Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.RemoteCode.337.origin
Network activity:
Connects to:
- TCP(???) arm.modby####.com:10014
- TCP(???) arm.modby####.com:10017
- TCP(???) arm.modby####.com:10012
- TCP(???) arm.modby####.com:443
- UDP(???) p####.google####.com:443
- TCP(???) arm.modby####.com:10018
- UDP(DNS) 8####.8.4.4:53
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) www.go####.com:443
- TCP(TLS/1.0) pla####.google####.com:443
- TCP(TLS/1.0) api####.a####.com.my:443
- TCP(TLS/1.0) in-prod####.traffic####.net:443
- TCP(TLS/1.0) c####.vssclou####.tv:443
- TCP(TLS/1.0) www.go####.com:443
- TCP(TLS/1.0) p####.google####.com:443
- TCP(TLS/1.0) f####.gst####.com:443
- TCP(TLS/1.0) connect####.gst####.com:443
- TCP(TLS/1.0) rr1---s####.g####.com:443
- TCP(TLS/1.2) 74.1####.131.94:443
DNS requests:
- api####.a####.com.my
- arm.modby####.com
- c####.vssclou####.tv
- connect####.gst####.com
- f####.gst####.com
- in-prod####.traffic####.net
- p####.google####.com
- pla####.google####.com
- rr1---s####.g####.com
- www.go####.com
- www.google####.com
HTTP GET requests:
- c####.vssclou####.tv:443/
- c####.vssclou####.tv:443/mvs/minAllowedVersion?platform=####
HTTP HEAD requests:
- api####.a####.com.my:443/ctap/about
- www.go####.com:443/
HTTP POST requests:
- in-prod####.traffic####.net:443/logs?api-version=####
File system changes:
Creates the following files:
- /data/data/####/.fsgkea
- /data/data/####/.jg.ac
- /data/data/####/.jg.ri
- /data/data/####/.jg.store.report_cf
- /data/data/####/.jg.store.report_pid
- /data/data/####/1788527495363_0
- /data/data/####/1788527496233_1
- /data/data/####/1788527511871_0
- /data/data/####/1788527512091_1
- /data/data/####/1788527526101_0
- /data/data/####/1788527526314_1
- /data/data/####/2026-09-04T13;11;19.000Z.events
- /data/data/####/2026-09-04T13;11;32.000Z.events
- /data/data/####/2026-09-04T13;11;44.000Z.events
- /data/data/####/2026-09-04T13;12;00.000Z.events
- /data/data/####/2026-09-04T13;12;17.000Z.events
- /data/data/####/2026-09-04T13;12;25.000Z.events
- /data/data/####/2026_09_04_16_11_19.log
- /data/data/####/2026_09_04_16_11_32.log
- /data/data/####/2026_09_04_16_11_43.log
- /data/data/####/2026_09_04_16_11_59.log
- /data/data/####/2026_09_04_16_12_16.log
- /data/data/####/2026_09_04_16_12_25.log
- /data/data/####/AppCenter.xml
- /data/data/####/classes.dex
- /data/data/####/classes.dex;classes2.dex
- /data/data/####/classes.dex;classes3.dex
- /data/data/####/classes.dex;classes4.dex
- /data/data/####/classes.dex;classes5.dex
- /data/data/####/com.astro.ultraview_oAuth_prefs.xml
- /data/data/####/com.astro.ultraview_preferences.xml
- /data/data/####/com.microsoft.appcenter.persistence-journal
- /data/data/####/encrypted_preferences.xml
- /data/data/####/hbdict
- /data/data/####/hbdict-journal
- /data/data/####/jgobfppppp (deleted)
- /data/data/####/libjiagu.so
Miscellaneous:
Loads the following dynamic libraries:
- libjiagu
Uses the following algorithms to encrypt data:
- AES-CTR-NoPadding
- AES-ECB-NoPadding
- RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
- RSA-ECB-PKCS1Padding
Uses special library to hide executable bytecode.
Gets information about network.
Displays its own windows over windows of other apps.
Uses a packer.