La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Android.Triada.5245

Aggiunto al database dei virus Dr.Web: 2022-02-22

La descrizione è stata aggiunta:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Triada.573.origin
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) gat####.funbl####.io:80
  • TCP(HTTP/1.1) ip####.com:80
  • TCP(HTTP/1.1) api.applove####.com:80
  • TCP(TLS/1.0) s.openmed####.com:443
  • TCP(TLS/1.0) acco####.go####.com:443
  • TCP(TLS/1.0) wild####.moa####.com.####.net:443
  • TCP(TLS/1.0) tls.vu####.edges####.net:443
  • TCP(TLS/1.0) res.z####.com:443
  • TCP(TLS/1.0) api-acc####.edges####.net:443
  • TCP(TLS/1.0) api.applove####.com:443
  • TCP(TLS/1.0) mt####.ray####.com:443
  • TCP(TLS/1.0) wcf.seven####.com:443
  • TCP(TLS/1.0) cdn.app####.com:443
  • TCP(TLS/1.0) adc-ad-####.ad####.com:443
  • TCP(TLS/1.0) www.you####.com:443
  • TCP(TLS/1.0) a####.go####.com:443
  • TCP(TLS/1.0) adc3-la####.adco####.com:443
  • TCP(TLS/1.0) firebas####.google####.com:443
  • TCP(TLS/1.0) pla####.google####.com:443
  • TCP(TLS/1.0) net.ray####.com:443
  • TCP(TLS/1.0) f####.gst####.com:443
  • TCP(TLS/1.0) fk-set####.ray####.com:443
  • TCP(TLS/1.0) digital####.google####.com:443
  • TCP(TLS/1.0) gd.a.s####.com:443
  • TCP(TLS/1.0) unit####.edges####.net:443
  • TCP(TLS/1.2) f####.gst####.com:443
  • TCP(TLS/1.2) pla####.google####.com:443
  • TCP(TLS/1.2) firebas####.google####.com:443
  • TCP d16qllj####.cloudf####.net:443
  • TCP f####.gst####.com:443
  • TCP analyti####.minte####.net:9377
  • TCP analy####.ray####.com:443
  • TCP d2####.2usrq####.com:443
DNS requests:
  • a####.go####.com
  • acco####.go####.com
  • adc-ad-####.ad####.com
  • adc3-la####.adco####.com
  • ads.api.vu####.com
  • analy####.ray####.com
  • analyti####.minte####.net
  • and####.google####.com
  • api.applove####.com
  • api.vu####.com
  • cd####.vu####.com
  • cdn.app####.com
  • co####.unit####.uni####.com
  • confi####.ray####.com
  • d####.fl####.com
  • d16qllj####.cloudf####.net
  • d2####.2usrq####.com
  • digital####.google####.com
  • f####.gst####.com
  • firebas####.google####.com
  • gat####.funbl####.io
  • ip####.com
  • m####.go####.com
  • mt####.ray####.com
  • net.ray####.com
  • pla####.google####.com
  • pv.s####.com
  • res.z####.com
  • s.openmed####.com
  • ssl.gst####.com
  • wcf.seven####.com
  • web####.unit####.uni####.com
  • www.google####.com
  • www.you####.com
  • z.moa####.com
HTTP GET requests:
  • adc-ad-####.ad####.com:443/launch/__controllers__/4.0.0/3.2.2.0/controll...
  • api-acc####.edges####.net:443/api/v5/new?ifa=####&app_id=####
  • api.applove####.com/api/v3/template/get?slot_id=####&update_time=####&us...
  • api.applove####.com:443/api/v3/pagead/get?osv=####&srnc=####&token=####&...
  • api.applove####.com:443/video/v4/ad/get?osv=####&srnc=####&token=####&ds...
  • api.applove####.com:443/video/v4/creative/get?osv=####&ispre=####&srnc=#...
  • cdn.app####.com:443/tools/sdk/confign/nativeads_new/2.5.9/native_ads_con...
  • cdn.app####.com:443/tools/sdk/confign/rewarded/2.5.9/rewarded_config.txt
  • cdn.app####.com:443/tools/sdk/langs/2.4.4/langs.json
  • fk-set####.ray####.com:443/rewardsetting?app_id=####&sign=####&open=####...
