Technical information
Malicious functions:
Removes app icon from the screen.
Network activity:
Connects to:
- TCP(???) gi####.com:443
- UDP(DNS) 8####.8.4.4:53
- UDP(DNS) <Google DNS>
- TCP(TLS/1.0) connect####.gst####.com:443
- TCP(TLS/1.0) www.google####.com:443
- TCP(TLS/1.0) pla####.google####.com:443
- TCP(TLS/1.0) app-mea####.com:443
- TCP(TLS/1.2) 64.2####.162.138:443
- TCP(TLS/1.2) www.google####.com:443
DNS requests:
- app-mea####.com
- connect####.gst####.com
- gi####.com
- pla####.google####.com
- rr3---s####.g####.com
- www.a.sh####.com
- www.google####.com
File system changes:
Creates the following files:
- /data/data/####/config
- /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
- /system/bin/ping -c 1 8.8.8.8
- /system/bin/ping -c 1 www.baidu.com
Uses administrator priveleges.
Accesses the ITelephony private interface.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about active device administrators.
Parses information from SMS.
Gets information about incoming/outgoing calls.
Requests the system alert window permission.
Contains hidden alternative main activities.