La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Android.DownLoader.5061

Aggiunto al database dei virus Dr.Web: 2021-06-30

La descrizione è stata aggiunta:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Click.311.origin
  • Android.DownLoader.1007.origin
  • Android.Mobifun.29.origin
  • Android.Mobifun.30.origin
  • Android.Mobifun.32.origin
  • Android.RemoteCode.306.origin
  • Android.RemoteCode.6122
  • Android.SmsBot.752.origin
  • Android.Triada.4567
  • Android.Triada.4937
  • Android.Triada.510.origin
  • Android.Triada.537.origin
  • Android.Triada.553.origin
  • Android.Triada.566.origin
Downloads the following detected threats from the Internet:
  • Android.Click.311.origin
  • Android.Mobifun.32.origin
  • Android.RemoteCode.306.origin
  • Android.RemoteCode.6122
  • Android.SmsBot.752.origin
  • Android.Triada.510.origin
  • Android.Triada.553.origin
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) log.koapk####.com:80
  • TCP(HTTP/1.1) b.scoreca####.com:80
  • TCP(HTTP/1.1) 13.2####.16.115:8081
  • TCP(HTTP/1.1) 3####.i####.com:12310
  • TCP(HTTP/1.1) n####.fitness####.top:80
  • TCP(HTTP/1.1) d.moce####.com:9091
  • TCP(HTTP/1.1) z4####.ep####.com:13002
  • TCP(HTTP/1.1) jz####.mc####.com:12029
  • TCP(HTTP/1.1) 50.1####.11.47:80
  • TCP(HTTP/1.1) www.d####.xyz:80
  • TCP(HTTP/1.1) y####.k8####.com:80
  • TCP(HTTP/1.1) api.mobitec####.xyz:80
  • TCP(HTTP/1.1) d.moce####.com:80
  • TCP(HTTP/1.1) p####.pay####.com:80
  • TCP(HTTP/1.1) api.applove####.com:80
  • TCP(HTTP/1.1) n####.um####.top:80
  • TCP(HTTP/1.1) api.bi####.com:80
  • TCP(HTTP/1.1) d####.dd7####.com:80
  • TCP(HTTP/1.1) sty.zk####.com:80
  • TCP(HTTP/1.1) cdn.ve####.com:80
  • TCP(HTTP/1.1) z4####.ep####.com:14002
  • TCP(HTTP/1.1) t####.c8####.com:13002
  • TCP(HTTP/1.1) hw9####.new####.com:80
  • TCP(HTTP/1.1) z.c####.com:80
  • TCP(TLS/1.0) crb.k####.com:443
  • TCP(TLS/1.0) tc.airmo####.com:443
  • TCP(TLS/1.0) gd.a.s####.com:443
  • TCP(TLS/1.0) api.mobitec####.xyz:443
  • TCP(TLS/1.0) wcf.seven####.com:443
  • TCP(TLS/1.0) f####.google####.com:443
  • TCP(TLS/1.0) rgk.zu####.cn:443
  • TCP(TLS/1.0) z.c####.com:443
  • TCP(TLS/1.0) bigcl####.zhuifen####.top:443
  • TCP(TLS/1.0) discuzf####.site:443
  • TCP(TLS/1.0) digice####.rubicon####.com.####.net:443
  • TCP(TLS/1.0) cm.g.doublec####.net:443
  • TCP(TLS/1.0) match####.ad####.org:443
  • TCP(TLS/1.0) eus.rubicon####.com.####.net:443
  • TCP(TLS/1.0) creativ####.com:443
  • TCP(TLS/1.0) 1####.250.102.95:443
  • TCP(TLS/1.0) md####.google####.com:443
  • TCP(TLS/1.0) cm.lentain####.com:443
