Loading Joe Sandbox Report ...

Edit tour

Android Analysis Report
SyZ12afSEL

Overview

General Information

Sample Name:SyZ12afSEL
Analysis ID:686317
MD5:0533968891354ac78b45c486600a7890
SHA1:4e9bc1bcbeec32ad93762482b9e1295c7f1bcee5
SHA256:b01b74aaf249d0740f541c081c0c0de4bf455b4b68f2634fab6cf8aafcd95d52
Infos:

Detection

S.O.V.A.
Score:80
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Detected S.O.V.A.
Multi AV Scanner detection for submitted file
Removes its application launcher (likely to stay hidden)
Monitors outgoing Phone calls
Drops a new dex file
Contains a screen recorder (to take screenshot)
Opens an internet connection
Checks if the Android Monkey is running (UI Automation)
Parses SMS data (e.g. originating address)
Has permission to receive SMS in the background
Lists and deletes files in the same context
Queries media storage location field
Monitors incoming Phone calls
Detected TCP or UDP traffic on non-standard ports
Has functionalty to add an overlay to other apps
Has permission to draw over other applications or user interfaces
Installs a new wake lock (to get activate on phone screen on)
Found suspicious command strings (may be related to BOT commands)
Monitors incoming SMS
Might use exploit to break dedexer tools
Sends SMS using SmsManager
Accesses android OS build fields
Executes native commands
Performs DNS lookups (Java API)
Requests potentially dangerous permissions
Queries several sensitive phone informations
Has permission to send SMS in the background
Queries the unique operating system id (ANDROID_ID)
Has permissions to monitor, redirect and/or block calls
Has permission to execute code after phone reboot
Uses reflection

