La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Android.DownLoader.4852

Aggiunto al database dei virus Dr.Web: 2020-03-26

La descrizione è stata aggiunta:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Backdoor.719.origin
  • Android.DownLoader.906.origin
  • Android.DownLoader.909.origin
  • Android.Mobifun.11.origin
  • Android.RemoteCode.262.origin
  • Android.RemoteCode.277.origin
  • Android.RemoteCode.6122
  • Android.Triada.4567
  • Android.Triada.467.origin
  • Android.Triada.477.origin
  • Android.Triada.491.origin
Downloads the following detected threats from the Internet:
  • Android.Backdoor.719.origin
  • Android.DownLoader.909.origin
  • Android.RemoteCode.262.origin
  • Android.RemoteCode.277.origin
  • Android.RemoteCode.6122
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) 4####.79.35.115:80
  • TCP(HTTP/1.1) new.faceboo####.com:80
  • TCP(HTTP/1.1) ti.domainf####.com:80
  • TCP(HTTP/1.1) cdn.lk####.com:80
  • TCP(HTTP/1.1) 4####.ur####.xyz:80
  • TCP(HTTP/1.1) api.bi####.com:80
  • TCP(HTTP/1.1) lives####.h####.com:80
  • TCP(HTTP/1.1) api.e####.com:80
  • TCP(HTTP/1.1) 3.1####.84.154:8001
  • TCP(HTTP/1.1) sdk.5g####.net:80
  • TCP(HTTP/1.1) cdn.dd####.com:8080
  • TCP(HTTP/1.1) a####.app####.com:80
  • TCP(HTTP/1.1) ba####.juicyt####.com:80
  • TCP(HTTP/1.1) api.melo####.com:80
  • TCP(HTTP/1.1) w0####.iw####.com:12038
  • TCP(HTTP/1.1) jz####.mc####.com:12029
  • TCP(HTTP/1.1) qs####.1k####.com:11027
  • TCP(HTTP/1.1) fff.abcdse####.com:8666
  • TCP(HTTP/1.1) dl3.ur####.xyz:80
  • TCP(HTTP/1.1) api.e####.com:5001
  • TCP(HTTP/1.1) without####.com:80
  • TCP(HTTP/1.1) z.c####.com:80
  • TCP(HTTP/1.1) sty.zk####.com:80
  • TCP(HTTP/1.1) ks####.3q####.com:12038
  • TCP(HTTP/1.1) d####.f####.top:8080
  • TCP(HTTP/1.1) cdn1203####.qini####.com:80
  • TCP(HTTP/1.1) ggg.koapk####.com:80
  • TCP(HTTP/1.1) x####.g####.com:8808
  • TCP(HTTP/1.1) 13.2####.16.115:8081
  • TCP(HTTP/1.1) V2####.98####.com:10091
  • TCP(HTTP/1.1) tpc.googles####.com:80
  • TCP(HTTP/1.1) api.f####.com:80
  • TCP(HTTP/1.1) s####.us####.cdnetw####.net:80
  • TCP(HTTP/1.1) at.al####.com:80
  • TCP(HTTP/1.1) s3####.ur####.xyz:80
  • TCP(HTTP/1.1) d####.dd7####.com:80
  • TCP(HTTP/1.1) cdn.lk####.com:8080
  • TCP(SSL/3.0) s####.mat####.com:443
  • TCP(SSL/3.0) s####.1rx.io:443
  • TCP(SSL/3.0) gl####.px.quants####.com:443
  • TCP(SSL/3.0) s####.tubem####.com:443
  • TCP(SSL/3.0) g.geo####.com:443
  • TCP(SSL/3.0) d####.a####.com:443
  • TCP(TLS/1.0) pixel-####.sites####.com:443
  • TCP(TLS/1.0) p####.everest####.net:443
  • TCP(TLS/1.0) d####.a####.com:443
  • TCP(TLS/1.0) lives####.h####.com:443
  • TCP(TLS/1.0) y####.h####.com:443
  • TCP(TLS/1.0) pugm220####.pubm####.com:443
  • TCP(TLS/1.0) tpc.googles####.com:443
