La mia libreria
La mia libreria

+ Aggiungi alla libreria

Supporto
Supporto 24/7 | Regole per contattare

Richieste

Profile

Android.Locker.17991

Aggiunto al database dei virus Dr.Web: 2024-04-02

La descrizione è stata aggiunta:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Locker.1463.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • UDP(DNS) 8####.8.4.4:53
  • TCP(TLS/1.0) bend-me####.com:443
  • TCP(TLS/1.0) s####.g.doublec####.net:443
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.0) ads.traffic####.net:443
  • TCP(TLS/1.0) rr6---s####.g####.com:443
  • TCP(TLS/1.0) www.google####.com:443
  • TCP(TLS/1.0) 74.1####.131.139:443
  • TCP(TLS/1.0) ssl.gst####.com:443
  • TCP(TLS/1.0) i.bgm####.com:443
  • TCP(TLS/1.0) n####.abimim####.com:443
  • TCP(TLS/1.0) sto####.google####.com:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) analy####.go####.com:443
  • TCP(TLS/1.0) longst####.com:443
  • TCP(TLS/1.0) ei.ph####.com:443
  • TCP(TLS/1.0) i.bn####.com:443
  • TCP(TLS/1.0) cdn1-sm####.ph####.com:443
  • TCP(TLS/1.0) go####.com:443
  • TCP(TLS/1.0) www.go####.ru:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) rr9---s####.g####.com:443
  • TCP(TLS/1.0) u####.com:443
  • TCP(TLS/1.0) and####.a####.go####.com:443
  • TCP(TLS/1.0) bng####.com:443
  • TCP(TLS/1.0) 1####.177.14.94:443
  • TCP(TLS/1.0) retarge####.com:443
  • TCP(TLS/1.0) bongac####.com:443
  • TCP(TLS/1.0) bongaca####.com:443
  • TCP(TLS/1.0) www.por####.com:443
  • TCP(TLS/1.0) h####.por####.com:443
  • TCP(TLS/1.0) bts.ins####.com:443
  • TCP(TLS/1.2) 1####.177.14.94:443
  • TCP(TLS/1.2) www.google####.com:443
  • TCP(TLS/1.2) analy####.go####.com:443
  • UDP www.google####.com:443
DNS requests:
  • ads.traffic####.net
  • analy####.go####.com
  • and####.a####.go####.com
  • and####.google####.com
  • bend-me####.com
  • bng####.com
  • bongac####.com
  • bongaca####.com
  • bts.ins####.com
  • cdn1-sm####.ph####.com
  • clie####.go####.com
  • ei.ph####.com
  • gmscomp####.google####.com
  • go####.com
  • h####.por####.com
  • i.bgm####.com
  • i.bn####.com
  • longst####.com
  • m####.go####.com
  • retarge####.com
  • rr6---s####.g####.com
  • rr9---s####.g####.com
  • s####.g.doublec####.net
  • ssl.gst####.com
  • sto####.google####.com
  • u####.com
  • www.go####.com
  • www.go####.ru
  • www.google####.com
  • www.google-####.com
  • www.googlet####.com
  • www.por####.com
  • xo####.metlcul####.net
File system changes:
Creates the following files:
  • /data/data/####/000001.dbtmp
  • /data/data/####/00c9a39c41ac1f05_0
  • /data/data/####/011992c1d3586590_0
  • /data/data/####/011992c1d3586590_1
  • /data/data/####/0344846568edff1b_0
  • /data/data/####/035f11932fdaacbd_0
  • /data/data/####/0424364c5a83aed6_0
  • /data/data/####/0424364c5a83aed6_1
  • /data/data/####/0438dc8034130bf8_0
  • /data/data/####/04ca1207673f84d9_0
  • /data/data/####/05e4321c3549cc51_0
  • /data/data/####/08067955b2bf17d0_0