Classification

No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: SyZ12afSELAvira: detected
Source: SyZ12afSELVirustotal: Detection: 54%Perma Link
Source: SyZ12afSELReversingLabs: Detection: 36%
Source: SyZ12afSELCode Location: Lz/l0;.a(Ljava/lang/Throwable;)V
Source: unknownHTTPS traffic detected: 142.250.186.170:443 -> 192.168.2.102:37478 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.186.42:443 -> 192.168.2.102:44740 version: TLS 1.2
Source: com.facebook.cache.disk.DefaultDiskStorage;->isExternal:69API Call: android.os.Environment.getExternalStorageDirectory
Source: com.facebook.common.statfs.StatFsHelper;->ensureInitialized:9API Call: android.os.Environment.getExternalStorageDirectory
Source: com.gdwicoopc.mlwmelkys.network.MultipartUtilityV2;-><init>:8API Call: java.net.URL.openConnection (not executed)
Source: com.gdwicoopc.mlwmelkys.network.Request;->get:13API Call: java.net.URL.openConnection (not executed)
Source: com.gdwicoopc.mlwmelkys.network.Request;->getHttp:38API Call: java.net.URL.openConnection (not executed)
Source: com.gdwicoopc.mlwmelkys.network.Request;->post:71API Call: java.net.URL.openConnection (not executed)
Source: com.gdwicoopc.mlwmelkys.network.Request;->postHttpJson:128API Call: java.net.URL.openConnection (not executed)
Source: com.facebook.react.modules.camera.ImageEditingManager$CropTask;->openBitmapInputStream:52API Call: java.net.URL.openConnection (not executed)
Source: com.dropbox.core.http.StandardHttpRequestor;->prepRequest:16API Call: java.net.URL.openConnection (not executed)
Source: com.airbnb.lottie.network.NetworkFetcher;->fetchFromNetworkInternal:28API Call: java.net.URL.openConnection (not executed)
Source: tech.gusavila92.apache.http.impl.pool.BasicConnFactory;->create:64API Call: java.net.Socket.connect (not executed)
Source: com.facebook.imagepipeline.producers.HttpUrlConnectionNetworkFetcher;->openConnectionTo:37API Call: java.net.URL.openConnection (not executed)
Source: tech.gusavila92.websocketclient.WebSocketClient$WebSocketConnection;->createAndConnectTCPSocket:42API Call: java.net.Socket.connect (not executed)
Source: tech.gusavila92.websocketclient.WebSocketClient$WebSocketConnection;->createAndConnectTCPSocket:50API Call: java.net.Socket.connect (not executed)
Source: tech.gusavila92.websocketclient.WebSocketClient$WebSocketConnection;->createAndConnectTCPSocket:66API Call: java.net.Socket.connect (not executed)
Source: tech.gusavila92.websocketclient.WebSocketClient$WebSocketConnection;->createAndConnectTCPSocket:74API Call: java.net.Socket.connect (not executed)
Source: global trafficTCP traffic: 192.168.2.102:55348 -> 8.8.4.4:853
Source: e.o$o;->a:6API Call: java.net.InetAddress.getByName (not executed)
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52998
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 45782
Source: unknownNetwork traffic detected: HTTP traffic on port 57982 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 45502 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 39634 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58216
Source: unknownNetwork traffic detected: HTTP traffic on port 45782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 41952 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 35490 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 45756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57950 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36420
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 37478
Source: unknownNetwork traffic detected: HTTP traffic on port 44740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57982
Source: unknownNetwork traffic detected: HTTP traffic on port 34118 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44756
Source: unknownNetwork traffic detected: HTTP traffic on port 53130 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 44712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 58604 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 39626 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 44756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57984 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 58216 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 45418 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 44746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53228
Source: unknownNetwork traffic detected: HTTP traffic on port 37478 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 41954 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57984
Source: unknownNetwork traffic detected: HTTP traffic on port 45504 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 58444 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56534
Source: unknownNetwork traffic detected: HTTP traffic on port 34086 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 34120 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 55354 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57950
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58444
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41954
Source: unknownNetwork traffic detected: HTTP traffic on port 59774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 45758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41952
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 45756
Source: unknownNetwork traffic detected: HTTP traffic on port 36420 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44746
Source: unknownNetwork traffic detected: HTTP traffic on port 45758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44740
Source: unknownNetwork traffic detected: HTTP traffic on port 41336 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58604
Source: unknownNetwork traffic detected: HTTP traffic on port 53798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 52998 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39634
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39626
Source: unknownNetwork traffic detected: HTTP traffic on port 53228 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 41326 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 59882 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 56534 -> 443
Source: com.dropbox.core.http.StandardHttpRequestor$Uploader;-><init>:3API Call: java.net.HttpURLConnection.connect
Source: com.dropbox.core.http.StandardHttpRequestor;->doGet:45API Call: java.net.HttpURLConnection.connect
Source: com.airbnb.lottie.network.NetworkFetcher;->fetchFromNetworkInternal:32API Call: java.net.HttpURLConnection.connect
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.203.100
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.203.100
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.203.100
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.203.100
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.168.78
Source: classes.dex, androidString found in binary or memory: http://%s/%s.%s?platform=android&dev=%s&minify=%s
Source: classes.dexString found in binary or memory: http://%s/%s1http://%s/%s.%s?platform=android&dev=%s&minify=%s)http://%s/inspector/device?name=%s&ap
Source: layout_window_web.xmlString found in binary or memory: http://schemas.android.com/apk/res/android
Source: classes.dex, androidString found in binary or memory: http://www.android.com/
Source: classes.dex, androidString found in binary or memory: https://github.com/facebook/react-native/wiki/Breaking-Changes#d4611211-reactnativeandroidbreaking-m
Source: classes.dex, androidString found in binary or memory: https://www.dropbox.com/upgrade?oqa=upeaoq
Source: -k-r-c-p-u-r-p-e-l-s-h-b-j-p-d-w-r-y-s-t-s-j-w-d-m-f-a-k-w-c-r-o-o-k-t-n-g-z-g-z-p-k-f-a-j-k-b-q-t-w-o-p-o-f-m-g-l-a-a-c-j-w-f-g-w-q-s-t-e-x-a-q-t-j-m-g-y-k-z-f-r-w-h-o-k-t-k-z-d-a-r-z-c-e-t-d-x-i-t-m-jfO.sR.drString found in binary or memory: https://xireycicin.xyz
Source: unknownHTTPS traffic detected: 142.250.186.170:443 -> 192.168.2.102:37478 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.186.42:443 -> 192.168.2.102:44740 version: TLS 1.2

