NOTES:
REFERENCES:
ASSOCIATED FILES:
NOTES:

Shown above: Telegram channel where I downloaded the malware from.

Shown above: Screenshot of the app icon in the device's home screen after I downloaded it.

Shown above: Screenshot of the login screen that appears when you first open the app.

Shown above: Screenshot of the app after I logged in.

Shown above: I had the choice to change server locations.

Shown above: Traffic from the Android device when I downloaded, opened, and logged into the malicious app.

Shown above: TCP stream of configuration traffic after I'd logged into the malicious app.

Shown above: TCP stream of websocket traffic generated by the app after logging in.
Click here to return to the main page.