SHA1:
- bb99a43937248fa0f5144a1a209af3e6216ba7c6
It is the /data/system/.loki/liblokih.so library that is used by other Trojans belonging to the Android.Loki family.
The library is incorporated into the system_server process by the Android.Loki.3 Trojan. Then it downloads the /data/system/.loki/lokisdk.jar file, retrieves the com.loki.sdk.SDKEntry class, and runs the entry method.