Key, Mouse, Clipboard, Microphone and Screen Capturing

barindex
Source: Lcom/gdwicoopc/mlwmelkys/screenshot/Capture;->createDisplay(Landroid/media/projection/MediaProjection;)Landroid/hardware/display/VirtualDisplay;Method: getDisplayMetrics and createVirtualDisplay
Source: com.gdwicoopc.mlwmelkys.services.AccessibilityService;->showLoading:122API Call: WindowManager.addView
Source: com.gdwicoopc.mlwmelkys.services.AccessibilityService;->showWeb:148API Call: WindowManager.addView
Source: com.facebook.react.devsupport.DebugOverlayController$1;->run:20API Call: WindowManager.addView
Source: com.gdwicoopc.mlwmelkys.utils.extensions.BaseExtensionsKt;->sendSms2:252API Call: android.telephony.SmsManager.sendTextMessage
Source: submitted apkRequest permission: android.permission.SEND_SMS
Source: submitted apkRequest permission: android.permission.PROCESS_OUTGOING_CALLS
Source: .a;->a:2API Calls in same method context: File.listFiles,File.delete
Source: com.facebook.soloader.SysUtil;->dumbDeleteRecursive:15API Calls in same method context: File.listFiles,File.delete
Source: com.airbnb.lottie.network.NetworkCache;->clear:37API Calls in same method context: File.listFiles,File.delete
Source: com.facebook.react.modules.camera.ImageEditingManager$CleanTask;->cleanDirectory:5API Calls in same method context: File.listFiles,File.delete
Source: com.gdwicoopc.mlwmelkys.services.BackgroundService;->acquireWakeLock:22API Call: android.os.PowerManager$WakeLock.acquire
Source: com.facebook.react.HeadlessJsTaskService;->acquireWakeLockNow:14API Call: android.os.PowerManager$WakeLock.acquire
Source: com.facebook.react.modules.systeminfo.AndroidInfoHelpers;->getMetroHostPropValue:40API Call: java.lang.Runtime.exec
Source: submitted apkRequest permission: android.permission.INTERNET
Source: submitted apkRequest permission: android.permission.PROCESS_OUTGOING_CALLS
Source: submitted apkRequest permission: android.permission.RECEIVE_SMS
Source: submitted apkRequest permission: android.permission.REORDER_TASKS
Source: submitted apkRequest permission: android.permission.SEND_SMS
Source: submitted apkRequest permission: android.permission.SYSTEM_ALERT_WINDOW
Source: submitted apkRequest permission: android.permission.WAKE_LOCK
Source: submitted apkRequest permission: android.permission.WRITE_SETTINGS
Source: com.facebook.react.common.ShakeDetector;->start:26API Call: android.hardware.SensorManager.registerListener
Source: com.gdwicoopc.mlwmelkys.core.Settings;->accessibilityPackage1:41API Call: android.content.SharedPreferences.getString
Source: com.gdwicoopc.mlwmelkys.core.Settings;->allowed:49API Call: android.content.SharedPreferences.getBoolean
Source: com.gdwicoopc.mlwmelkys.core.Settings;->allowedAccessibility:57API Call: android.content.SharedPreferences.getBoolean
Source: com.gdwicoopc.mlwmelkys.core.Settings;->anyOpenApp:64API Call: android.content.SharedPreferences.getString
Source: com.gdwicoopc.mlwmelkys.core.Settings;->appInfoPackage:71API Call: android.content.SharedPreferences.getString
Source: com.gdwicoopc.mlwmelkys.core.Settings;->botId:78API Call: android.content.SharedPreferences.getString
Source: com.gdwicoopc.mlwmelkys.core.Settings;->currentInjectList:88API Call: android.content.SharedPreferences.getString
Source: com.gdwicoopc.mlwmelkys.core.Settings;->is2FARequested:97API Call: android.content.SharedPreferences.getBoolean
Source: com.gdwicoopc.mlwmelkys.core.Settings;->isBinanceRequested:107API Call: android.content.SharedPreferences.getBoolean
Source: com.gdwicoopc.mlwmelkys.core.Settings;->isFirstOpened:115API Call: android.content.SharedPreferences.getBoolean
Source: com.gdwicoopc.mlwmelkys.core.Settings;->isGAllowRequested:123API Call: android.content.SharedPreferences.getBoolean
Source: com.gdwicoopc.mlwmelkys.core.Settings;->isGRequested:133API Call: android.content.SharedPreferences.getBoolean
