Technical information
Malicious functions:
Overlays the screen with its own window and blocks GUI access.
Removes app icon from the screen.
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) 8####.8.4.4:53
- TCP(TLS/1.0) and####.google####.com:443
- TCP(TLS/1.0) and####.a####.go####.com:443
- TCP(TLS/1.0) 64.2####.163.95:443
- TCP(TLS/1.0) 64.2####.161.94:443
- TCP(TLS/1.0) gmscomp####.google####.com:443
- TCP(TLS/1.0) rr1---s####.g####.com:443
- TCP(TLS/1.0) 64.2####.161.100:443
- TCP(TLS/1.0) rr3---s####.g####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) 2####.85.233.100:443
- TCP(TLS/1.2) 64.2####.163.95:443
- TCP(TLS/1.2) 64.2####.161.94:443
- UDP 64.2####.163.95:443
- UDP rr1---s####.g####.com:443
- UDP p####.google####.com:443
- UDP rr2---s####.g####.com:443
DNS requests:
- and####.a####.go####.com
- and####.google####.com
- gmscomp####.google####.com
- p####.google####.com
- rr1---s####.g####.com
- rr2---s####.g####.com
- rr3---s####.g####.com
Miscellaneous:
Uses administrator priveleges.
Gets information about phone status (number, IMEI, etc.).
Gets information about active device administrators.
Gets information about installed apps.
Adds tasks to the system scheduler.
Parses information from SMS.
Gets information about sent/received SMS.
Requests the system alert window permission.