La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Android.Joker.265

Aggiunto al database dei virus Dr.Web: 2020-07-17

La descrizione è stata aggiunta:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Joker.156.origin
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) i.7####.org:80
  • TCP(HTTP/1.1) purchas####.club:80
  • TCP(TLS/1.0) 1####.177.14.95:443
  • TCP(TLS/1.0) api.face####.com:443
  • TCP(TLS/1.0) app-mea####.com:443
  • TCP(TLS/1.0) 7####.org:443
  • TCP(TLS/1.0) sett####.crashly####.com:443
  • TCP(TLS/1.0) i.7####.org:443
  • TCP(TLS/1.0) 2####.85.233.95:443
  • TCP(TLS/1.0) googl####.g.doublec####.net:443
  • TCP(TLS/1.2) 1####.194.73.94:443
  • TCP(TLS/1.2) 1####.194.73.95:443
  • TCP(TLS/1.2) 1####.177.14.95:443
  • TCP(TLS/1.2) 2####.85.233.100:443
DNS requests:
  • 7####.org
  • app-mea####.com
  • g####.face####.com
  • googl####.g.doublec####.net
  • i.7####.org
  • purchas####.club
  • sett####.crashly####.com
HTTP GET requests:
  • i.7####.org/300/b117361.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/b236931.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/b316414.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/b320569.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/b51745.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c130324.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c131777.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c135516.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c166817.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c170264.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c170764.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c173610.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c174699.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c174783.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c176439.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c176461.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c176523.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c176559.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c176605.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c176648.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c176664.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c177151.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c177472.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c177519.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c177705.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c177823.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/c40578.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/f51021773.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/f52532209.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/f52589357.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/f59194165.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/f65691190.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/f81022161.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g264364.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g358721.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g396699.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g433885.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g435008.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g532469.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g568919.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g633750.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g644048.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g667654.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g671117.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g694046.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g701547.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g785038.