  • TCP(TLS/1.0) x.bidsw####.net:443
  • TCP(TLS/1.0) fo####.site:443
  • TCP(TLS/1.0) lp.xl####.com:443
  • TCP(TLS/1.0) iflexf####.com:443
  • TCP(TLS/1.0) jsc.m####.com:443
  • TCP(TLS/1.0) img.gamedis####.com:443
  • TCP(TLS/1.0) c####.pay####.com:443
  • TCP(TLS/1.0) 5.ah####.com:443
  • TCP(TLS/1.0) b.scoreca####.com:443
  • TCP(TLS/1.0) v1####.oss-cn-####.aliy####.com:443
  • TCP(TLS/1.0) im####.tab####.com:443
  • TCP(TLS/1.0) www.qq####.ltd:443
  • TCP(TLS/1.0) 7.z####.top:443
  • TCP(TLS/1.0) cm.idealm####.io:443
  • TCP(TLS/1.2) 1####.250.102.94:443
  • TCP(TLS/1.2) 1####.250.102.100:443
  • TCP(TLS/1.2) 1####.250.102.95:443
  • UDP 1####.250.102.95:443
DNS requests:
  • 3####.i####.com
  • 5.ah####.com
  • 7.z####.top
  • api.applove####.com
  • api.bi####.com
  • api.dc.tkcre####.com
  • api.mobitec####.xyz
  • api.news-he####.co
  • api.s####.com
  • b.scoreca####.com
  • bigcl####.zhuifen####.top
  • c####.pay####.com
  • c.m####.com
  • cdn.m####.com
  • cdn.ve####.com
  • cm.g.doublec####.net
  • cm.idealm####.io
  • cm.lentain####.com
  • cm.m####.com
  • crb.k####.com
  • creativ####.com
  • d####.dd7####.com
  • d.moce####.com
  • discuzf####.site
  • eus.rubicon####.com
  • f####.google####.com
  • fo####.site
  • hw9####.new####.com
  • iflexf####.com
  • im####.tab####.com
  • img.gamedis####.com
  • jsc.m####.com
  • jz####.mc####.com
  • log.koapk####.com
  • lp.xl####.com
  • m####.ad####.org
  • md####.google####.com
  • n####.fitness####.top
  • n####.um####.top
  • ne####.s####.com
  • nu####.js####.com
  • p####.pay####.com
  • pv.s####.com
  • rgk.zu####.cn
  • s####.m####.com
  • sb.scoreca####.com
  • secure-####.rubicon####.com
  • serv####.m####.com
  • sty.zk####.com
  • t####.c8####.com
  • tc.airmo####.com
  • v####.6####.com
  • v1####.oss-cn-####.aliy####.com
  • wcf.seven####.com
  • www.d####.xyz
  • www.qq####.ltd
  • x####.g####.com
  • x####.g####.com
  • x.bidsw####.net
  • y####.k8####.com
  • yh####.zhuifen####.top
  • yh####.zhuifen####.top.####.8
  • z12.c####.com
  • z2.c####.com
  • z3.c####.com
  • z4####.ep####.com
  • z5.c####.com
  • z9.c####.com
HTTP GET requests:
  • api.applove####.com/api/v3/cache/get?osv=####&srnc=####&token=####&ds=##...
  • api.applove####.com/api/v3/search/get?osv=####&token=####&pm=####&os=###...
  • api.applove####.com/api/v3/template/get?slot_id=####&update_time=####&us...
  • api.mobitec####.xyz/v1.1/HR080720NT/document/get?type=####&user_ip=####&...
  • api.mobitec####.xyz/v1.1/HR316NT/document/get?type=####&user_ip=####&ua=...
