Executes next shell scripts:
- /system/bin/sh
- cat /sys/class/net/wlan0/address
- chmod 755 <Package Folder>/.jiagu/libjiagu.so
- chmod 777 <Package Folder>/app_bin/daemon
- ls -l /sbin/su
- ls -l /system/bin/su
- ls -l /system/sbin/su
- ls -l /system/xbin/su
- ls -l /vendor/bin/su
- mars_d -p <Package> -s com.security.guard.monitor.daemon.AssistantService -p1r 46 -p1w 47 -p2r 48 -p2w 49
Loads the following dynamic libraries:
- andengine
- daemon_api20
- libjiagu
Uses special library to hide executable bytecode.
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about accounts (Google, Facebook, etc.) registered on the device.
Displays its own windows over windows of other applications.