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g853465.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/g896554.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/h94073.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/i9873.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/m588730.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/n34573.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/r1057254.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/r1198205.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/r1204704.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/r866797.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/s398470.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/s64306.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/u353445.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/u363597.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/u404974.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/u407052.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/u408502.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/u409832.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/x141584.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/x163289.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/x169332.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/x45294.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/x89308.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/x92711.jpg?wd=####&hd=####&app=####
  • i.7####.org/300/z127636.jpg?wd=####&hd=####&app=####
HTTP POST requests:
  • purchas####.club/api/t/
  • purchas####.club/zaka/update123/
File system changes:
Creates the following files:
  • /data/data/####/04117ffc24becde08c18dabb4592ba09.0.tmp
  • /data/data/####/04117ffc24becde08c18dabb4592ba09.1.tmp
  • /data/data/####/06a20fa79e76bd55d781c8dfe2f6bb0d.0.tmp
  • /data/data/####/06a20fa79e76bd55d781c8dfe2f6bb0d.1.tmp
  • /data/data/####/072efd82675e91c13706498ebfe616c4.0.tmp
  • /data/data/####/072efd82675e91c13706498ebfe616c4.1.tmp
  • /data/data/####/09c6a74b840a3311_0
  • /data/data/####/0fbf3980a8adf2cccbcdf5bd3afe76d6.0.tmp
  • /data/data/####/0fbf3980a8adf2cccbcdf5bd3afe76d6.1.tmp
  • /data/data/####/1557357152169.dex
  • /data/data/####/1557357152169.dex.flock (deleted)
  • /data/data/####/1557357152169.jar
  • /data/data/####/1557357152169.tmp
  • /data/data/####/1c1dfb515099f7625e44bdf2c506096b.0.tmp
  • /data/data/####/1c1dfb515099f7625e44bdf2c506096b.1.tmp
  • /data/data/####/1e456e6e6f8fc4771ea75305ffa71c53.0.tmp
  • /data/data/####/1e456e6e6f8fc4771ea75305ffa71c53.1.tmp
  • /data/data/####/1ed6916db115ef26fefd021c71e4d7db.0.tmp
  • /data/data/####/1ed6916db115ef26fefd021c71e4d7db.1.tmp
  • /data/data/####/1f1b7fb18a0b5fec8c58e6ff4fedce15.0.tmp
  • /data/data/####/1f1b7fb18a0b5fec8c58e6ff4fedce15.1.tmp
  • /data/data/####/2315b53255e1227ccadd5c1d30efd121.0.tmp
  • /data/data/####/2315b53255e1227ccadd5c1d30efd121.1.tmp
  • /data/data/####/24b1a1f3d254cb6775bfb64aeacb057b.0.tmp
  • /data/data/####/24b1a1f3d254cb6775bfb64aeacb057b.1.tmp
  • /data/data/####/2ad1d2c3732d58cc224dfa7a123e128d.0.tmp
  • /data/data/####/2ad1d2c3732d58cc224dfa7a123e128d.1.tmp
  • /data/data/####/2cc27c84119d8349a2897053768ea307.0.tmp
  • /data/data/####/2cc27c84119d8349a2897053768ea307.1.tmp
  • /data/data/####/32884adcc7949b5e14284db7fcf25bc6.0.tmp
  • /data/data/####/32884adcc7949b5e14284db7fcf25bc6.1.tmp
  • /data/data/####/359aa5aef27d067f2ca14143f4bd6015.0.tmp
  • /data/data/####/359aa5aef27d067f2ca14143f4bd6015.1.tmp
  • /data/data/####/3a1f06d1001ed1b9c2147a8e695a1092.0.tmp
  • /data/data/####/3a1f06d1001ed1b9c2147a8e695a1092.1.tmp
  • /data/data/####/3e9433cedfa47dfd880cc97db9c96651.0.tmp
  • /data/data/####/3e9433cedfa47dfd880cc97db9c96651.1.tmp