  • TCP(TLS/1.0) securep####.g.doublec####.net:443
  • TCP(TLS/1.0) a.msst####.com.####.com:443
  • TCP(TLS/1.0) n0####.cumulus####.com:443
  • TCP(TLS/1.0) 2-01-27####.cdx.ced####.net:443
  • TCP(TLS/1.0) afp.do####.weig####.####.net:443
  • TCP(TLS/1.0) www.face####.com:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) me####.h####.com:443
  • TCP(TLS/1.0) log.lk####.com:443
  • TCP(TLS/1.0) s.m####.com:7777
  • TCP(TLS/1.0) p####.ybp.y####.com:443
  • TCP(TLS/1.0) lp.cooktra####.com:443
  • TCP(TLS/1.0) dsum####.casalem####.com.####.net:443
  • TCP(TLS/1.0) fcm####.go####.com:443
  • TCP(TLS/1.0) s0.2####.net:443
  • TCP(TLS/1.0) con####.face####.net:443
  • TCP(TLS/1.0) googl####.g.doublec####.net:443
  • TCP(TLS/1.0) d5p.d####.com:443
  • TCP(TLS/1.0) g####.n####.com:443
  • TCP(TLS/1.0) s####.tubem####.com:443
  • TCP(TLS/1.0) g.geo####.com:443
  • TCP(TLS/1.0) gcm.ctn####.com:443
  • TCP(TLS/1.0) f####.google####.com:443
  • TCP(TLS/1.0) st####.xx.f####.net:443
  • TCP(TLS/1.0) id.r####.com:443
  • TCP(TLS/1.0) gl####.px.quants####.com:443
  • TCP(TLS/1.0) s####.1rx.io:443
  • TCP(TLS/1.0) c####.cloudf####.com:443
  • TCP(TLS/1.0) abc.lk####.com:443
  • TCP(TLS/1.0) adser####.go####.nl:443
  • TCP(TLS/1.0) eu####.3####.com:443
  • TCP(TLS/1.0) trac####.m6r.eu.####.net:443
  • TCP(TLS/1.0) p####.ups-a####.aolp-ds####.####.cloud:443
  • TCP(TLS/1.0) pag####.googles####.com:443
  • TCP(TLS/1.0) cdn.amppro####.org:443
  • TCP(TLS/1.0) cdn1203####.qini####.com:443
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.0) adser####.go####.com:443
  • TCP(TLS/1.0) f####.gst####.com:443
  • TCP(TLS/1.0) p####.rubicon####.com:443
  • TCP(TLS/1.0) odr.moo####.com:443
  • TCP(TLS/1.0) s####.mat####.com:443
  • TCP(TLS/1.0) c####.pay####.com:443
  • TCP(TLS/1.0) j2w####.zeta####.ak####.net:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) www.gst####.com:443
  • TCP(TLS/1.0) rtb.o####.net:443
  • TCP(TLS/1.0) ade.googles####.com:443
  • TCP(TLS/1.0) fcm####.you####.com:443
  • TCP(TLS/1.0) bcd.lk####.com:443
  • TCP(TLS/1.0) mok####.com:443
DNS requests:
  • 4####.ur####.xyz
  • 77.149.227.####.arpa
  • V2####.98####.com
  • a####.app####.com
  • a.msst####.com
  • abc.lk####.com
  • ade.googles####.com
  • adser####.go####.com
  • adser####.go####.nl
  • api.bi####.com
  • api.e####.com
  • api.f####.com
  • api.melo####.com
  • at.al####.com
  • ba####.juicyt####.com
  • bcd.lk####.com
  • c####.cloudf####.com
  • c####.pay####.com
  • cdn####.f####.top
  • cdn.amppro####.org
  • cdn.dd####.com
  • cdn.lk####.com
  • cm.g.doublec####.net
  • cms.quants####.com
  • con####.face####.net
  • d####.dd7####.com
  • d####.f####.top
  • d####.f####.top
  • d.a####.com
  • d.faceboo####.com