  • fk-set####.ray####.com:443/rewardsetting?app_id=####&sign=####&unit_ids=...
  • fk-set####.ray####.com:443/setting?app_id=####&sign=####&open=####&chann...
  • fk-set####.ray####.com:443/setting?unit_ids=####&app_id=####&sign=####&o...
  • gat####.funbl####.io/config/client?cc=####&appType=####&osType=####&grou...
  • gd.a.s####.com:443/cityjson
  • ip####.com/json/?lang=####
  • mt####.ray####.com:443/2021/0629/confirmDialog-2b9fddb88412e09a244a9bb41...
  • res.z####.com:443/1576833642421_5566250.mp4
  • res.z####.com:443/1579245869408_竖屏1.mp4
  • res.z####.com:443/1588922659811_1579245843203_640x640.jpg
  • tls.vu####.edges####.net:443/assets/6180b09d627987001693a67b/icon.png
  • tls.vu####.edges####.net:443/templates/defaults/img/4.5-stars.svg
  • tls.vu####.edges####.net:443/templates/defaults/img/vungle.svg
  • tls.vu####.edges####.net:443/templates/e2a809f2d2f817c93129ebe0c03a2f93....
  • tls.vu####.edges####.net:443/zen/95dfbee756d0d75d41978e8157597534.mp4-27...
  • unit####.edges####.net:443/webview/3.4.6/release/config.json?ts=####&sdk...
  • unit####.edges####.net:443/webview/3.4.6/release/index.html
  • wild####.moa####.com.####.net:443/VNG/android/fe5b19d/status.json?ts=###...
HTTP POST requests:
  • adc3-la####.adco####.com:443/v4/launch
  • api-acc####.edges####.net:443/api/v5/ads
  • api-acc####.edges####.net:443/config
  • firebas####.google####.com:443/v1/projects/vnow-831a7/installations
  • net.ray####.com:443/openapi/ad/v5?app_id=####&unit_id=####&placement_id=...
  • s.openmed####.com:443/init?v=####&plat=####&sdkv=####&k=####
  • s.openmed####.com:443/om/wf?v=####&plat=####&sdkv=####
File system changes:
Creates the following files:
  • /data/data/####/.YFlurrySenderIndex.info.AnalyticsData_PW4WPX7H...Q8_311
  • /data/data/####/.YFlurrySenderIndex.info.StreamingMain
  • /data/data/####/.old_file_converted
  • /data/data/####/.yflurrydatasenderblock.fbb4f486-145c-4705-8bf2...b759ca
  • /data/data/####/0.f1cc21b6.png
  • /data/data/####/026ae9c9824b3e483fa6c71fa88f57ae27816141
  • /data/data/####/0f88c08ea611aef3_0
  • /data/data/####/0f88c08ea611aef3_0 (deleted)
  • /data/data/####/0f88c08ea611aef3_1
  • /data/data/####/10.2bb9f35b.png
  • /data/data/####/19a4681e1e71d91d_0
  • /data/data/####/19a4681e1e71d91d_1
  • /data/data/####/1e4983bf64f52d46_0
  • /data/data/####/1e4983bf64f52d46_1
  • /data/data/####/2.4cd3348d.png
  • /data/data/####/20.384794c3.png
  • /data/data/####/21.c4eb42f3.png
  • /data/data/####/212dc9bf918f8c04_0 (deleted)
  • /data/data/####/22e85a2e1b1a8433_0
  • /data/data/####/22e85a2e1b1a8433_1