  • /data/data/####/403a509e8b92fe43e9a079e4b2b0ad51.0.tmp
  • /data/data/####/403a509e8b92fe43e9a079e4b2b0ad51.1.tmp
  • /data/data/####/47056d6d9fbf623943a6a74a57063e93.0.tmp
  • /data/data/####/47056d6d9fbf623943a6a74a57063e93.1.tmp
  • /data/data/####/49d88aa689d13766f8397d2fdabbf4a1.0.tmp
  • /data/data/####/49d88aa689d13766f8397d2fdabbf4a1.1.tmp
  • /data/data/####/4d1855a6d93a4039204cf54a79044f51.0.tmp
  • /data/data/####/4d1855a6d93a4039204cf54a79044f51.1.tmp
  • /data/data/####/4ddb60f3a346b04e09c2b1d6f0c7661d.0.tmp
  • /data/data/####/4ddb60f3a346b04e09c2b1d6f0c7661d.1.tmp
  • /data/data/####/518b8bf9359d5865f1bc80a76c7e0da2.0.tmp
  • /data/data/####/518b8bf9359d5865f1bc80a76c7e0da2.1.tmp
  • /data/data/####/52e77fdccab14f32da52cf55eb25c6ba.0.tmp
  • /data/data/####/52e77fdccab14f32da52cf55eb25c6ba.1.tmp
  • /data/data/####/5412df68847fc2a12a4375662e624652.0.tmp
  • /data/data/####/5412df68847fc2a12a4375662e624652.1.tmp
  • /data/data/####/5994de34f96d88f8a59d7c9f908f9b9b.0.tmp
  • /data/data/####/5994de34f96d88f8a59d7c9f908f9b9b.1.tmp
  • /data/data/####/59a1182ef2f75f7120d3f287ef1c5878.0.tmp
  • /data/data/####/59a1182ef2f75f7120d3f287ef1c5878.1.tmp
  • /data/data/####/5F120F6400CA-0001-0D31-063B7360CE8FBeginSession.cls_temp
  • /data/data/####/5F120F6400CA-0001-0D31-063B7360CE8FSessionApp.cls_temp
  • /data/data/####/5F120F6400CA-0001-0D31-063B7360CE8FSessionDevice.cls
  • /data/data/####/5F120F6400CA-0001-0D31-063B7360CE8FSessionOS.cls_temp
  • /data/data/####/5F120F6400CA-0001-0D31-063B7360CE8FSessionUser.cls_temp
  • /data/data/####/5F120F6603A0-0001-0D72-063B7360CE8FBeginSession.cls_temp
  • /data/data/####/5F120F6603A0-0001-0D72-063B7360CE8FSessionApp.cls_temp
  • /data/data/####/5F120F6603A0-0001-0D72-063B7360CE8FSessionDevice.cls_temp
  • /data/data/####/5F120F6603A0-0001-0D72-063B7360CE8FSessionOS.cls_temp
  • /data/data/####/5a0aaa1101ee09e814ebebe405088301.0.tmp
  • /data/data/####/5a0aaa1101ee09e814ebebe405088301.1.tmp
  • /data/data/####/5f10934d8bbf33919d7824d20292c9f4.0.tmp
  • /data/data/####/5f10934d8bbf33919d7824d20292c9f4.1.tmp
  • /data/data/####/6712f4cb37eb2c7c8d632c7715d66666.0.tmp
  • /data/data/####/6712f4cb37eb2c7c8d632c7715d66666.1.tmp
  • /data/data/####/6a44b078ba91f08ce1fb0a6776b24809.0.tmp
  • /data/data/####/6a44b078ba91f08ce1fb0a6776b24809.1.tmp
  • /data/data/####/6aaa9d6e4e52637980abb992053d1ca8.0.tmp
  • /data/data/####/6aaa9d6e4e52637980abb992053d1ca8.1.tmp
  • /data/data/####/7279355ff54684999e72aac310d9fa9f.0.tmp
  • /data/data/####/7279355ff54684999e72aac310d9fa9f.1.tmp
  • /data/data/####/742bd8ac61604db2ac9670c0a067df0b.0.tmp
  • /data/data/####/742bd8ac61604db2ac9670c0a067df0b.1.tmp
  • /data/data/####/74c0a1fe9ff90585019db27980c91476.0.tmp
  • /data/data/####/74c0a1fe9ff90585019db27980c91476.1.tmp
  • /data/data/####/7b5965d679c3f5f9b0b72c99825f5c70.0.tmp
  • /data/data/####/7b5965d679c3f5f9b0b72c99825f5c70.1.tmp
  • /data/data/####/7ef7bfc309cfbd7694a1e681dbe52c8b.0.tmp
  • /data/data/####/7ef7bfc309cfbd7694a1e681dbe52c8b.1.tmp
  • /data/data/####/8269e3dbaa8de1e2b170ba3e42315cab.0.tmp
  • /data/data/####/8269e3dbaa8de1e2b170ba3e42315cab.1.tmp
  • /data/data/####/86b2f7caabf684d84d624c4bb66d2594.0.tmp
  • /data/data/####/86b2f7caabf684d84d624c4bb66d2594.1.tmp
  • /data/data/####/878c3ff627630d437d13765c01f6453f.0.tmp
  • /data/data/####/878c3ff627630d437d13765c01f6453f.1.tmp
  • /data/data/####/87de8198e621a2a79d8520c418d0d923.0.tmp
  • /data/data/####/87de8198e621a2a79d8520c418d0d923.1.tmp
  • /data/data/####/8a1e7195b11d63dd699085329cac1f30.0.tmp
  • /data/data/####/8a1e7195b11d63dd699085329cac1f30.1.tmp
  • /data/data/####/8eea1d6509d218729229fa27bbdea187.0.tmp
  • /data/data/####/8eea1d6509d218729229fa27bbdea187.1.tmp
  • /data/data/####/9163188811677dae153532f24328e99d.0.tmp