  • d5p.d####.com
  • dclk-m####.do####.com
  • di####.pubna####.net
  • dl3.ur####.xyz
  • dsum####.casalem####.com
  • e.dlx.add####.com
  • eb2.3####.com
  • f####.google####.com
  • f####.gst####.com
  • fcm####.go####.com
  • fcm####.you####.com
  • fff.abcdse####.com
  • g####.bestv####.cc
  • gcm.ctn####.com
  • ggg.koapk####.com
  • googl####.g.doublec####.net
  • google####.g.doublec####.net
  • google2####.ne####.com
  • h####.c####.com
  • hd.h####.com
  • ib.a####.com
  • id.r####.com
  • im####.pubm####.com
  • jz####.mc####.com
  • ks####.3q####.com
  • lives####.h####.com
  • log.lk####.com
  • lp.cooktra####.com
  • me####.h####.com
  • mok####.com
  • mt####.go####.com
  • n0####.cumulus####.com
  • new.faceboo####.com
  • odr.moo####.com
  • p####.adverti####.com
  • p####.everest####.net
  • p####.rubicon####.com
  • p####.ybp.y####.com
  • pag####.googles####.com
  • pixel-####.sites####.com
  • qs####.1k####.com
  • r.faceboo####.com
  • re####.ur####.xyz
  • rtb.o####.net
  • s####.1rx.io
  • s####.mat####.com
  • s.dailyre####.com
  • s.m####.com
  • s0.2####.net
  • s3####.ur####.xyz
  • sdk.5g####.net
  • securep####.g.doublec####.net
  • so####.sp####.com
  • ssb####.smartad####.com
  • ssum####.casalem####.com
  • st####.xx.f####.net
  • stati####.msst####.com
  • sty.zk####.com
  • syn####.everest####.net
  • t####
  • ti.domainf####.com
  • tpc.googles####.com
  • trac####.m6r.eu
  • um.w####.net
  • w0####.iw####.com
  • without####.com
  • www.am####.com
  • www.face####.com
  • www.go####.com
  • www.google-####.com
  • www.googlet####.com
  • www.googlet####.com
  • www.gst####.com
  • x####.g####.com
  • x####.g####.com
  • y####.h####.com
  • y####.k8####.com
  • z12.c####.com
  • z2.c####.com
  • z3.c####.com
  • z5.c####.com
  • z6.c####.com
HTTP GET requests:
  • 4####.ur####.xyz/getInitConfig?sysVer=####&networkType=####&iso=####&ime...
  • a####.app####.com/aff_c?offer_id=####&aff_id=####&aff_click_id=####&unid...
  • a####.app####.com/aff_r?offer_id=71814&aff_id=28816&url=http://direct.pu...
  • api.f####.com/co?u=####&s=####&gaid=####&imei=####&androidId=####&at=###...
  • api.melo####.com/api/v4/click?campaign_id=####&publisher_id=####&rt=####...
  • at.al####.com/t/font_633469_vsn760jskh.ttf?t=####
  • cdn.dd####.com:8080/group1/M01/00/07/ChmjBl3PvQaAMCZEAATSRRTWghE496.enc
  • cdn.lk####.com/anzb/2we9s349w8si34w93498eso.zip
  • cdn.lk####.com/dtjz/lz1016.zip
  • cdn.lk####.com/dtjz/xu310.jar
  • cdn.lk####.com/traffic-racer/?channelid=####
  • cdn.lk####.com/wp-content/themes/sokidaTheme/css/mobile.css?v=####
  • cdn.lk####.com/wp-content/themes/sokidaTheme/css/public/bootstrap.min.css
  • cdn.lk####.com/wp-content/themes/sokidaTheme/css/public/font-awesome.min...
