- SHA1: e96da20cfad50842ab59781f051fda590d231cc9 (libcutils.so)
Description
Android.BackDoor.3105 is the detection name of an originally harmless libcutils.so system library that has been modified in such a way that whenever any program uses it, a malicious library (the backdoor Android.BackDoor.3104) is launched.
Operating routine
The library is located in /system/lib/libcutils.so. A dependency related to the Android.BackDoor.3104 malware has been added into it, so every time any program uses this library, Android.BackDoor.3104, which is located in /system/lib/libmtd.so, is launched.