Technical information
Malicious functions:
Executes code of the following detected threats:
- Android.BankBot.14766
Threat detection based on machine learning.
Network activity:
Connects to:
- UDP(DNS) <Google DNS>
- UDP(DNS) 8####.8.4.4:53
- TCP(TLS/1.0) connect####.gst####.com:443
- TCP(TLS/1.0) www.google####.com:443
DNS requests:
- connect####.gst####.com
- www.google####.com
File system changes:
Creates the following files:
- /data/data/####/4dbe56746444b251406a339c56cb7791.xml
- /data/data/####/libclb.so
- /data/data/####/payload.dex
- /data/data/####/payload.dex (deleted)
- /data/data/####/payload.dex.flock (deleted)
- /data/data/####/payload.jar
- /data/media/####/uu.dd
Miscellaneous:
Loads the following dynamic libraries:
- libclb
Uses the following algorithms to decrypt data:
- AES-CBC-NoPadding
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.
Gets information about sent/received SMS.
Requests the system alert window permission.
Attempts to detect sandbox environment.