05.04.2017 Views

Pegasus for Android

eatsvTG

eatsvTG

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Furthermore the ​libsgn.so​ binary contains a single hardcoded IP address from where to<br />

receive the payload that eventually gets written out to the ​.coldboot_init​ file. This IP<br />

address, ​130.195.234.251​, can be seen below in the following screenshot taken during<br />

analysis.<br />

Requests to this IP address are made in the following <strong>for</strong>mat ​/adinfo?gi=%s&bf=%s​ where<br />

the values of the gi and bf parameters are populated using a combination of the<br />

random_hexlified_md5() ​and ​get_mac_address()​ functions.<br />

29

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!