Source: com.gdwicoopc.mlwmelkys.core.Settings;->isTrustRequested:143API Call: android.content.SharedPreferences.getBoolean
Source: com.gdwicoopc.mlwmelkys.core.Settings;->registered:151API Call: android.content.SharedPreferences.getBoolean
Source: com.gdwicoopc.mlwmelkys.core.Settings;->selected:159API Call: android.content.SharedPreferences.getBoolean
Source: com.gdwicoopc.mlwmelkys.core.Settings;->stackTrace:166API Call: android.content.SharedPreferences.getString
Source: com.gdwicoopc.mlwmelkys.core.Settings;->toDelete:174API Call: android.content.SharedPreferences.getBoolean
Source: com.gdwicoopc.mlwmelkys.core.Settings;->vncEnabled:182API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.devsupport.DevInternalSettings;->isAnimationFpsDebugEnabled:10API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.devsupport.DevInternalSettings;->isBundleDeltasCppEnabled:13API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.devsupport.DevInternalSettings;->isBundleDeltasEnabled:16API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.devsupport.DevInternalSettings;->isElementInspectorEnabled:19API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.devsupport.DevInternalSettings;->isFpsDebugEnabled:22API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.devsupport.DevInternalSettings;->isHotModuleReplacementEnabled:25API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.devsupport.DevInternalSettings;->isJSDevModeEnabled:28API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.devsupport.DevInternalSettings;->isJSMinifyEnabled:31API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.devsupport.DevInternalSettings;->isReloadOnJSChangeEnabled:34API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.devsupport.DevInternalSettings;->isRemoteJSDebugEnabled:37API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.devsupport.DevInternalSettings;->isStartSamplingProfilerOnInit:40API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.modules.i18nmanager.I18nUtil;->isPrefSet:9API Call: android.content.SharedPreferences.getBoolean
Source: com.facebook.react.packagerconnection.PackagerConnectionSettings;->getDebugServerHost:7API Call: android.content.SharedPreferences.getString
Source: com.facebook.soloader.SoLoader;->loadLibrary:275API Call: java.lang.System.loadLibrary
Source: classification engineClassification label: mal80.troj.spyw.evad.and@0/254@0/0
Source: .f;->a:8API Call: Real call: private final dalvik.system.DexPathList dalvik.system.BaseDexClassLoader.pathList
Source: .f;->a:12API Call: Real call: private dalvik.system.DexPathList$Element[] dalvik.system.DexPathList.dexElements
Source: .f;->a:17API Call: Real call: DexPathList[[zip file "/data/app/~~YzDtIKibwx6vRzHCbCrodQ==/com.gdwicoopc.mlwmelkys-ciROcEFX4GMbUjucXgJwMQ==/base.apk"],nativeLibraryDirectories=[/data/app/~~YzDtIKibwx6vRzHCbCrodQ==/com.gdwicoopc.mlwmelkys-ciROcEFX4GMbUjucXgJwMQ==/lib/x86_64, /system/lib64, /system/system_ext/lib64, /system/product/lib64, /system/vendor/lib64]]
Source: .f;->a:17API Call: Real call: private static dalvik.system.DexPathList$Element[] dalvik.system.DexPathList.makePathElements(java.util.List,java.io.File,java.util.List)
Source: kotlinx.coroutines.android.AndroidExceptionPreHandler;->handleException:13API Call: java.lang.reflect.Method.invoke
Source: kotlinx.coroutines.android.a;->a:9API Call: java.lang.reflect.Method.invoke
Source: com.dropbox.core.android.FixedSecureRandom;->getDeviceSerialNumber:36API Call: java.lang.reflect.Field.get
Source: com.facebook.react.bridge.JavaMethodWrapper;->invoke:166API Call: java.lang.reflect.Method.invoke
Source: com.dropbox.core.DbxWrappedException;->executeOtherBlocks:8API Call: java.lang.reflect.Method.invoke
Source: com.dropbox.core.DbxWrappedException;->executeOtherBlocks:21API Call: java.lang.reflect.Field.get