  • b.scoreca####.com/beacon.js
  • cdn.ve####.com/cocoDY/app-5329125.zip
  • cdn.ve####.com/dtbx/yeahmobi/app-release-0317.zip
  • cdn.ve####.com/dy/emapp-v2.zip
  • cdn.ve####.com/hwyw/sdljow39ws9w38ref985.zip
  • cdn.ve####.com/plugins/dp2.zip
  • cdn.ve####.com/plugins/yz058Uc30i628.zip
  • d####.dd7####.com/upload/hw/D10049dex20190529.jar
  • d####.dd7####.com/upload/hw/batdex20191010.jar
  • d####.dd7####.com/upload/hw/c1005dex20190527.jar
  • d####.dd7####.com/upload/hw/kklz02dex20200414.jar
  • d####.dd7####.com/upload/hw/lsdk20200506.jar
  • d####.dd7####.com/upload/plog/game1212.jar
  • d####.dd7####.com/upload/plog/jar20190515.jar
  • d####.dd7####.com/upload/plog/kk20201106.jar
  • d####.dd7####.com/upload/plog/sdk0625.jar
  • d####.dd7####.com/upload/plog/skk20210416.jar
  • d####.dd7####.com/upload/plog/xianmm0512.jar
  • d####.dd7####.com/upload/plog/yeah0510.jar
  • n####.fitness####.top/favicon.ico
  • n####.fitness####.top/games/DesertRoad.html
  • n####.fitness####.top/r.html
  • n####.fitness####.top/static/dist/css/detailv2.css
  • n####.fitness####.top/static/dist/js/ads-detail.js
  • n####.um####.top/
  • n####.um####.top/favicon.ico
  • n####.um####.top/zepto.min.js
  • p####.pay####.com/s-r/332/60063a81055a8
  • y####.k8####.com/hwyw/nkumcor.zip
  • y####.k8####.com/zhuti/6Y24shdjshdkshc.zip
  • z.c####.com/stat.htm?id=####&cnzz_eid=####
HTTP POST requests:
  • 3####.i####.com:12310/el206fx/
  • 3####.i####.com:12310/l7bpbnl/
  • 3####.i####.com:12310/meq3r3z/
  • api.bi####.com/un
  • d.moce####.com/wap/gateway
  • d.moce####.com:9091/wap/gateway
  • hw9####.new####.com/api/activite
  • hw9####.new####.com/api/tbdynamic
  • jz####.mc####.com:12029/hfdlls/
  • jz####.mc####.com:12029/i3v8nb/
  • jz####.mc####.com:12029/lfkdnr/
  • log.koapk####.com/pgm/sr/gm/gy
  • sty.zk####.com/cc/v1/api?sid=####
  • t####.c8####.com:13002/4ad8fq/
  • t####.c8####.com:13002/lgu4ds/
  • www.d####.xyz/Orders/getlive?channel=####&Slevi=####&anmac=####&anosv=##...
  • z4####.ep####.com:13002/4ad8fq/
  • z4####.ep####.com:13002/a7atzr/
  • z4####.ep####.com:13002/lgu4ds/
  • z4####.ep####.com:14002/a2jyco/
  • z4####.ep####.com:14002/ajnhz5/
  • z4####.ep####.com:14002/uv2tay/
File system changes:
Creates the following files:
  • /data/data/####/.m
  • /data/data/####/.t
  • /data/data/####/007fa86f97f8f769_0
  • /data/data/####/011134986548f3458aa3e7e2a7fceb8d
  • /data/data/####/07922d09ed5f137e_0
  • /data/data/####/0c23c2870c87d54c_0
  • /data/data/####/1.dex
  • /data/data/####/1.dex.flock (deleted)
  • /data/data/####/1.jar
  • /data/data/####/103225dpa
  • /data/data/####/103225dpa.dex
  • /data/data/####/103225dpa.dex.flock (deleted)
  • /data/data/####/109201jvy
  • /data/data/####/109201jvy.dex