  • /data/data/####/3.573fbdd2.png
  • /data/data/####/30.2f9b85ba.png
  • /data/data/####/31.bd0c9b93.png
  • /data/data/####/32.b87222f1.png
  • /data/data/####/34.3e058ec1.png
  • /data/data/####/35.c6ebd6d5.png
  • /data/data/####/36.8f6e0baa.png
  • /data/data/####/37.3b529239.png
  • /data/data/####/38.4ed29b65.png
  • /data/data/####/4.5-stars.svg
  • /data/data/####/4.ed8132d6.png
  • /data/data/####/40.21b86cf6.png
  • /data/data/####/42.acd7421f.png
  • /data/data/####/43.084356dc.png
  • /data/data/####/431PF-5FXfvcnv63N5eKpNRhzoFuSVVoBy2XcgWrl08=
  • /data/data/####/431PF-5FXfvcnv63N5eKpNRhzoFuSVVoBy2XcgWrl08=.vng_meta
  • /data/data/####/44.52f0a3a1.png
  • /data/data/####/45.f2af0356.png
  • /data/data/####/46.b0ef0c0c.png
  • /data/data/####/47.8747dce2.png
  • /data/data/####/53xOx6jBwPXx3LWk3JIU58LtiCOPqFKm7sSBo-4_B28=
  • /data/data/####/53xOx6jBwPXx3LWk3JIU58LtiCOPqFKm7sSBo-4_B28=.vng_meta
  • /data/data/####/7.c1140a9a.png
  • /data/data/####/7110a13a450ddd0e_0
  • /data/data/####/7110a13a450ddd0e_1
  • /data/data/####/7b87995873aede0e_0 (deleted)
  • /data/data/####/7bf3a1e7bbd31e612eda3310c2cdb8075c43c6b5
  • /data/data/####/8.7753f926.png
  • /data/data/####/9.b8c9cb29.png
  • /data/data/####/95dfbee756d0d75d41978e8157597534.mp4-270x480-h264-Q2.mp4
  • /data/data/####/AdConfig.xml
  • /data/data/####/AdTimingCrashSP.xml
  • /data/data/####/AppInfo
  • /data/data/####/AppVersion
  • /data/data/####/Cookies-journal
  • /data/data/####/DT_Event.xml
  • /data/data/####/FLURRY_SHARED_PREFERENCES.xml
  • /data/data/####/FirebaseAppHeartBeat.xml
  • /data/data/####/PDuGMxdVRW9IRod9GMzO4yVzYSdV-6UnuPoD1mqqtEg=
  • /data/data/####/PDuGMxdVRW9IRod9GMzO4yVzYSdV-6UnuPoD1mqqtEg=.vng_meta
  • /data/data/####/PersistedInstallation.W0RFRkFVTFRd+MToxMDg3ODU4...Q.json
  • /data/data/####/PersistedInstallation2086134418tmp
  • /data/data/####/PersistedInstallation669103167tmp
  • /data/data/####/RewardedVideo.db
  • /data/data/####/RewardedVideo.db-journal
  • /data/data/####/TKzM8_FcFwvAIVmjS3w8h6JqT1TdlZb1NsT4ugl2MFo=
  • /data/data/####/TKzM8_FcFwvAIVmjS3w8h6JqT1TdlZb1NsT4ugl2MFo=.vng_meta
  • /data/data/####/UnityAdsStorage-private-data.json
  • /data/data/####/UnityAdsStorage-public-data.json
  • /data/data/####/UnityAdsTest.txt (deleted)
  • /data/data/####/UnityAdsWebApp.html
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a88382ac6d6ba3d9_0 (deleted)
  • /data/data/####/aa_config
  • /data/data/####/afd1707ad76c449f9c1ce4de75dac80e.zip
  • /data/data/####/androidx.work.workdb-journal (deleted)
  • /data/data/####/androidxu3dqqnc0z.
