SHA1:
- 329c2e94e8c95a0d588fed72ea7e53fe21ea7837
Description
A malicious application spread by the Android.BankBot.Coper.1 dropper trojan and installed on Android devices under the guise of a system app called Cache plugin. It contains an executable dex file that performs the main malicious actions.
Operating routine
An application package of the Android.BankBot.Coper.2 contains a dex file that is located in \res\raw\syxinxxjzdmhf and encrypted with the RC4 algorithm. This file is an Android.BankBot.Coper.1.origin banking trojan. A native library liblfxeKfnTv.so and a ngLlO6J4EqyiYVjCBS3psvf8kwkw6JNt key is used to decrypt it. After this module is decrypted and launched, the icon of the host malicious app is hidden from the list of installed apps on the main screen.
More details on Android.BankBot.Coper.1
More details on Android.BankBot.Coper.2