  • /data/data/####/109201jvy.dex.flock (deleted)
  • /data/data/####/1D2ECA4D2366CF6371FF735881567A01
  • /data/data/####/2021_06_30readzibao.xml
  • /data/data/####/2033D7433CBA2BE0B8BB8B222807D877.dex
  • /data/data/####/2033D7433CBA2BE0B8BB8B222807D877.dex.flock (deleted)
  • /data/data/####/20DEB631D7FEF78CBB01A5210DAB31E1.dex
  • /data/data/####/20DEB631D7FEF78CBB01A5210DAB31E1.dex.flock (deleted)
  • /data/data/####/20DEB631D7FEF78CBB01A5210DAB31E1.jar
  • /data/data/####/30CF515C7CB78484C87197F4EF54417B
  • /data/data/####/323e68b02c1ba9ed10a1577555b8daf6
  • /data/data/####/34fec97d0c3c2322_0
  • /data/data/####/37599f2b0e03a23d_0
  • /data/data/####/395ddf330601ee85_0
  • /data/data/####/45f8ae3573d46f20_0
  • /data/data/####/4fd966615e6d4bc8_0
  • /data/data/####/53a6586a659c646c_0
  • /data/data/####/53a6586a659c646c_0 (deleted)
  • /data/data/####/5b1fe178f18e67e6_0
  • /data/data/####/5b1fe178f18e67e6_1
  • /data/data/####/633433a63e863cbf_0
  • /data/data/####/652d02a403725528_0
  • /data/data/####/66c36b768ec850fd_0
  • /data/data/####/6eb9b8c978169d65_0
  • /data/data/####/712B3A72BC84BE358148C5F3D1780018.dex
  • /data/data/####/712B3A72BC84BE358148C5F3D1780018.dex.flock (deleted)
  • /data/data/####/75c4161650b81ec9cc60c23a9af31c6e.xml
  • /data/data/####/76e5c7ebb8d59f70_0
  • /data/data/####/7836585BA5B236EA6F3C0BFC13122292.dex (deleted)
  • /data/data/####/7836585BA5B236EA6F3C0BFC13122292.dex.flock (deleted)
  • /data/data/####/7836585BA5B236EA6F3C0BFC13122292.jar
  • /data/data/####/7be847b137db9603_0
  • /data/data/####/7d4f7dfb9663794d_0
  • /data/data/####/8868e3b0215cba35ff1c9f4ff5c9df77
  • /data/data/####/90fcea5881ba139b_0
  • /data/data/####/93f7e29102bc5419_0
  • /data/data/####/9454C5CB868992BD1B29C8D1BA6DFD36.dex
  • /data/data/####/9454C5CB868992BD1B29C8D1BA6DFD36.dex.flock (deleted)
  • /data/data/####/957dcdb894d228ee_0
  • /data/data/####/995C95CF1BC24E3170EC135A878B2D7B.dex
  • /data/data/####/995C95CF1BC24E3170EC135A878B2D7B.dex.flock (deleted)
  • /data/data/####/99877.dex
  • /data/data/####/99877.dex (deleted)
  • /data/data/####/99877.dex.flock (deleted)
  • /data/data/####/99877.jar
  • /data/data/####/99877aaa
  • /data/data/####/99877aaa.dex
  • /data/data/####/99877aaa.dex (deleted)
  • /data/data/####/99877aaa.dex.flock (deleted)
  • /data/data/####/9C26A376E364BE82A9D96ECE9D817C63.dex
  • /data/data/####/9C26A376E364BE82A9D96ECE9D817C63.dex.flock (deleted)
  • /data/data/####/9e31ab134df45432_0
  • /data/data/####/9e31ab134df45432_0 (deleted)
  • /data/data/####/A690152C11F2E473CA1264F4658AC6C0
  • /data/data/####/AJVohiFD.xml
  • /data/data/####/BFDB36197AD62250D717DC665B6B32FF
  • /data/data/####/C5A4543D83D1F1096AB0EED4A3CA89EE.dex