Source: d.g;-><init>:10API Call: java.lang.reflect.Field.get
Source: d.g;-><init>:17API Call: java.lang.reflect.Method.invoke
Source: d.v;->b:5API Call: java.lang.reflect.Method.invoke
Source: d.w;->b:5API Call: java.lang.reflect.Method.invoke
Source: d.x;->b:4API Call: java.lang.reflect.Method.invoke
Source: com.facebook.react.modules.datepicker.DismissableDatePickerDialog;->fixSpinner:15API Call: java.lang.reflect.Field.get
Source: com.facebook.react.modules.datepicker.DismissableDatePickerDialog;->fixSpinner:24API Call: java.lang.reflect.Field.get
Source: com.facebook.react.modules.datepicker.DismissableDatePickerDialog;->fixSpinner:28API Call: java.lang.reflect.Field.get
Source: com.facebook.react.modules.datepicker.DismissableDatePickerDialog;->fixSpinner:40API Call: java.lang.reflect.Method.invoke
Source: com.facebook.react.views.drawer.ReactDrawerLayoutManager;->setElevation:115API Call: java.lang.reflect.Method.invoke
Source: e.i;->b:7API Call: java.lang.reflect.Field.get
Source: e.i;->c:16API Call: java.lang.reflect.Field.get
Source: e.o$e0;-><init>:8API Call: java.lang.reflect.Field.get
Source: g.c;-><init>:9API Call: java.lang.reflect.Field.get
Source: g.c;->a:19API Call: java.lang.reflect.Method.invoke
Source: g.c;->a:29API Call: java.lang.reflect.Method.invoke
Source: m.a;->getStackTraceElement:23API Call: java.lang.reflect.Field.get
Source: m.a;->getStackTraceElement:48API Call: java.lang.reflect.Method.invoke
Source: m.a;->getStackTraceElement:50API Call: java.lang.reflect.Method.invoke
Source: m.a;->getStackTraceElement:52API Call: java.lang.reflect.Method.invoke
Source: n.a;->a:3API Call: java.lang.reflect.Method.invoke
Source: com.facebook.imagepipeline.platform.GingerbreadPurgeableDecoder;->getMemoryFileDescriptor:37API Call: java.lang.reflect.Method.invoke
Source: com.facebook.react.views.scroll.ReactHorizontalScrollView;->getOverScrollerFromParent:75API Call: java.lang.reflect.Field.get
Source: com.facebook.react.views.scroll.ReactScrollView;->getOverScrollerFromParent:78API Call: java.lang.reflect.Field.get
Source: com.facebook.soloader.SoLoader$Api14Utils;->getClassLoaderLdLoadLibrary:5API Call: java.lang.reflect.Method.invoke
Source: com.facebook.soloader.SoLoader$1;->load:24API Call: java.lang.reflect.Method.invoke
Source: com.horcrux.svg.RenderableView;->mergeProperties:149API Call: java.lang.reflect.Field.get
Source: com.horcrux.svg.RenderableView;->mergeProperties:151API Call: java.lang.reflect.Field.get
Source: com.facebook.react.views.textinput.ReactTextInputManager;->setCursorColor:167API Call: java.lang.reflect.Field.get
Source: com.facebook.react.uimanager.DisplayMetricsHolder;->initDisplayMetrics:74API Call: java.lang.reflect.Method.invoke
Source: com.facebook.react.uimanager.DisplayMetricsHolder;->initDisplayMetrics:76API Call: java.lang.reflect.Method.invoke
Source: com.facebook.react.uimanager.ViewManagersPropertyCache$PropSetter;->updateShadowNodeProp:23API Call: java.lang.reflect.Method.invoke
Source: com.facebook.react.uimanager.ViewManagersPropertyCache$PropSetter;->updateShadowNodeProp:32API Call: java.lang.reflect.Method.invoke
Source: com.facebook.react.uimanager.ViewManagersPropertyCache$PropSetter;->updateViewProp:59API Call: java.lang.reflect.Method.invoke
Source: com.facebook.react.uimanager.ViewManagersPropertyCache$PropSetter;->updateViewProp:69API Call: java.lang.reflect.Method.invoke
Source: com.samstore.xivort.a;->onCreate:39API Call: java.lang.reflect.Method.invoke
Source: com.samstore.xivort.a;->onCreate:52API Call: java.lang.reflect.Field.get
Source: com.samstore.xivort.a;->onCreate:65API Call: java.lang.reflect.Field.get
Source: com.samstore.xivort.a;->onCreate:72API Call: java.lang.reflect.Field.get
Source: com.samstore.xivort.a;->onCreate:85API Call: java.lang.reflect.Field.get