  • cdn.lk####.com/wp-content/themes/sokidaTheme/css/public/nprogress.css
  • cdn.lk####.com/wp-content/themes/sokidaTheme/css/public/reset.css
  • cdn.lk####.com/wp-content/themes/sokidaTheme/css/theme.css?v=####
  • cdn.lk####.com/wp-content/themes/sokidaTheme/fonts/fontawesome-webfont.t...
  • cdn.lk####.com/wp-content/themes/sokidaTheme/images/top.png
  • cdn.lk####.com/wp-content/themes/sokidaTheme/js/CustomAds.js
  • cdn.lk####.com/wp-content/themes/sokidaTheme/js/public/bootstrap.min.js
  • cdn.lk####.com/wp-content/themes/sokidaTheme/js/public/echo.js
  • cdn.lk####.com/wp-content/themes/sokidaTheme/js/public/jquery-1.11.2.min...
  • cdn.lk####.com/wp-content/themes/sokidaTheme/js/public/nprogress.js
  • cdn.lk####.com/wp-content/themes/sokidaTheme/js/public/swiper/swiper.min...
  • cdn.lk####.com/wp-content/themes/sokidaTheme/js/shejiwo.js?v=####
  • cdn.lk####.com/wp-content/uploads/2020/02/11Ninja-Parkour-Trial1-300x300...
  • cdn.lk####.com/wp-content/uploads/2020/02/152-happy-parkour1-300x300-1.jpg
  • cdn.lk####.com/wp-content/uploads/2020/02/165-elf-jungle-parkour1-300x30...
  • cdn.lk####.com/wp-content/uploads/2020/02/183-gold-miner-excavator1-300x...
  • cdn.lk####.com/wp-content/uploads/2020/02/186-vertical-drop1-300x300-1.jpg
  • cdn.lk####.com/wp-content/uploads/2020/02/262-traffic-racer1-300x300-1.jpg
  • cdn.lk####.com/wp-content/uploads/2020/02/264-rabbit-samurai1-300x300-1....
  • cdn.lk####.com/wp-content/uploads/2020/03/favicon.ico
  • cdn.lk####.com/wp-content/uploads/2020/03/sokiDa.jpg
  • cdn.lk####.com/wp-includes/css/dist/block-library/style.min.css?ver=####
  • cdn.lk####.com/wp-includes/js/wp-embed.min.js?ver=####
  • cdn.lk####.com:8080/nicro/6b60ae568647d2b3679775518d97c691
  • cdn1203####.qini####.com/hw04-31.y
  • d####.dd7####.com/upload/hw/D10049dex20190529.jar
  • d####.dd7####.com/upload/hw/D10173dex20190919.jar
  • d####.dd7####.com/upload/hw/batdex20191010.jar
  • d####.dd7####.com/upload/hw/c1005dex20190527.jar
  • d####.dd7####.com/upload/hw/h5rq20191022.jar
  • d####.dd7####.com/upload/hw/infodex20190814.jar
  • d####.dd7####.com/upload/hw/kkdex20200108.jar
  • d####.dd7####.com/upload/hw/nextdex20190326.jar
  • d####.dd7####.com/upload/hw/qcdex20200316.jar
  • d####.dd7####.com/upload/hw/qshw20200111.jar
  • d####.dd7####.com/upload/hw1/CJAR20190515.jar
  • d####.f####.top:8080/ttad/api/getAd/CYeTtNvOLESCbbHsZFUAWw==
  • d####.f####.top:8080/ttad/api/jv5/CYeTtNvOLESCbbHsZFUAWw==/BCD2BFB24B8A4...