  • /data/data/####/C5A4543D83D1F1096AB0EED4A3CA89EE.dex.flock (deleted)
  • /data/data/####/Cookies-journal
  • /data/data/####/D10049dex20190529.dex
  • /data/data/####/D10049dex20190529.dex.flock (deleted)
  • /data/data/####/EAF23804542C00F84ACD3828835CB14B.dex
  • /data/data/####/EAF23804542C00F84ACD3828835CB14B.dex.flock (deleted)
  • /data/data/####/EB52888EFB3AC8E303C8832480A52509.dex
  • /data/data/####/EB52888EFB3AC8E303C8832480A52509.dex.flock (deleted)
  • /data/data/####/EC0DA9876DC2A33B72C2A6BBEE1FE801.dex
  • /data/data/####/EC0DA9876DC2A33B72C2A6BBEE1FE801.dex.flock (deleted)
  • /data/data/####/EC0DA9876DC2A33B72C2A6BBEE1FE801.jar
  • /data/data/####/EE3D4E0EA36A873E21A899A983DE7B56.dex
  • /data/data/####/EE3D4E0EA36A873E21A899A983DE7B56.dex.flock (deleted)
  • /data/data/####/EE3D4E0EA36A873E21A899A983DE7B56.jar
  • /data/data/####/F2E2B77256C5B8D15F9E9738F49E5F8A
  • /data/data/####/FE7C072A3E9803151B6BFAFEDB0AC33C.dex
  • /data/data/####/FE7C072A3E9803151B6BFAFEDB0AC33C.dex.flock (deleted)
  • /data/data/####/FE7C072A3E9803151B6BFAFEDB0AC33C.jar
  • /data/data/####/MobikokCommonConfig.xml
  • /data/data/####/MobikokDeviceConfig.xml
  • /data/data/####/RDEwMjM5_iuy_data.xml
  • /data/data/####/RDEwMjM5_uuid_data.xml
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a0.d
  • /data/data/####/a30627c14af560ed_0
  • /data/data/####/a3dbd06de37dcd58dc86b7fc5ee17cab.xml
  • /data/data/####/a77b560200c09907_0
  • /data/data/####/aa1dc02f14bd694ad17d1f188edfa210
  • /data/data/####/ab953bc209a067df_0
  • /data/data/####/af8fa188f5b024c46569eeaddebe1f32.xml
  • /data/data/####/af8fa188f5b024c46569eeaddebe1f32.xml.bak
  • /data/data/####/as_aa.xml
  • /data/data/####/as_aa.xml.bak
  • /data/data/####/base.apk
  • /data/data/####/base.dex
  • /data/data/####/base.dex.flock (deleted)
  • /data/data/####/batdex20191010.dex
  • /data/data/####/batdex20191010.dex.flock (deleted)
  • /data/data/####/bc316a62f30fa0816798444f19deb86a.d
  • /data/data/####/be17ca2d5fa41151aedcf115afbfa22c.xml
  • /data/data/####/bf005dea9dd54ffea10790ccdb9539d6
  • /data/data/####/by_dis_sadfsadfads.xml
  • /data/data/####/by_dis_sadfsadfads.xml.bak (deleted)
  • /data/data/####/by_rewfrenfio2pj.ertwe
  • /data/data/####/by_werjklgewjrfer.xml
  • /data/data/####/c1005dex20190527.dex
  • /data/data/####/c1005dex20190527.dex.flock (deleted)
  • /data/data/####/c34a4c3h54e6_ntyjbsdr
  • /data/data/####/c34a4c3h54e6_z5h768e5n89g768x0u87e0j7i8a56756o....7c567e
  • /data/data/####/com.cc.iuo.fefew.try.の.s3u4b34f3f4_btybgfbjgf
  • /data/data/####/com.wagd.tku_ct_default.xml
  • /data/data/####/com.wagd.tku_preferences.xml
  • /data/data/####/com.wagd.tkuye_after_install_pkg.xml
  • /data/data/####/commaincvmvvv.
