32
android Malware and analysis
is made deleting Obad from the device impossible after gaining
the extended privileges. Obad also had no declared activities; it ran
completely in the background without user awareness. To connect
with C&C servers, Obad would rst check to ensure that the device
had Internet access and then it would download the main page of
Facebook.com. Obad then extracted a specic element from the page
and that was used as the decryption key for the strings containing the
C&C server addresses. Obad also attempted to obtain root privileges
with the command “su id”. e high number of unknown exploit-
able vulnerabilities used in Obad opened a new chapter in Android
malware, where future families may be engineered with the increa ...