Persistence and Installation Behavior

barindex
Source: Android AppFile dump: /storage/emulated/0/Android/obb/com.gdwicoopc.mlwmelkys//-k-r-c-p-u-r-p-e-l-s-h-b-j-p-d-w-r-y-s-t-s-j-w-d-m-f-a-k-w-c-r-o-o-k-t-n-g-z-g-z-p-k-f-a-j-k-b-q-t-w-o-p-o-f-m-g-l-a-a-c-j-w-f-g-w-q-s-t-e-x-a-q-t-j-m-g-y-k-z-f-r-w-h-o-k-t-k-z-d-a-r-z-c-e-t-d-x-i-t-m-jfO.sRJump to dropped file
Source: com.gdwicoopc.mlwmelkys.services.BackgroundService;->acquireWakeLock:21API Call: android.os.PowerManager.newWakeLock
Source: com.facebook.react.HeadlessJsTaskService;->acquireWakeLockNow:11API Call: android.os.PowerManager.newWakeLock
Source: submitted apkRequest permission: android.permission.RECEIVE_BOOT_COMPLETED

Hooking and other Techniques for Hiding and Protection

barindex
Source: com.gdwicoopc.mlwmelkys.utils.extensions.BaseExtensionsKt;->appHidden:7API Call: android.content.pm.PackageManager.setComponentEnabledSetting
Source: submitted apkRequest permission: android.permission.SYSTEM_ALERT_WINDOW
Source: submitted apkRequest permission: android.permission.PROCESS_OUTGOING_CALLS
Source: com.onelab.securecomm.db.BackupDBManager;->getBackupDbPasswordByAccount:54API Call: java.security.MessageDigest.getInstance
Source: com.onelab.securecomm.db.BackupDBManager;->getBackupDbPasswordByAccount:56API Call: java.security.MessageDigest.update
Source: com.onelab.securecomm.db.BackupDBManager;->getBackupDbPasswordByAccount:57API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.DigestUtils;->digest:3API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.DigestUtils;->getDigest:4API Call: java.security.MessageDigest.getInstance
Source: tech.gusavila92.apache.commons.codec.digest.DigestUtils;->md2:24API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.DigestUtils;->md5:36API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.DigestUtils;->sha1:51API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.DigestUtils;->sha256:63API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.DigestUtils;->sha384:75API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.DigestUtils;->sha512:87API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.DigestUtils;->updateDigest:98API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.DigestUtils;->updateDigest:101API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.DigestUtils;->updateDigest:102API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:49API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:52API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:53API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:55API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:56API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:57API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:58API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:59API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:61API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:62API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:69API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:71API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:72API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:73API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:74API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:75API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:76API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Md5Crypt;->md5Crypt:77API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:25API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:26API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:28API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:29API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:30API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:31API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:32API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:33API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:34API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:35API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:36API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:38API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:39API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:43API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:44API Call: java.security.MessageDigest.digest
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:48API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:49API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:50API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:51API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:52API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:53API Call: java.security.MessageDigest.update
Source: tech.gusavila92.apache.commons.codec.digest.Sha2Crypt;->sha2Crypt:54API Call: java.security.MessageDigest.digest
Source: com.facebook.soloader.SoLoader$1;->getLibHash:4API Call: java.security.MessageDigest.getInstance