  • /data/data/####/08067955b2bf17d0_1
  • /data/data/####/091770d4d798b659_0
  • /data/data/####/095697837f2e73ac_0
  • /data/data/####/0a364fb28e1eff70_0
  • /data/data/####/0c2416b1449261f6_0
  • /data/data/####/0e4c7d5cde42f3b5_0
  • /data/data/####/0e5525ad6f8a7616_0
  • /data/data/####/0e8f995a9ac4e8ee_0
  • /data/data/####/0f22edf1a51f75af_0
  • /data/data/####/0fcf2478b2fbe300_0
  • /data/data/####/0fcf2478b2fbe300_1
  • /data/data/####/10e63e46a740de2a_0
  • /data/data/####/11e6d0c100ef6553_0
  • /data/data/####/11e6d0c100ef6553_1
  • /data/data/####/13b53e57478e4448_0 (deleted)
  • /data/data/####/14537e9b213b5cc9_0
  • /data/data/####/148f3493f55a4752_0
  • /data/data/####/15e1d9acfe6e886b_0 (deleted)
  • /data/data/####/161d9053e51eac57_0
  • /data/data/####/163567cc20e931d4_0
  • /data/data/####/163567cc20e931d4_1
  • /data/data/####/17035ffa4fe9bbce_0
  • /data/data/####/17035ffa4fe9bbce_1
  • /data/data/####/18cabb7dadfd7b62_0
  • /data/data/####/1a73a35e34dc0e25_0
  • /data/data/####/1abf3fa900d1cb67_0 (deleted)
  • /data/data/####/1bde810935a57a90_0
  • /data/data/####/1e3b77baae7964e9_0
  • /data/data/####/1fda99d0c2eaf8cb_0
  • /data/data/####/1fda99d0c2eaf8cb_1
  • /data/data/####/2027d0f868605718_0
  • /data/data/####/2027d0f868605718_1
  • /data/data/####/20fa18c4d66d488b_0
  • /data/data/####/2149adc73d374813_0
  • /data/data/####/232a1d518cc58c1e_0
  • /data/data/####/24449f8686913b34_0
  • /data/data/####/249947e98aff6cef_0
  • /data/data/####/2505f1bdf1528e50_0
  • /data/data/####/251721d7b63a8a47_0
  • /data/data/####/281248dbb1e939ba_0
  • /data/data/####/2823126cf3744b87_0
  • /data/data/####/2940195bd9870d6e_0
  • /data/data/####/2940195bd9870d6e_1
  • /data/data/####/294298e7d77c7686_0
  • /data/data/####/29ff2adec073b02d_0
  • /data/data/####/2c37f19e48b0254a_0
  • /data/data/####/2cc80dabc69f58b6_0
  • /data/data/####/2da5704dc250e0b5_0
  • /data/data/####/2e1406899f8cf9e8_0
  • /data/data/####/2e56ae2b907de178_0
  • /data/data/####/2e56ae2b907de178_1
  • /data/data/####/2e73a86b7ab26bf2_0
  • /data/data/####/2fc06c91053754df_0
  • /data/data/####/2fd38243a7946951_0
  • /data/data/####/31a0aa6c3a16b075_0
  • /data/data/####/331e373f6aa531f4_0
  • /data/data/####/34c6330fe881daac_0
  • /data/data/####/35b8c1a142033ac2_0
  • /data/data/####/37bed84895ee1102_0
  • /data/data/####/3c5c7155ad1d6273_0
  • /data/data/####/3ea4d78ea985ea67_0
  • /data/data/####/40fddf9e2dee04c3_0
  • /data/data/####/41eb7bc870b1379d_0
  • /data/data/####/438c05330753b200_0
  • /data/data/####/440d53a968c7f1c5_0
  • /data/data/####/440e1e9d02144084_0 (deleted)
  • /data/data/####/44ee0fcc81d7b74c_0
  • /data/data/####/461b605a9f07e4d2_0
  • /data/data/####/46355a6d7891d029_0
  • /data/data/####/484a13f734f95b5e_0
  • /data/data/####/491a42e71fcf3dd5_0
  • /data/data/####/4a62e14f56eee015_0
  • /data/data/####/4a6d0735747b10b1_0
  • /data/data/####/4b45bd71788dc5e0_0
  • /data/data/####/4b9e40bc343ddfbf_0