  • /data/data/####/commaincvmvvv.dex
  • /data/data/####/commaincvmvvv.dex.flock (deleted)
  • /data/data/####/commainxvw2c3w5m2i2an2.2
  • /data/data/####/commainxvw2c3w5m2i2an2.dex
  • /data/data/####/commainxvw2c3w5m2i2an2.dex.flock (deleted)
  • /data/data/####/cso.xml
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e038e17b0e57b6ecc...0e1356
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e038e17b0e57b6ecc...6cache
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e06951c391-1611-4...83b735
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e06951c391-1611-4...leted)
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e09071e7e2-9ded-4...3f.dex
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e09071e7e2-9ded-4...a2053f
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e09071e7e2-9ded-4...leted)
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0a539f0747d432ad...45eb4c
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0a539f0747d432ad...leted)
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0b6cb96745f47e9c...65f071
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0b6cb96745f47e9c...leted)
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0fa496ba8-c93e-4...22.dex
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0fa496ba8-c93e-4...34c122
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0fa496ba8-c93e-4...leted)
  • /data/data/####/d291155f857b9ae7a3697094138469ac.d
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0065f8ea5-7ff2-4...335988
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0065f8ea5-7ff2-4...88.dex
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0065f8ea5-7ff2-4...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e02f3176a8-1076-4...65caa2
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e02f3176a8-1076-4...a2.dex
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e02f3176a8-1076-4...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e038e17b0e57b6ecc...0e1356
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e038e17b0e57b6ecc...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0626ef02e3ec8360...0cache
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0626ef02e3ec8360...fbd310
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0668834a64f3f65d...0361be
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0668834a64f3f65d...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0737f29df-4ecd-4...e0.dex
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0737f29df-4ecd-4...f151e0
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0737f29df-4ecd-4...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0788325cc-5797-4...81.dex
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0788325cc-5797-4...d62a81
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0788325cc-5797-4...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e07bd85be31372d8d...be7608
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e07bd85be31372d8d...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0800f460d-a6df-4...1c.dex
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0800f460d-a6df-4...a38e1c
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0800f460d-a6df-4...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e094914311-d95d-4...cd.dex
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e094914311-d95d-4...efe0cd
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e094914311-d95d-4...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0c81d6971-1553-4...36.dex
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0c81d6971-1553-4...581c36
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0c81d6971-1553-4...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0d9950357cb51efb...6a4399
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0d9950357cb51efb...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0e59457e3575aab6...1cache
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0e59457e3575aab6...9cfde1
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0e763cf9a-cab0-4...f827fc
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0e763cf9a-cab0-4...fc.dex
