Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.CoinMine.27.origin
Network activity:
Connects to:
- UDP(DNS) <Google DNS>
- TCP(TLS/1.0) api.i####.is:443
- TCP(TLS/1.0) apta####.fud####.xyz:8443
DNS requests:
- api.i####.is
- apta####.fud####.xyz
HTTP GET requests:
- api.i####.is:443/
HTTP POST requests:
- apta####.fud####.xyz:8443/api/v0/event
File system changes:
Creates the following files:
- /com.aepzgcm.xofmnf/files/CZ
- /com.aepzgcm.xofmnf/files/brjsupfx
- /com.aepzgcm.xofmnf/files/images
- /data/user/####/FirebaseHeartBeatW0RFRkFVTFRd+MTozODkyNzY5Mzc3M...Nh.xml
- /data/user/####/Pljpan1tvds.xml
- /data/user/####/brjsupfx
- /data/user/####/com.google.android.gms.appid-no-backup
- /data/user/####/com.google.firebase.messaging.xml
- /data/user/####/ic_google_play
- /data/user/####/images
- /data/user/####/reporter.xml
Miscellaneous:
Executes the following shell scripts:
- /system/bin/su
Loads the following dynamic libraries:
- liblydois
Uses elevated priveleges.
Displays its own windows over windows of other apps.
Appears corrupted in a way typical for malicious files.
Attempts to detect sandbox environment.