Pegasus for Android
eatsvTG
eatsvTG
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Furthermore the libsgn.so binary contains a single hardcoded IP address from where to<br />
receive the payload that eventually gets written out to the .coldboot_init file. This IP<br />
address, 130.195.234.251, can be seen below in the following screenshot taken during<br />
analysis.<br />
Requests to this IP address are made in the following <strong>for</strong>mat /adinfo?gi=%s&bf=%s where<br />
the values of the gi and bf parameters are populated using a combination of the<br />
random_hexlified_md5() and get_mac_address() functions.<br />
29