  • /data/data/####/androidxu3dqqnc0z.dex
  • /data/data/####/androidxu3dqqnc0z.dex.flock (deleted)
  • /data/data/####/appnext_dbs472
  • /data/data/####/appnext_dbs472-journal
  • /data/data/####/asset_package.zip
  • /data/data/####/b08c6bd61db37df7_0
  • /data/data/####/bg2.png.a557bee1.webp
  • /data/data/####/bg3.png.4e900c08.webp
  • /data/data/####/bg_bonus.a2c28610.png.webp
  • /data/data/####/bg_checkin.1797ce97.png.webp
  • /data/data/####/bg_circle.a9612a43.png.webp
  • /data/data/####/bg_game.df720637.png.webp
  • /data/data/####/btn-refernow-en.fd0fc6ee.png.webp
  • /data/data/####/btn-refernow-hi.f199a4f6.png.webp
  • /data/data/####/btn-refernow-id.9a9fe68e.png.webp
  • /data/data/####/cJZKeOuBrn4kERxqtaUH3SZ2oysoEQEeKwjgmXLRnTc.ttf
  • /data/data/####/cache_policy_journal
  • /data/data/####/cache_touch_timestamp
  • /data/data/####/cc521c568c681388_0
  • /data/data/####/challenge-redeemcard-bg.ce234050.png.webp
  • /data/data/####/checkintip.9aab093f.png.webp
  • /data/data/####/chunk-0920cb3b.3b5f72f2.js
  • /data/data/####/chunk-0920cb3b.f7511fde.css
  • /data/data/####/chunk-097f0ec7.562345ce.js
  • /data/data/####/chunk-097f0ec7.df13a0d7.css
  • /data/data/####/chunk-09e5b021.8b4b78e2.css
  • /data/data/####/chunk-09e5b021.a4f44b61.js
  • /data/data/####/chunk-112935b8.468e75b8.js
  • /data/data/####/chunk-112935b8.6d2e0ca8.css
  • /data/data/####/chunk-1581edc4.823d5f59.css
  • /data/data/####/chunk-1581edc4.84b638d8.js
  • /data/data/####/chunk-16ac501b.5bc60f7d.js
  • /data/data/####/chunk-16ac501b.f9b9f604.css
  • /data/data/####/chunk-198d38fe.12ecb430.js
  • /data/data/####/chunk-198d38fe.68a1c342.css
  • /data/data/####/chunk-1d0417fe.5b6361b4.css
  • /data/data/####/chunk-1d0417fe.a1e991a1.js
  • /data/data/####/chunk-1f789381.07bf6db1.css
  • /data/data/####/chunk-1f789381.f46ecc66.js
  • /data/data/####/chunk-20d6afd0.4685f41b.js
  • /data/data/####/chunk-20d6afd0.d5d7bf07.css
  • /data/data/####/chunk-222a306d.c42e41df.css
  • /data/data/####/chunk-222a306d.fdef3a7b.js
  • /data/data/####/chunk-2a4c20b0.656aebe3.js
  • /data/data/####/chunk-2a4c20b0.b0d394bd.css
  • /data/data/####/chunk-2cd5af2c.812fd44a.css
  • /data/data/####/chunk-2cd5af2c.f7d11e0c.js
  • /data/data/####/chunk-2d0c0846.e511a780.js
  • /data/data/####/chunk-2d0e5e97.0a1c38b1.js
  • /data/data/####/chunk-2d0e5e97.f5c070f7.js
  • /data/data/####/chunk-2d208c0c.e29149ed.js
  • /data/data/####/chunk-2d213786.6b800e50.js
  • /data/data/####/chunk-2e8a2bec.8578221f.css
  • /data/data/####/chunk-2e8a2bec.a6bafacc.js
  • /data/data/####/chunk-3053d40c.91a0beb0.js
  • /data/data/####/chunk-3290b65c.561e87a6.js
  • /data/data/####/chunk-3290b65c.b333fc7f.css
  • /data/data/####/chunk-3460e195.5ae53c4e.css
  • /data/data/####/chunk-3460e195.7be0109e.js
  • /data/data/####/chunk-3574d0b3.3340fe19.css
  • /data/data/####/chunk-3574d0b3.b5b47d46.js
  • /data/data/####/chunk-36bcb528.53d73b35.css
  • /data/data/####/chunk-36bcb528.92fa31b2.js
  • /data/data/####/chunk-382dc3ed.3107b276.css
  • /data/data/####/chunk-382dc3ed.31bc4874.js
  • /data/data/####/chunk-396ade4a.7dcf18c4.js
  • /data/data/####/chunk-396ade4a.9e9c215c.css
