SHA1: b94832212a3febe8eca65343ee2fa557152ce486
Android.BackDoor.41 is an executable UNIX file designed to run on Android mobile devices. It is incorporated into Android.Backdoor.260.origin as an additional module and is used by this Trojan to install other components on the system.
Android.BackDoor.41 installs the “super” module into /system/bin and libnativeLoad.so and liblocSDK4b.so into /system/lib. Moreover, it stealthily installs the substrate_signed.apk application (Tool.Substrate.1.origin) and other modules of Android.Backdoor.260.origin on the infected device.