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0e763cf9a-cab0-4...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0ebe5b97612e530b...1b9fe0
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0ebe5b97612e530b...leted)
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0f7549b1613be968...1cache
  • /data/data/####/d32253dd858111eb8cdbb8599f4fd9e0f7549b1613be968...bae0a1
  • /data/data/####/d8192e68e16cb20287ec75a318c686d1.xml
  • /data/data/####/data.dex
  • /data/data/####/data.dex.flock (deleted)
  • /data/data/####/data.jar
  • /data/data/####/dd8315697578eca7_0
  • /data/data/####/dsas.png
  • /data/data/####/dws3esr.xml
  • /data/data/####/dws3esr.xml.bak
  • /data/data/####/dws3esr.xml.bak (deleted)
  • /data/data/####/e130b00538abaa06_0
  • /data/data/####/e3grd43rd.data-journal
  • /data/data/####/e3t6rsd.data-journal
  • /data/data/####/e6700dd970cc2c21_0
  • /data/data/####/ecea103f3b3d39f3_0
  • /data/data/####/edae8a21c95c1722_0
  • /data/data/####/edaf00b783a9574b_0
  • /data/data/####/el.xml
  • /data/data/####/f46bd295e6a190c4_0
  • /data/data/####/fa065dc043822981_0
  • /data/data/####/faef094efc404d87_0
  • /data/data/####/fb9dd01690a0d1ddbce9e527fb32207f.xml
  • /data/data/####/fb9dd01690a0d1ddbce9e527fb32207f.xml.bak
  • /data/data/####/game1212.dex
  • /data/data/####/game1212.dex.flock (deleted)
  • /data/data/####/gameid
  • /data/data/####/gameid.zip
  • /data/data/####/gopm.xml
  • /data/data/####/gt5eer.xml
  • /data/data/####/gt5eer.xml.bak
  • /data/data/####/gt5eer.xml.bak (deleted)
  • /data/data/####/iavi.txt.xml
  • /data/data/####/iavi.txt.xml.bak
  • /data/data/####/index
  • /data/data/####/jar20190515.dex
  • /data/data/####/jar20190515.dex.flock (deleted)
  • /data/data/####/jm.xml
  • /data/data/####/kk20201106.dex
  • /data/data/####/kk20201106.dex.flock (deleted)
  • /data/data/####/kklz02dex20200414.dex
  • /data/data/####/kklz02dex20200414.dex.flock (deleted)
  • /data/data/####/ktdc.xml
  • /data/data/####/libdsbx.so
  • /data/data/####/libdsbx.so-32
  • /data/data/####/libdsbx.so-64
  • /data/data/####/libnav-6mdw2z.so
  • /data/data/####/libpbfd.so
  • /data/data/####/libpbfd.so-32
  • /data/data/####/libpbfd.so-64
  • /data/data/####/lob.xml
  • /data/data/####/lsdk20200506.dex
  • /data/data/####/lsdk20200506.dex.flock (deleted)
  • /data/data/####/lx.xml
  • /data/data/####/metrics_guid
  • /data/data/####/mq.xml
  • /data/data/####/mt.xml
  • /data/data/####/oniow
  • /data/data/####/oyhx.png
  • /data/data/####/pl_config.xml
  • /data/data/####/readzibao.xml
  • /data/data/####/s1s1k1_c2o3n23f2i3g2.xml
  • /data/data/####/s3p43_4z5he6n4g6x45u7e890jp-i00-ao-0.xml
  • /data/data/####/s3p43_4z5he6n4g6x45u7e890jp-i00-ao-0.xml.bak
  • /data/data/####/s3p43_tyjhtyhyrtyrty.xml
  • /data/data/####/s3p43_tyjhtyhyrtyrty.xml.bak
  • /data/data/####/sb-2021-06-28-11-14-14.dex
  • /data/data/####/sb-2021-06-28-11-14-14.dex.flock (deleted)
  • /data/data/####/sbtyu76j7ui78pi7_6i7c8i78i78oin78fi76i8ig78i7.xml
  • /data/data/####/sdk0625.dex
  • /data/data/####/sdk0625.dex.flock (deleted)
  • /data/data/####/skk20210416.dex
  • /data/data/####/skk20210416.dex.flock (deleted)
  • /data/data/####/sp.xml
  • /data/data/####/sp_dojz.xml
  • /data/data/####/sp_quin.xml
  • /data/data/####/sp_quin.xml.bak
  • /data/data/####/sp_ramgq.xml
  • /data/data/####/sp_rmwwpn.xml
  • /data/data/####/sp_rmwwpn.xml.bak
  • /data/data/####/sp_toov.xml
  • /data/data/####/sp_toov.xml.bak
  • /data/data/####/sp_ucukoz.xml
  • /data/data/####/sp_ucukoz.xml.bak
  • /data/data/####/sp_uenzy.xml
  • /data/data/####/sp_uenzy.xml.bak
  • /data/data/####/sp_uybzk.xml
  • /data/data/####/sp_uybzk.xml.bak
  • /data/data/####/sr.xml
  • /data/data/####/tchi.xml
  • /data/data/####/the-real-index
  • /data/data/####/ts_od.db
  • /data/data/####/ts_od.db-journal
  • /data/data/####/uma.xml
  • /data/data/####/uuid_data.xml
  • /data/data/####/wdc_data.xml
  • /data/data/####/wpd.db
  • /data/data/####/wpd.db-journal
  • /data/data/####/xfksgku
  • /data/data/####/xianmm0512.dex
