SHA1:
- 4d2e9122e13f1864a20b1a1d673194d35141549d
Android-Trojan, comes as a software module that is downloaded and launched by the malicious application Android.RemoteCode.152.origin. It is downloaded from the server located at: Android.RemoteCode.152.origin. It is downloaded from the server located at:
http://37.252.**.**:40326/sys/module/load/bd0f0f04-436c-476e-b624-86830531f9e2/
Upon launching, Android.Click.249.origin downloads and launches another program module using the DexClassLoader class. This module is a modified version of the advertising development SDK (Software Development Kit) called MobFox. It is downloaded from the server at the following address:
http://37.252.**.**:35823/sys/module/load/66788944-13d0-49dc-97ab-195dd4667000/
This module is used by the Android.Click.249.origin Trojan for creating ad banners, which it automatically clicks.