Executes the following shell scripts:
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/1J9GZ1C1X3J6QRTLY8ZG1K0K1WTJYW6.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/DJ1KNDG1TZRM2F59Y0J8P8SK5C9BEOU.zip.cur.prof
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/1J9GZ1C1X3J6QRTLY8ZG1K0K1WTJYW6.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/1J9GZ1C1X3J6QRTLY8ZG1K0K1WTJYW6.vdex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/DJ1KNDG1TZRM2F59Y0J8P8SK5C9BEOU.odex
- chmod 777 /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/oat/arm/DJ1KNDG1TZRM2F59Y0J8P8SK5C9BEOU.vdex
- cp /data/user/0/<Package>/app_payload_lib/empty_classes.dex /data/user/0/<Package>/app_payload_lib/<Package>/R13MKZ7Q7X8PDOX66HWRTDPZZGUBUDH9.dex
- cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/1J9GZ1C1X3J6QRTLY8ZG1K0K1WTJYW6.zip
- cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/DJ1KNDG1TZRM2F59Y0J8P8SK5C9BEOU.zip
- cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/L79KJPC1X3FAMJLLI4N8DOOCLWPBIC2.zip
- dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/R13MKZ7Q7X8PDOX66HWRTDPZZGUBUDH9.dex --oat-file=/data/user/0/<Package>/cache/<Package>/R13MKZ7Q7X8PDOX66HWRTDPZZGUBUDH9.dex --compiler-filter=verify-none --instruction-set=x86
- getprop ro.dalvik.vm.isa.arm
- getprop ro.dalvik.vm.isa.arm64
- sh -c cp /data/user/0/<Package>/app_payload_lib/empty_classes.dex /data/user/0/<Package>/app_payload_lib/<Package>/R13MKZ7Q7X8PDOX66HWRTDPZZGUBUDH9.dex
- sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/R13MKZ7Q7X8PDOX66HWRTDPZZGUBUDH9.dex --oat-file=/data/user/0/<Package>/cache/<Package>/R13MKZ7Q7X8PDOX66HWRTDPZZGUBUDH9.dex --compiler-filter=verify-none --instruction-set=x86
Loads the following dynamic libraries:
Uses the following algorithms to encrypt data:
Uses the following algorithms to decrypt data:
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about active device administrators.
Gets information about installed apps.
Gets information about sent/received SMS.
Intercepts notifications.
Requests the system alert window permission.