Source: com.facebook.soloader.SoLoader$1;->getLibHash:7API Call: java.security.MessageDigest.update
Source: com.facebook.soloader.SoLoader$1;->getLibHash:9API Call: java.security.MessageDigest.digest
Source: com.facebook.common.util.SecureHashUtil;->makeHash:8API Call: java.security.MessageDigest.getInstance
Source: com.facebook.common.util.SecureHashUtil;->makeHash:10API Call: java.security.MessageDigest.update
Source: com.facebook.common.util.SecureHashUtil;->makeHash:11API Call: java.security.MessageDigest.digest
Source: com.facebook.common.util.SecureHashUtil;->makeHash:15API Call: java.security.MessageDigest.getInstance
Source: com.facebook.common.util.SecureHashUtil;->makeHash:16API Call: java.security.MessageDigest.update
Source: com.facebook.common.util.SecureHashUtil;->makeHash:17API Call: java.security.MessageDigest.digest
Source: com.facebook.common.util.SecureHashUtil;->makeSHA1HashBase64:36API Call: java.security.MessageDigest.getInstance
Source: com.facebook.common.util.SecureHashUtil;->makeSHA1HashBase64:37API Call: java.security.MessageDigest.update
Source: com.facebook.common.util.SecureHashUtil;->makeSHA1HashBase64:38API Call: java.security.MessageDigest.digest
Source: com.facebook.react.devsupport.DevSupportManagerImpl;->showDevOptionsDialog:313API Call: android.app.ActivityManager.isUserAMonkey
Source: com.gdwicoopc.mlwmelkys.ui.activities.StartActivity$register$1;->invokeSuspend:43Field Access: android.os.Build$VERSION.RELEASE
Source: com.gdwicoopc.mlwmelkys.core.Config;->getAccessibilityLink:45Field Access: android.os.Build$VERSION.RELEASE
Source: com.gdwicoopc.mlwmelkys.utils.extensions.BaseExtensionsKt;->isEms:135Field Access: android.os.Build.BRAND
Source: com.gdwicoopc.mlwmelkys.utils.extensions.BaseExtensionsKt;->isEms:140Field Access: android.os.Build.DEVICE
Source: com.gdwicoopc.mlwmelkys.utils.extensions.BaseExtensionsKt;->isEms:144Field Access: android.os.Build.FINGERPRINT
Source: com.gdwicoopc.mlwmelkys.utils.extensions.BaseExtensionsKt;->isEms:159Field Access: android.os.Build.MODEL
Source: com.gdwicoopc.mlwmelkys.utils.extensions.BaseExtensionsKt;->isEms:170Field Access: android.os.Build.MANUFACTURER
Source: com.gdwicoopc.mlwmelkys.utils.extensions.BaseExtensionsKt;->isEms:175Field Access: android.os.Build.PRODUCT
Source: com.gdwicoopc.mlwmelkys.utils.Utils;->getDeviceModel:6Field Access: android.os.Build.MANUFACTURER
Source: com.gdwicoopc.mlwmelkys.utils.Utils;->getDeviceModel:9Field Access: android.os.Build.MODEL
Source: com.dropbox.core.android.FixedSecureRandom;->getBuildFingerprintAndDeviceSerial:25Field Access: android.os.Build.FINGERPRINT
Source: com.facebook.soloader.SysUtil;->getSupportedAbis:47Field Access: android.os.Build.CPU_ABI
Source: com.facebook.react.modules.systeminfo.AndroidInfoHelpers;->getFriendlyDeviceName:17Field Access: android.os.Build.MODEL
Source: com.facebook.react.modules.systeminfo.AndroidInfoHelpers;->getFriendlyDeviceName:19Field Access: android.os.Build.MODEL
Source: com.facebook.react.modules.systeminfo.AndroidInfoHelpers;->getFriendlyDeviceName:23Field Access: android.os.Build$VERSION.RELEASE
Source: com.facebook.react.modules.systeminfo.AndroidInfoHelpers;->isRunningOnGenymotion:75Field Access: android.os.Build.FINGERPRINT
Source: com.facebook.react.modules.systeminfo.AndroidInfoHelpers;->isRunningOnStockEmulator:78Field Access: android.os.Build.FINGERPRINT
Source: com.facebook.react.modules.systeminfo.AndroidInfoModule;->getConstants:30Field Access: android.os.Build$VERSION.RELEASE
Source: com.facebook.react.modules.systeminfo.AndroidInfoModule;->getConstants:36Field Access: android.os.Build.FINGERPRINT
Source: com.facebook.react.modules.systeminfo.AndroidInfoModule;->getConstants:39Field Access: android.os.Build.MODEL
Source: Lcom/dropbox/core/v2/team/ActiveWebSession$Serializer;->serialize(Lcom/dropbox/core/v2/team/ActiveWebSession;Lcom/fasterxml/jackson/core/JsonGenerator;Z)VMethod string: "os"
Source: Lcom/dropbox/core/v2/team/DevicesActive$Serializer;->serialize(Lcom/dropbox/core/v2/team/DevicesActive;Lcom/fasterxml/jackson/core/JsonGenerator;Z)VMethod string: "android"
Source: Lcom/dropbox/core/v2/fileproperties/PropertyFieldTemplate$Serializer;->serialize(Lcom/dropbox/core/v2/fileproperties/PropertyFieldTemplate;Lcom/fasterxml/jackson/core/JsonGenerator;Z)VMethod string: "type"
Source: Ltech/gusavila92/apache/http/message/BasicStatusLine;-><init>(Ltech/gusavila92/apache/http/ProtocolVersion;ILjava/lang/String;)VMethod string: "version"
Source: Lcom/onelab/securecomm/db/data/UserProfileBean;-><init>(Lorg/json/JSONObject;)VMethod string: "phone"
Source: Lcom/onelab/securecomm/db/SecureCommDBManager;->saveNotificationMessage(Ljava/lang/String;JJJIJLjava/lang/String;)VMethod string: "time"
Source: com.facebook.react.modules.systeminfo.AndroidInfoModule;->getAndroidID:25API Call: android.provider.Settings$Secure.getString