  • dl3.ur####.xyz/1584327394337.jar
  • lives####.h####.com/iframe/16141475
  • s####.us####.cdnetw####.net/app/t2/assets/crypto-js.min.js
  • s####.us####.cdnetw####.net/app/t2/images/2019072308354276064.png
  • s####.us####.cdnetw####.net/app/t2/images/Magic-Run.jpg
  • s####.us####.cdnetw####.net/app/t2/images/TacticalSquad1.png
  • s####.us####.cdnetw####.net/app/t2/images/TacticalSquad2.png
  • s####.us####.cdnetw####.net/app/t2/images/UFORUN1.png
  • s####.us####.cdnetw####.net/app/t2/jquery-2.1.1.min.js
  • s####.us####.cdnetw####.net/app/t2/static/dist/css/basis.min.css?v=####
  • s####.us####.cdnetw####.net/app/t2/static/dist/css/detail-v2.min.css
  • s####.us####.cdnetw####.net/app/t2/static/dist/css/font_633469_vsn760jsk...
  • s####.us####.cdnetw####.net/app/t2/static/dist/images/border-img.png
  • s####.us####.cdnetw####.net/app/t2/static/dist/js/flexible.min.js
  • s####.us####.cdnetw####.net/app/t2/static/dist/js/util.js?v=####
  • s3####.ur####.xyz/api/getOffer?androidId=####&imsi=####&sch=####&ch=####...
  • ti.domainf####.com/st/alt?appnm=####&idad=####&insrcpn=####&idapp=####&o...
  • ti.domainf####.com/st/hg?mapid=####&ssizen=####&amb=####&plsysat=####&av...
  • tpc.googles####.com/sodar/sodar2.js
  • without####.com/api/v1/sa?act=####&domain=####&chid=####&template_id=###...
  • without####.com/assets/pwa.js
  • without####.com/favicon.ico
  • without####.com/template1/detail.html?q=####
  • x####.g####.com:8808/a/e?a=####
  • z.c####.com/stat.htm?id=####&cnzz_eid=####
HTTP POST requests:
  • 4####.ur####.xyz/searchReport
  • V2####.98####.com:10091/wisdom/marking
  • api.bi####.com/un
  • api.e####.com/config
  • api.e####.com:5001/get_c
  • ba####.juicyt####.com/sdk/v2/ofr/g_o_d_s5z2de3z5d6e9m1np?a=####
  • fff.abcdse####.com:8666/bd/getIp
  • ggg.koapk####.com/pgm/sr/gm/gy
  • jz####.mc####.com:12029/hfdlls/
  • jz####.mc####.com:12029/i3v8nb/
  • jz####.mc####.com:12029/iw0nnw/
  • jz####.mc####.com:12029/lfkdnr/
  • ks####.3q####.com:12038/neisdop/
  • new.faceboo####.com/index.php?r=####
  • qs####.1k####.com:11027/kd92kx/
  • qs####.1k####.com:11027/mskeww/
  • sdk.5g####.net/sdk/v2/ofr/g_o_d_s5z2de3z5d6e9m1np?a=####
  • sdk.5g####.net/sdk/v2/p/u_n_b2t6z5i2j56xa3zq1qf?a=####
  • sdk.5g####.net/sdk/v2/r_z_c_w2z5dw2aa3m5ll7u31?a=####
  • sty.zk####.com/cc/v1/api?sid=####
  • w0####.iw####.com:12038/iowncjk/
  • w0####.iw####.com:12038/pwjdaae/
  • x####.g####.com:8808/a/f
File system changes:
Creates the following files:
  • /data/data/####/0-c
  • /data/data/####/0-e
  • /data/data/####/0-f
  • /data/data/####/0-g
  • /data/data/####/0437750A541C5BE283568783752E76EF.xml
  • /data/data/####/04B69214746C416CA629FE15C2A7FC4A.xml
  • /data/data/####/0BFDEFEB708580BC2A81DCB3F81D1F7B.xml
  • /data/data/####/1-d
  • /data/data/####/1.jar
  • /data/data/####/2-d
  • /data/data/####/2078793401
  • /data/data/####/246045666.jar
  • /data/data/####/2a95f0c5-7aef-4e4a-9304-4e2389f9abaa.jar
  • /data/data/####/65D01155FE444F4EA2F8949B14E5555A.xml