  • /data/data/####/chunk-3b18f6aa.8ed2f66e.css
  • /data/data/####/chunk-3b18f6aa.b36e26e4.js
  • /data/data/####/chunk-3c958150.40115834.js
  • /data/data/####/chunk-3c958150.e65e338d.css
  • /data/data/####/chunk-3e70bf22.9f051c1a.js
  • /data/data/####/chunk-3e70bf22.c6eb95ec.css
  • /data/data/####/chunk-3f0d49a1.382e79a5.js
  • /data/data/####/chunk-3f0d49a1.c9c2de30.css
  • /data/data/####/chunk-42f0dbba.1ff2150f.js
  • /data/data/####/chunk-42f0dbba.e11784b4.css
  • /data/data/####/chunk-435747c8.d755da26.css
  • /data/data/####/chunk-435747c8.dadce641.js
  • /data/data/####/chunk-43e48476.6b32b697.css
  • /data/data/####/chunk-43e48476.78f7a040.js
  • /data/data/####/chunk-441c5675.416833a1.css
  • /data/data/####/chunk-441c5675.f4b070e9.js
  • /data/data/####/chunk-487479c7.e6194745.js
  • /data/data/####/chunk-487479c7.f31231df.css
  • /data/data/####/chunk-49ef8378.3b2f134c.js
  • /data/data/####/chunk-49ef8378.a9de160b.css
  • /data/data/####/chunk-4cc25658.884d4045.js
  • /data/data/####/chunk-4cc25658.9c634c20.css
  • /data/data/####/chunk-4d0ad7e0.ffd5080d.js
  • /data/data/####/chunk-4d350800.e5233f98.js
  • /data/data/####/chunk-4ee9c667.946d926d.js
  • /data/data/####/chunk-4ee9c667.a9af9a5a.css
  • /data/data/####/chunk-510524b7.290a33f1.css
  • /data/data/####/chunk-510524b7.99b48105.js
  • /data/data/####/chunk-59ddcdcc.5ba5f962.css
  • /data/data/####/chunk-59ddcdcc.d1bace08.js
  • /data/data/####/chunk-5a4bda97.1784be4b.js
  • /data/data/####/chunk-5a4bda97.1ecbad2c.css
  • /data/data/####/chunk-5ed47ed6.61be5832.css
  • /data/data/####/chunk-5ed47ed6.fddf1406.js
  • /data/data/####/chunk-60a9c2de.5f1e1b48.js
  • /data/data/####/chunk-60a9c2de.7ba062d2.css
  • /data/data/####/chunk-636090c4.64faab60.js
  • /data/data/####/chunk-636090c4.c97e86c3.css
  • /data/data/####/chunk-6acee490.18169113.css
  • /data/data/####/chunk-6acee490.c3681427.js
  • /data/data/####/chunk-6c756b73.c48c7d69.js
  • /data/data/####/chunk-6c756b73.d2e68206.css
  • /data/data/####/chunk-6e2d27ac.7230eb1d.js
  • /data/data/####/chunk-6e2d27ac.bf26bb9a.css
  • /data/data/####/chunk-768f1694.26f9eb8b.css
  • /data/data/####/chunk-768f1694.6237232a.js
  • /data/data/####/chunk-79b8fb84.9523e0b1.css
  • /data/data/####/chunk-79b8fb84.af51573e.js
  • /data/data/####/chunk-7bb6e16c.a8149f6a.css
  • /data/data/####/chunk-7bb6e16c.b9095f57.js
  • /data/data/####/chunk-7c08eb96.1ae80f39.css
  • /data/data/####/chunk-7c08eb96.ffda7583.js
  • /data/data/####/chunk-7dd5a9a0.6971f087.css
  • /data/data/####/chunk-7dd5a9a0.8da8e7ff.js
  • /data/data/####/chunk-984d3510.10121719.js
  • /data/data/####/chunk-984d3510.3fd4076b.css
  • /data/data/####/chunk-a0376a12.3fed8e54.css
  • /data/data/####/chunk-a0376a12.4ea7ea7f.js
  • /data/data/####/chunk-b22852b8.d2dd825d.js
  • /data/data/####/chunk-b22852b8.f04cc715.css
  • /data/data/####/chunk-ba28149c.6061587b.js
  • /data/data/####/chunk-ba28149c.943fab6e.css
  • /data/data/####/chunk-bdfdb94a.a20062a0.css
  • /data/data/####/chunk-bdfdb94a.ef998446.js
  • /data/data/####/chunk-c3c738b8.3d74f96e.css
  • /data/data/####/chunk-c3c738b8.637e388f.js