Stealing of Sensitive Information

barindex
Source: com.gdwicoopc.mlwmelkys.receivers.CallReceiverRegistered receiver: android.intent.action.NEW_OUTGOING_CALL
Source: com.gdwicoopc.mlwmelkys.receivers.SMSReceiver$onReceive$1$1;->invokeSuspend:21API Call: android.telephony.SmsMessage.getMessageBody
Source: submitted apkRequest permission: android.permission.RECEIVE_SMS
Source: com.facebook.common.util.UriUtil;->isLocalCameraUri:37Field access: android.provider.MediaStore$Images$Media.EXTERNAL_CONTENT_URI
Source: com.facebook.common.util.UriUtil;->isLocalCameraUri:40Field access: android.provider.MediaStore$Images$Media.INTERNAL_CONTENT_URI
Source: com.gdwicoopc.mlwmelkys.receivers.CallReceiverRegistered receiver: android.intent.action.PHONE_STATE
Source: com.gdwicoopc.mlwmelkys.receivers.SMSReceiverRegistered receiver: android.provider.Telephony.SMS_RECEIVED

Remote Access Functionality

barindex
Source: Lcom/gdwicoopc/mlwmelkys/tasks/accessibility/KeyInject;->executeTaskOn(Landroid/view/accessibility/AccessibilityEvent;)ZMethod: Various indicators of S.O.V.A.
Source: Lcom/dropbox/core/v2/team/MembersRemoveArg;->getWipeData()ZInstruction: "iget-boolean v0, p0, lcom/dropbox/core/v2/team/membersremovearg;->wipedata:z"
Source: Lcom/airbnb/lottie/model/content/CircleShape;->isReversed()ZInstruction: "iget-boolean v0, p0, lcom/airbnb/lottie/model/content/circleshape;->isreversed:z"
Source: Lcom/onelab/securecomm/databinding/ActivityGroupChatRoom2BindingImpl;->onFieldChange(ILjava/lang/Object;I)ZInstruction: "lcom/onelab/securecomm/databinding/activitygroupchatroom2bindingimpl;->onchangeappbar(lcom/onelab/securecomm/databinding/chatroomappbarbinding;i)z"
Source: Lcom/gdwicoopc/mlwmelkys/utils/extensions/BaseExtensionsKt$sendSms$1;-><clinit>()VInstruction: "sput-object v0, lcom/gdwicoopc/mlwmelkys/utils/extensions/baseextensionskt$sendsms$1;->$:[s"
Source: Lcom/dropbox/core/v1/DbxClientV1;->startUploadFileChunked(Ljava/lang/String;Lcom/dropbox/core/v1/DbxWriteMode;J)Lcom/dropbox/core/v1/DbxClientV1$Uploader;Instruction: "lcom/dropbox/core/v1/dbxclientv1;->startuploadfilechunked(iljava/lang/string;lcom/dropbox/core/v1/dbxwritemode;j)lcom/dropbox/core/v1/dbxclientv1$uploader;"
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
Capture SMS Messages
1
System Information Discovery
Remote Services11
Access Call Log
Exfiltration Over Other Network Medium1
Encrypted Channel
2
Exploit SS7 to Redirect Phone Calls/SMS
Remotely Track Device Without Authorization1
Delete Device Data
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop Protocol1
Screen Capture
Exfiltration Over Bluetooth1
Non-Standard Port
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without Authorization1
Carrier Billing Fraud
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin Shares1
Capture SMS Messages
Automated Exfiltration1
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

This section contains all screenshots as thumbnails, including those not shown in the slideshow.