  • /data/data/####/9163188811677dae153532f24328e99d.1.tmp
  • /data/data/####/97392d6f91f5b672c5edfc66c3ccba3c.0.tmp
  • /data/data/####/97392d6f91f5b672c5edfc66c3ccba3c.1.tmp
  • /data/data/####/9e078eea2ec5fe33ce2b0442b8a0ffe4.0.tmp
  • /data/data/####/9e078eea2ec5fe33ce2b0442b8a0ffe4.1.tmp
  • /data/data/####/9f1072e74807fffcd78d8efc3e965e2d.0.tmp
  • /data/data/####/9f1072e74807fffcd78d8efc3e965e2d.1.tmp
  • /data/data/####/AppEventsLogger.persistedevents
  • /data/data/####/Cookies-journal
  • /data/data/####/JFIOW
  • /data/data/####/JFIOW.dex
  • /data/data/####/JFIOW.dex.flock (deleted)
  • /data/data/####/TwitterAdvertisingInfoPreferences.xml
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a035aaf5f87b7799998d17ba27cddb29.0.tmp
  • /data/data/####/a035aaf5f87b7799998d17ba27cddb29.1.tmp
  • /data/data/####/a5b9295b85142b491cf87401a2f453cd.0.tmp
  • /data/data/####/a5b9295b85142b491cf87401a2f453cd.1.tmp
  • /data/data/####/a7e427b420ff128bf517de0bc508ee1e.0.tmp
  • /data/data/####/a7e427b420ff128bf517de0bc508ee1e.1.tmp
  • /data/data/####/ac3b7d3e3d4efa4dbcd4d0028b9ef12c.0.tmp
  • /data/data/####/ac3b7d3e3d4efa4dbcd4d0028b9ef12c.1.tmp
  • /data/data/####/adfd48cff9b0a9b69e0d0b491ec749c9.0.tmp
  • /data/data/####/adfd48cff9b0a9b69e0d0b491ec749c9.1
  • /data/data/####/admob.xml
  • /data/data/####/b14181f619fc2d1b8648cd5a1b5278d0.0.tmp
  • /data/data/####/b14181f619fc2d1b8648cd5a1b5278d0.1.tmp
  • /data/data/####/c05a6c9e837a734f4dc4ca13263ac0c9.0.tmp
  • /data/data/####/c05a6c9e837a734f4dc4ca13263ac0c9.1.tmp
  • /data/data/####/c1464fa723ef0b839a0573172804c3d6.0.tmp
  • /data/data/####/c1464fa723ef0b839a0573172804c3d6.1.tmp
  • /data/data/####/c315a6ee6cf69298a2a920ff2d420a00.0.tmp
  • /data/data/####/c315a6ee6cf69298a2a920ff2d420a00.1.tmp
  • /data/data/####/c828c4623b7396db1105a9a8609e4b35.0.tmp
  • /data/data/####/c828c4623b7396db1105a9a8609e4b35.1.tmp
  • /data/data/####/c8a81727315df2db4d6613aa2998e1af.0.tmp
  • /data/data/####/c8a81727315df2db4d6613aa2998e1af.1.tmp
  • /data/data/####/cbfa6599417be7dee01f6847c4ffbbc0.0.tmp
  • /data/data/####/cbfa6599417be7dee01f6847c4ffbbc0.1.tmp
  • /data/data/####/ce08b92c8fb0be05c652702d461430a8.0.tmp
  • /data/data/####/ce08b92c8fb0be05c652702d461430a8.1.tmp
  • /data/data/####/cecc6e57312067d0f2e06d7dacbf8e5a.0.tmp
  • /data/data/####/cecc6e57312067d0f2e06d7dacbf8e5a.1.tmp
  • /data/data/####/ced7b30940bd233042a214528c319ce6.0.tmp
  • /data/data/####/ced7b30940bd233042a214528c319ce6.1.tmp
  • /data/data/####/com.crashlytics.prefs.xml
  • /data/data/####/com.crashlytics.sdk.android.crashlytics-core;co...re.xml
  • /data/data/####/com.crashlytics.sdk.android;answers;settings.xml
  • /data/data/####/com.crashlytics.settings.json
  • /data/data/####/com.facebook.internal.PURCHASE.xml
  • /data/data/####/com.facebook.internal.SKU_DETAILS.xml
  • /data/data/####/com.facebook.internal.preferences.APP_GATEKEEPERS.xml
  • /data/data/####/com.facebook.internal.preferences.APP_SETTINGS.xml
  • /data/data/####/com.facebook.sdk.appEventPreferences.xml
  • /data/data/####/com.facebook.sdk.attributionTracking.xml
  • /data/data/####/com.google.InstanceId.properties
  • /data/data/####/com.google.android.gms.appid-no-backup
  • /data/data/####/com.google.android.gms.appid.xml
  • /data/data/####/com.google.android.gms.measurement.prefs.xml
  • /data/data/####/com.google.android.gms.measurement.prefs.xml.bak
  • /data/data/####/com.tsoqbaefde.prettywallpapers_preferences.xml
  • /data/data/####/com.tsoqbaefde.prettywallpapers_preferences.xml.bak
  • /data/data/####/d3de4a71706aad6470fd3e62a91a2552.0.tmp
  • /data/data/####/d3de4a71706aad6470fd3e62a91a2552.1
  • /data/data/####/da4b5a7fb75359f5c964eabe15c58b11.0.tmp
  • /data/data/####/da4b5a7fb75359f5c964eabe15c58b11.1.tmp
  • /data/data/####/dae7b9107d469c68fcc985d5b0b87073.0.tmp