  • /data/data/####/chunk-cc99e368.76c40e66.css
  • /data/data/####/chunk-cc99e368.9e243819.js
  • /data/data/####/chunk-cedf0df0.00218859.css
  • /data/data/####/chunk-cedf0df0.fadb4f62.js
  • /data/data/####/chunk-common.082ff0b6.css
  • /data/data/####/chunk-common.2ff1be0a.js
  • /data/data/####/chunk-common.4eb7ae15.js
  • /data/data/####/chunk-common.fea91aeb.css
  • /data/data/####/chunk-dcf33c96.1fd00f5e.js
  • /data/data/####/chunk-dcf33c96.8e97d91b.css
  • /data/data/####/chunk-ddbc83cc.9cdb0e08.css
  • /data/data/####/chunk-ddbc83cc.d89d6c97.js
  • /data/data/####/chunk-e400475a.714df218.js
  • /data/data/####/chunk-e400475a.fd66beb8.css
  • /data/data/####/chunk-ea26b7ac.abebd5a7.js
  • /data/data/####/chunk-ea26b7ac.c2ef2c52.css
  • /data/data/####/chunk-eca31988.5f1d9e6e.js
  • /data/data/####/chunk-ee8a5360.c8cd347f.js
  • /data/data/####/chunk-ee8a5360.e3fa0eab.css
  • /data/data/####/chunk-f3de5500.42421b0e.js
  • /data/data/####/chunk-f3de5500.76d7149f.css
  • /data/data/####/chunk-f910a9d8.3afead16.css
  • /data/data/####/chunk-f910a9d8.f688e9b4.js
  • /data/data/####/chunk-vendors.205624ff.css
  • /data/data/####/chunk-vendors.47984c36.js
  • /data/data/####/chunk-vendors.99753d00.css
  • /data/data/####/chunk-vendors.b2457925.js
  • /data/data/####/cocos2d-js-min.5ac6a.js
  • /data/data/####/coin-rp.ccf51795.png
  • /data/data/####/coin.50f2d229.mp3
  • /data/data/####/com.google.android.datatransport.events-journal
  • /data/data/####/com.google.android.gms.appid-no-backup
  • /data/data/####/com.google.android.gms.appid.xml
  • /data/data/####/com.google.android.gms.measurement.prefs.xml
  • /data/data/####/com.vd.vidnow_ct_default.xml
  • /data/data/####/com.vd.vidnow_preferences.xml
  • /data/data/####/com.vungle.sdk.xml
  • /data/data/####/common-empty.06c31d82.png.webp
  • /data/data/####/completed-1645525302971
  • /data/data/####/config_ad
  • /data/data/####/config_banner
  • /data/data/####/config_common_en
  • /data/data/####/config_hotword
  • /data/data/####/config_i18n
  • /data/data/####/config_movie
  • /data/data/####/config_native_ad_config
  • /data/data/####/config_share
  • /data/data/####/config_spider
  • /data/data/####/config_website
  • /data/data/####/config_youtube
  • /data/data/####/confirmDialog.html
  • /data/data/####/confirmDialog.js
  • /data/data/####/confirm_dlg_icon.b3e9c568.png.webp
  • /data/data/####/contribution1.9245b44f.png.webp
  • /data/data/####/crashFile
  • /data/data/####/ct_download.db-journal
  • /data/data/####/currentFile
  • /data/data/####/cv.xml
  • /data/data/####/d7711073613e8abb2f6115d497aa126b.0
  • /data/data/####/d7711073613e8abb2f6115d497aa126b.1
  • /data/data/####/dana-label.e25a133c.png
  • /data/data/####/default.0064ab3d.png.webp
  • /data/data/####/default.710f167c.png
  • /data/data/####/defaultavatar.db6c6fec.jpg
  • /data/data/####/detail_bg.2c59a754.png.webp
  • /data/data/####/dialog.50806a7b.js
  • /data/data/####/dialog.5099c563.js
  • /data/data/####/dialog.html
  • /data/data/####/download.zip
  • /data/data/####/download.zip (deleted)
  • /data/data/####/dt_event.db-journal
  • /data/data/####/e49b73494151f26d_0