  • /data/data/####/6A6BAFBF0A883B3CDE5430D882F6E490.xml
  • /data/data/####/6B59C67F4E3E07A0E22570B1D54BDC87.xml
  • /data/data/####/741bacaad0b7466594df6d923923967a
  • /data/data/####/79d0d4d1bac64b2d89cc15adb60eac7b
  • /data/data/####/8083FF58735015297E7624C9CFAC3D8C.xml
  • /data/data/####/9D53E3047D79D6D0DA0719B207D5D7E3.xml
  • /data/data/####/Cju0OGxGE-2p8PgJ2pw17s.0
  • /data/data/####/FBE8EAA155EBF69A221EC40557B7648E.xml
  • /data/data/####/Ka3D0B2oYALWjEsC6ikcR7.0
  • /data/data/####/MobikokCommonConfig.xml
  • /data/data/####/MobikokDeviceConfig.xml
  • /data/data/####/POST_DATA.xml
  • /data/data/####/_p.xml
  • /data/data/####/_sh.xml
  • /data/data/####/a215ec66894a0f38609ac53d26883909.jar
  • /data/data/####/appsflyer-data.xml
  • /data/data/####/as_aa.xml
  • /data/data/####/base.apk
  • /data/data/####/c1d051984a6a2bdb48368beb7b7b7190.d
  • /data/data/####/cached_ad_list.xml
  • /data/data/####/cached_offer_list.xml
  • /data/data/####/cmtbmx
  • /data/data/####/cnhmeghdjhkgi.xml
  • /data/data/####/com.dfc.sza_preferences.xml
  • /data/data/####/com.salmon.xml
  • /data/data/####/com.uutils.prefs.xml
  • /data/data/####/config.xml
  • /data/data/####/data.jar
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/db61e876.xml
  • /data/data/####/dojrya
  • /data/data/####/eb9005176242923167b577981a25e143.d
  • /data/data/####/f87f8be5
  • /data/data/####/f9660920.jar
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/fasdaaf.data-journal
  • /data/data/####/ftp_19230601.log
  • /data/data/####/gameid
  • /data/data/####/gameid.zip
  • /data/data/####/h5module_event_log
  • /data/data/####/hv.xml
  • /data/data/####/idd.xml
  • /data/data/####/ihdfhb.jar
  • /data/data/####/index
  • /data/data/####/iwswwewsdsw.xml
  • /data/data/####/j
  • /data/data/####/jgcsearq.jar
  • /data/data/####/jrswdsew.data-journal
  • /data/data/####/libcvub.so
  • /data/data/####/libcvub.so-32
  • /data/data/####/libcvub.so-64
  • /data/data/####/libcvub.so-64 (deleted)
  • /data/data/####/libnav-3wx9zw.so
  • /data/data/####/libnav-6mdw2z.so
  • /data/data/####/lob.xml
  • /data/data/####/lob.xml.bak
  • /data/data/####/mprefer.sdk.db-journal
  • /data/data/####/mysps.xml
  • /data/data/####/nczn.png
  • /data/data/####/npms_dex.jar
  • /data/data/####/oniow
  • /data/data/####/pl_config.xml
  • /data/data/####/qjuwel
  • /data/data/####/request_info.xml
  • /data/data/####/rq_file.xml
  • /data/data/####/rq_p.xml
  • /data/data/####/sdk_scl_pid_config.xml
  • /data/data/####/sp_h5module.xml
  • /data/data/####/sr_agent_log
  • /data/data/####/sunn.jar
  • /data/data/####/sunn.tmp (deleted)
  • /data/data/####/sunn.x
  • /data/data/####/susvq.jar
  • /data/data/####/uuid_data.xml
  • /data/data/####/ver.ini.xml
  • /data/data/####/wdc_data.xml
  • /data/data/####/wdwwswaws.data-journal
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/webviewCookiesChromiumPrivate.db-journal
  • /data/data/####/wesedsta.xml
  • /data/data/####/wpd.db
  • /data/data/####/wpd.db-journal
  • /data/data/####/xuah.xml
