An Android malware sample called "RedAlert" was found in the wild. The malware is known to collect data from infected phones and turns them to a remote controlled bots. You have to find out the address of the Command & Control (CC) server of the bots.
The permissions are stored in the manifest.xml file of the apk package. I’ll use the aapt tool to dump the permissions.
Just a short check about the permissions looks very dangerous. The package can read and write sms messages:
Now we can open the package in jadx-gui and check for strings that looks like an URL.
Maybe the CC Server URL will add a string from the list above. I’ll upload the apk file to virus total and get this graph: Note: We can see the string /stbi