  • /data/data/####/favicon.ico
  • /data/data/####/fe4d94827e1ccca64a9c4bc7449a3573.0.tmp
  • /data/data/####/feedback.40c32947.js
  • /data/data/####/feedback.69b5ab05.css
  • /data/data/####/filedownloader.db-journal
  • /data/data/####/game-machine-buddle2.7c2aa443.png
  • /data/data/####/game_block.3c232200.png
  • /data/data/####/gbridge.js
  • /data/data/####/generatefid.lock
  • /data/data/####/godap_download.db-journal
  • /data/data/####/godap_pub_data.xml
  • /data/data/####/google_app_measurement_local.db-journal
  • /data/data/####/hand.1da7be80.png
  • /data/data/####/head_bg.e318e326.png.webp
  • /data/data/####/head_bg.f67827e7.png.webp
  • /data/data/####/http_d1cth1.2usrqwl1z.com_0.localstorage-journal
  • /data/data/####/https_accounts.google.com_0.localstorage-journal
  • /data/data/####/icon-1.14fb6eec.png
  • /data/data/####/icon-2.e30e1cdb.png
  • /data/data/####/icon-3.c04675ce.png
  • /data/data/####/icon-4.0a0152ed.png
  • /data/data/####/icon-5.c0827820.png
  • /data/data/####/icon-bell.595dc249.png.webp
  • /data/data/####/icon-coin-shadow.d76e001b.png.webp
  • /data/data/####/icon-coin.2bc2711f.png.webp
  • /data/data/####/icon-l.1deb4972.png
  • /data/data/####/icon-ln.1753f105.png
  • /data/data/####/icon-r.c9938cac.png
  • /data/data/####/icon-referer-shadow.b97d97fa.png.webp
  • /data/data/####/icon-referer.c34368e5.png.webp
  • /data/data/####/icon-rn.29b33954.png
  • /data/data/####/icon.png
  • /data/data/####/icon1.403caf30.png
  • /data/data/####/icon2.c351ca5d.png
  • /data/data/####/icon3.c8004800.png
  • /data/data/####/icon4.1014a671.png
  • /data/data/####/icon5.5b9c0545.png
  • /data/data/####/icon6.28421958.png
  • /data/data/####/icon7.19672b31.png
  • /data/data/####/icon8.6c5a97ec.png
  • /data/data/####/icon9.3503227d.png
  • /data/data/####/icon_bonus.e92c1298.png
  • /data/data/####/icon_check.e1ffd301.png
  • /data/data/####/icon_coin.84e4aef2.png
  • /data/data/####/icon_game.0e5e2bf5.png
  • /data/data/####/icon_gift.2cb96876.png
  • /data/data/####/icon_q.74725d4d.png
  • /data/data/####/icon_step1.dd330b6a.png.webp
  • /data/data/####/icon_step2.741e0511.png.webp
  • /data/data/####/icon_step3.091917e7.png.webp
  • /data/data/####/icon_step4.836b7749.png.webp
  • /data/data/####/icon_task.9146b71f.png
  • /data/data/####/icon_video.92fa2418.png
  • /data/data/####/iconfont.c02901ca.woff
  • /data/data/####/icontip.66b9c54e.png
  • /data/data/####/index
  • /data/data/####/index.4a97f4b8.js
  • /data/data/####/index.6e5d2ace.js
  • /data/data/####/index.html
  • /data/data/####/index.json
  • /data/data/####/installationNum
  • /data/data/####/journal.tmp
  • /data/data/####/kOOXKYw5P2RnSpDeDM1qV0VYwcsv94LS7FzI0NJLz1I=
  • /data/data/####/kOOXKYw5P2RnSpDeDM1qV0VYwcsv94LS7FzI0NJLz1I=.vng_meta
  • /data/data/####/leaderboard-title-en.3ad0730c.png.webp
  • /data/data/####/leaderboard-title-hi.8b0bee22.png.webp
  • /data/data/####/leaderboard-title-id.dcf22970.png.webp
  • /data/data/####/lib_shared_preferences.xml
  • /data/data/####/lib_shared_preferences.xml.bak (deleted)
  • /data/data/####/loading.json
  • /data/data/####/lottie.min.js