  • /data/data/####/xx_c_s_t_20081331.xml
  • /data/data/####/yd_config_c.xml
  • /data/media/####/.aqdv
  • /data/media/####/.nomedia
  • /data/media/####/.udusid
  • /data/media/####/.vbef
  • /data/media/####/039eeeb7ee0044a875140d5cee36d814.temp
  • /data/media/####/25135A325E72315E9DD5C88FE7D66B5C.jar
  • /data/media/####/25135A325E72315E9DD5C88FE7D66B5C.temp
  • /data/media/####/592BDF65_3EBEA8EE.txt
  • /data/media/####/59fc0bd011e9bd86911a7064b51269c3.xml
  • /data/media/####/72325AF753D81B643267C1A6C3CA9824
  • /data/media/####/7E40FDC80A33B861CDFFAA6B9CAC0772
  • /data/media/####/83D6B3DF0E9B3448C437685A7A14553A.jar
  • /data/media/####/83D6B3DF0E9B3448C437685A7A14553A.temp
  • /data/media/####/8B429B1E846352DD62AAB4044983D14B
  • /data/media/####/93FF5E4215E2D69DE25BFDB87ADB5BF3.temp
  • /data/media/####/93FF5E4215E2D69DE25BFDB87ADB5BF3.zip
  • /data/media/####/CJAR20190515.jar
  • /data/media/####/Config.txt
  • /data/media/####/D10049dex20190529.jar
  • /data/media/####/D10173dex20190919.jar
  • /data/media/####/EE46838F_2BDB3C8F.txt
  • /data/media/####/_pn
  • /data/media/####/_shn
  • /data/media/####/batdex20191010.jar
  • /data/media/####/c1005dex20190527.jar
  • /data/media/####/de6a20aa7f2e36fb6abe61de5fb464b1_93.de
  • /data/media/####/dec7ced136e69ac0302028773e22e28f.temp
  • /data/media/####/global.xml
  • /data/media/####/h5rq20191022.jar
  • /data/media/####/i
  • /data/media/####/infodex20190814.jar
  • /data/media/####/j
  • /data/media/####/kkdex20200108.jar
  • /data/media/####/nextdex20190326.jar
  • /data/media/####/pfg.xml
  • /data/media/####/qcdex20200316.jar
  • /data/media/####/qshw20200111.jar
  • /data/media/####/use.xml
  • /data/media/####/web.apk
  • /data/media/####/webadlist_1.cache
  • /data/media/####/webadlist_1.xml
  • /data/media/####/webadlist_1_last.cache
  • /data/media/####/webinfo.xml
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/cat /proc/cpuinfo
  • cat /proc/cpuinfo
  • cat /proc/version
  • cat /sys/class/net/wlan0/address
  • getprop
  • getprop net.dns1
  • getprop persist.sys.timezone
  • getprop ro.board.platform
  • getprop ro.product.cpu.abi
  • ping -c 3 -w 6 www.amazon.com
  • ps
  • sh -c getprop net.dns1
  • sh -c getprop persist.sys.timezone
Loads the following dynamic libraries:
  • cmtbmx
  • libcvub
  • libnav-3wx9zw
  • oniow
Uses the following algorithms to encrypt data:
  • AES
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-ECB-PKCS5Padding
  • DES
  • DES-CBC-PKCS5Padding
  • DES-ECB-NoPadding
  • DESede
  • Des-ECB-NoPadding
  • RSA-ECB-PKCS1Padding
  • RSA-None-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-CFB-NoPadding
  • AES-ECB-PKCS5Padding
  • DES
  • DES-CBC-PKCS5Padding
  • DES-ECB-NoPadding
  • DESede
  • Des-ECB-NoPadding
  • RSA-ECB-PKCS1Padding
  • RSA-None-PKCS1Padding
Accesses the ITelephony private interface.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Gets information about running apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android