files:
- /data/data/####/.xml
- /data/data/####/dprscfduwy.dex
- /data/data/####/dprscfduwy.dex.flock (deleted)
- /data/data/####/dprscfduwy.jar
- /data/misc/####/primary.prof
Miscellaneous:
Uses administrator priveleges.
Gets information about phone status (number, IMEI, etc.).
Gets information about active device administrators.
Adds tasks to the system scheduler.
Parses information from SMS.
Gets information about sent/received SMS.
Requests the system alert window permission.