  • /data/data/####/m.bundle.js
  • /data/data/####/mbridge.msdk.db-journal
  • /data/data/####/mbridge.xml
  • /data/data/####/metrics_guid
  • /data/data/####/mix.34f52de0.js
  • /data/data/####/mix.html
  • /data/data/####/mp4.c62d7fhadbvufgfssmdg
  • /data/data/####/mp4.c62d7fpadbvufgfssmo0
  • /data/data/####/mycrash.log
  • /data/data/####/notlogined.10e7ab83.png.webp
  • /data/data/####/omDB.db
  • /data/data/####/omDB.db-journal
  • /data/data/####/pP4SWWcketo-o_TZszG0nwZKZbFjbAyxpveyz9sB4UA=
  • /data/data/####/pP4SWWcketo-o_TZszG0nwZKZbFjbAyxpveyz9sB4UA=.vng_meta
  • /data/data/####/paytm-ico.f76928e1.png
  • /data/data/####/paytm-label.e8136e2d.png
  • /data/data/####/proc_auxv
  • /data/data/####/redeem-result.f4144f00.png.webp
  • /data/data/####/refer-top-bg.5c58d61e.png.webp
  • /data/data/####/refer2.279347f3.png
  • /data/data/####/remote.fe739fbc.js
  • /data/data/####/rise-line.213c6f83.png
  • /data/data/####/rules-steps.27bdbee6.png
  • /data/data/####/share_date.xml
  • /data/data/####/share_date.xml.bak
  • /data/data/####/sp_wertwe.xml
  • /data/data/####/splash.4fdde.png
  • /data/data/####/step1.37b5265f.png.webp
  • /data/data/####/step1_2.f7d32f64.png.webp
  • /data/data/####/step2.03747dc4.png.webp
  • /data/data/####/step3.21ce8d7d.png.webp
  • /data/data/####/step4.12671af1.png.webp
  • /data/data/####/steps.c500a65a.png.webp
  • /data/data/####/steps.eb2d52b2.png.webp
  • /data/data/####/style-mobile.css
  • /data/data/####/switch
  • /data/data/####/tag-new.67d377e9.png
  • /data/data/####/tag-new_id.6b9aa8cf.png
  • /data/data/####/tasktip-img1.c47ea8fc.png.webp
  • /data/data/####/tasktip-img2.b4d79868.png.webp
  • /data/data/####/tasktip-img3_1.b664a55d.png.webp
  • /data/data/####/tasktip-img3_2.0b916f91.png.webp
  • /data/data/####/template
  • /data/data/####/the-real-index
  • /data/data/####/top_bg.7d4b702b.png.webp
  • /data/data/####/unlogin-bg.365c686e.png.webp
  • /data/data/####/update.zip
  • /data/data/####/update1.d38dc913.png.webp
  • /data/data/####/updatepath.856eaebf.png.webp
  • /data/data/####/video_bg.4c2eb988.png.webp
  • /data/data/####/vungle.svg
  • /data/data/####/vungle_db-journal
  • /data/data/####/webviewjavascriptbridge.js
  • /data/media/####/.nomedia
  • /data/media/####/UnityAdsTest.txt (deleted)
  • /data/media/####/VDMaster.mmap3
  • /data/media/####/VDMaster_20220222.xlog
  • /data/media/####/afd1707ad76c449f9c1ce4de75dac80e.zip
  • /data/media/####/confirmDialog.html
  • /data/media/####/confirmDialog.js
  • /data/media/####/m.bundle.js
  • /data/media/####/mycrash.log
  • /data/media/####/z
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • app_process /system/bin com.android.commands.pm.Pm list package -3
  • ls -l /system/bin/su
  • sh
Loads the following dynamic libraries:
  • libc++_shared
  • libmarsxlog
  • libmmkv
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS7PADDING
  • AES-CBC-PKCS7Padding
Accesses the ITelephony private interface.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.
Requests the system alert window permission.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android