  • /data/data/####/xianmm0512.dex.flock (deleted)
  • /data/data/####/xwps_d.xml
  • /data/data/####/xwps_d.xml.bak
  • /data/data/####/yeah0510.dex
  • /data/data/####/yeah0510.dex.flock (deleted)
  • /data/data/####/zmd.xml
  • /data/media/####/.apqt
  • /data/media/####/.hs
  • /data/media/####/.moon
  • /data/media/####/.owpt
  • /data/media/####/.vck
  • /data/media/####/.vwuw
  • /data/media/####/.wmgs
  • /data/media/####/.yc
  • /data/media/####/03F28E3824BF1807FB798611113FAAE4
  • /data/media/####/2021_06_30zibao
  • /data/media/####/2033D7433CBA2BE0B8BB8B222807D877
  • /data/media/####/2033D7433CBA2BE0B8BB8B222807D877.temp
  • /data/media/####/2033D7433CBA2BE0B8BB8B222807D877.zip
  • /data/media/####/47AB7209AD7ACF4EB1EA636A3039D803
  • /data/media/####/55549805EE12FF0275696B4E18ED4BA7
  • /data/media/####/5FBD524893B6AD91F2EA5615B685EB64
  • /data/media/####/712B3A72BC84BE358148C5F3D1780018
  • /data/media/####/712B3A72BC84BE358148C5F3D1780018.jar
  • /data/media/####/712B3A72BC84BE358148C5F3D1780018.temp
  • /data/media/####/9454C5CB868992BD1B29C8D1BA6DFD36
  • /data/media/####/9454C5CB868992BD1B29C8D1BA6DFD36.jar
  • /data/media/####/9454C5CB868992BD1B29C8D1BA6DFD36.temp
  • /data/media/####/995C95CF1BC24E3170EC135A878B2D7B
  • /data/media/####/995C95CF1BC24E3170EC135A878B2D7B.temp
  • /data/media/####/995C95CF1BC24E3170EC135A878B2D7B.zip
  • /data/media/####/9C26A376E364BE82A9D96ECE9D817C63
  • /data/media/####/9C26A376E364BE82A9D96ECE9D817C63.jar
  • /data/media/####/9C26A376E364BE82A9D96ECE9D817C63.temp
  • /data/media/####/C5A4543D83D1F1096AB0EED4A3CA89EE
  • /data/media/####/C5A4543D83D1F1096AB0EED4A3CA89EE.jar
  • /data/media/####/C5A4543D83D1F1096AB0EED4A3CA89EE.temp
  • /data/media/####/C8E46E6710F24F9AA6039B838AC7B723
  • /data/media/####/Config.txt
  • /data/media/####/D10049dex20190529.jar
  • /data/media/####/DC49A25FBC0DD1147ED02FB9AC181FE6
  • /data/media/####/E67117254EE1AF76D256AEE5D84A91BE
  • /data/media/####/E8B32184F8AB9B74FB932DD52CC981DB
  • /data/media/####/EAF23804542C00F84ACD3828835CB14B
  • /data/media/####/EAF23804542C00F84ACD3828835CB14B.temp
  • /data/media/####/EAF23804542C00F84ACD3828835CB14B.zip
  • /data/media/####/EB52888EFB3AC8E303C8832480A52509
  • /data/media/####/EB52888EFB3AC8E303C8832480A52509.temp
  • /data/media/####/EB52888EFB3AC8E303C8832480A52509.zip
  • /data/media/####/batdex20191010.jar
  • /data/media/####/c1005dex20190527.jar
  • /data/media/####/du
  • /data/media/####/ehqo
  • /data/media/####/fcqk
  • /data/media/####/game1212.jar
  • /data/media/####/gtq
  • /data/media/####/ihap
  • /data/media/####/isreadzibao
  • /data/media/####/jar20190515.jar
  • /data/media/####/jctr
  • /data/media/####/kk20201106.jar
  • /data/media/####/kklz02dex20200414.jar
  • /data/media/####/ks
  • /data/media/####/lsdk20200506.jar
  • /data/media/####/ndpy
  • /data/media/####/nyug
  • /data/media/####/sdk0625.jar
  • /data/media/####/skk20210416.jar
  • /data/media/####/tgov
  • /data/media/####/wk
  • /data/media/####/xbjr
  • /data/media/####/xianmm0512.jar
  • /data/media/####/yeah0510.jar
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • app_process /system/bin com.android.commands.pm.Pm list package -3
  • cat /proc/version
  • cat /sys/class/net/wlan0/address
  • getprop ro.bootimage.build.date.utc
  • getprop ro.build.description
  • getprop ro.build.fingerprint
  • getprop ro.build.product
  • getprop ro.build.version.all_codenames
  • getprop ro.sf.lcd_density
  • getprop ro.yunos.build.version
  • sh
Loads the following dynamic libraries:
  • oniow
  • xfksgku
Uses the following algorithms to encrypt data:
  • AES
  • AES-CBC-PKCS5Padding
  • DES-CBC-PKCS5Padding
  • RSA-None-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES
  • AES-CBC-PKCS5Padding
  • DES-CBC-PKCS5Padding
  • RSA-None-PKCS1Padding
  • desede-CBC-PKCS5Padding
Accesses the ITelephony private interface.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Adds tasks to the system scheduler.
Requests the system alert window permission.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android