  • /data/data/####/dae7b9107d469c68fcc985d5b0b87073.1.tmp
  • /data/data/####/db95b3669e7105667afdba9f5e5eeb76.0.tmp
  • /data/data/####/db95b3669e7105667afdba9f5e5eeb76.1.tmp
  • /data/data/####/dfe6b2497a7513ba_0
  • /data/data/####/e4b3cf85db9c3bef353c78bdf831513b.0.tmp
  • /data/data/####/e4b3cf85db9c3bef353c78bdf831513b.1.tmp
  • /data/data/####/e9809414fe8ba9ce23127e9d7d010b5b.0.tmp
  • /data/data/####/e9809414fe8ba9ce23127e9d7d010b5b.1.tmp
  • /data/data/####/ece753785749c70fae384c728be7c3f4.0.tmp
  • /data/data/####/ece753785749c70fae384c728be7c3f4.1.tmp
  • /data/data/####/edf648fd820ca03c42d55923dc344617.0.tmp
  • /data/data/####/edf648fd820ca03c42d55923dc344617.1.tmp
  • /data/data/####/ef0e66df1e44b84a49e004757ea200f3.0.tmp
  • /data/data/####/ef0e66df1e44b84a49e004757ea200f3.1.tmp
  • /data/data/####/evernote_jobs.db
  • /data/data/####/evernote_jobs.db-journal
  • /data/data/####/evernote_jobs.xml
  • /data/data/####/f038e94cb33282ab_0
  • /data/data/####/f1742fc235d6c78d3e176bc7a6f65020.0.tmp
  • /data/data/####/f1742fc235d6c78d3e176bc7a6f65020.1.tmp
  • /data/data/####/f30b4e1d743e9cb8125bda342c2de819.0.tmp
  • /data/data/####/f30b4e1d743e9cb8125bda342c2de819.1.tmp
  • /data/data/####/f385dbdea1f6b5925e10f493563831e9.0.tmp
  • /data/data/####/f385dbdea1f6b5925e10f493563831e9.1.tmp
  • /data/data/####/f3f36574fbcc5b42d57b3a338166e5bc.0.tmp
  • /data/data/####/f3f36574fbcc5b42d57b3a338166e5bc.1.tmp
  • /data/data/####/f4e9e9b0d0dae3a4c622176e9700ff5d.0.tmp
  • /data/data/####/f4e9e9b0d0dae3a4c622176e9700ff5d.1.tmp
  • /data/data/####/f75572e7208ab9d54ebfadb96e6652c7.0.tmp
  • /data/data/####/f75572e7208ab9d54ebfadb96e6652c7.1.tmp
  • /data/data/####/f88137781eabeecdc1ac3cbd6c6d77a7.0.tmp
  • /data/data/####/f88137781eabeecdc1ac3cbd6c6d77a7.1.tmp
  • /data/data/####/fa250dadb2bf4a59bd90708402362bd9.0.tmp
  • /data/data/####/fa250dadb2bf4a59bd90708402362bd9.1.tmp
  • /data/data/####/fbe2397225a16ef7ad17f3df548ec31c.0.tmp
  • /data/data/####/fbe2397225a16ef7ad17f3df548ec31c.1.tmp
  • /data/data/####/fff48efad00cb715ec14735eec1af048.0.tmp
  • /data/data/####/fff48efad00cb715ec14735eec1af048.1.tmp
  • /data/data/####/fon.db-journal
  • /data/data/####/google_app_measurement.db-journal
  • /data/data/####/google_app_measurement_local.db
  • /data/data/####/google_app_measurement_local.db-journal
  • /data/data/####/index
  • /data/data/####/initialization_marker
  • /data/data/####/io.fabric.sdk.android;fabric;io.fabric.sdk.andr...ng.xml
  • /data/data/####/journal
  • /data/data/####/main.xml
  • /data/data/####/main.xml.bak
  • /data/data/####/metrics_guid
  • /data/data/####/pref.xml
  • /data/data/####/sa_5ca6e1e0-b76c-4192-b6f2-2025a545aed3_1595019110332.tap
  • /data/data/####/sa_b99c7708-0c59-4958-a45c-231d43ab13e8_1595019112281.tap
  • /data/data/####/session_analytics.tap
  • /data/data/####/session_analytics.tap.tmp
  • /data/data/####/the-real-index
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86_64 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86_64 --instruction-set-features=default --dex-file=/data/user/0/<Package>/cache/1557357152169.jar --oat-fd=70 --oat-location=/data/user/0/<Package>/cache/1557357152169.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86_64 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86_64 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/JFIOW --oat-fd=51 --oat-location=/data/user/0/<Package>/cache/oct/JFIOW.dex --compiler-filter=speed
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
Accesses the ITelephony private interface.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about accounts associated with the device (Google, Facebook, etc.).
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.
Intercepts notifications.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android