  • /data/data/####/4cb013792b196a35_0
  • /data/data/####/4cb013792b196a35_1
  • /data/data/####/4dcb2d0a70eca986_0
  • /data/data/####/4ed0070704a56e97_0
  • /data/data/####/4efb51164db6be3f_0
  • /data/data/####/4f035b30d9cb0cd6_0
  • /data/data/####/51719afa404009ce_0
  • /data/data/####/5182bb62f90f43be_0
  • /data/data/####/55928a00bcb3c492_0
  • /data/data/####/55928a00bcb3c492_1
  • /data/data/####/55f49beb43d008e7_0
  • /data/data/####/56199bc988541b73_0
  • /data/data/####/56199bc988541b73_1
  • /data/data/####/5628245793eede06_0
  • /data/data/####/5678bc941dcb43bc_0
  • /data/data/####/568db1c8201e647f_0
  • /data/data/####/56c5d77ae254a86f_0
  • /data/data/####/56cf0ab3a8fe9083_0
  • /data/data/####/56cf0ab3a8fe9083_1
  • /data/data/####/57086f58d8589ebd_0
  • /data/data/####/57b7e0bfa9d50926_0
  • /data/data/####/58246537f2bb0f4e_0
  • /data/data/####/585a99a97f54440c_0
  • /data/data/####/58b30bc08e758eae_0
  • /data/data/####/5ab9bb70a657b951_0
  • /data/data/####/5adc33531b68b7a7_0
  • /data/data/####/5b8e498d769b2c74_0
  • /data/data/####/5ca50924ce3c5c59_0
  • /data/data/####/5ca5d0b6a1b4e269_0
  • /data/data/####/5e6d51c72016a562_0
  • /data/data/####/5f51b0efcaa9a261_0
  • /data/data/####/5fa35c56c4f1ca2d_0
  • /data/data/####/60589aceee8cdf84_0
  • /data/data/####/609fb67e0d20142f_0
  • /data/data/####/60a652f8d78f3054_0
  • /data/data/####/62c7a4b13f61aac3_0
  • /data/data/####/63c540c2f1635765_0
  • /data/data/####/646d22b04ae8557e_0
  • /data/data/####/684880aecad95b2c_0
  • /data/data/####/684880aecad95b2c_1
  • /data/data/####/68524c783c2617f6_0
  • /data/data/####/68524c783c2617f6_1
  • /data/data/####/6a99ca621f469030_0
  • /data/data/####/6b44d6a66a589119_0
  • /data/data/####/6b44d6a66a589119_1
  • /data/data/####/6c126ea0f9cdd135_0 (deleted)
  • /data/data/####/6da0ab2b7b0d1b14_0
  • /data/data/####/6fa1c75808ae4245_0
  • /data/data/####/70844bf27b990cbc_0
  • /data/data/####/71247d72f0b8b0fb_0
  • /data/data/####/72b14750d8674382_0
  • /data/data/####/72f79cb21f6b814e_0
  • /data/data/####/734ee181d7e90f92_0
  • /data/data/####/74317f94aa15fca0_0
  • /data/data/####/74ff48da6135b9c3_0
  • /data/data/####/75b372ba8b3ac08e_0
  • /data/data/####/7623edcd0b0b49f7_0
  • /data/data/####/764e4341e91ae4a5_0
  • /data/data/####/765fcbe3546d14df_0
  • /data/data/####/7688ad4166151327_0
  • /data/data/####/7765887b1a19369b_0
  • /data/data/####/7765887b1a19369b_1
  • /data/data/####/7822d38301e1f47e_0
  • /data/data/####/7848d8f61a956a99_0
  • /data/data/####/788c96c0b7e0eeab_0
  • /data/data/####/78a2b76316bae537_0
  • /data/data/####/79f078e9f94e85ca_0
  • /data/data/####/7b13364cfbb87544_0
  • /data/data/####/7d0e4646ae712910_0
  • /data/data/####/7e1a02ea4cd4fb87_0 (deleted)
  • /data/data/####/7e35f14ff2e45447_0
  • /data/data/####/7e35f14ff2e45447_1
  • /data/data/####/7e48091a74668621_0
  • /data/data/####/80307f82779fae6f_0
  • /data/data/####/805f26ef38ab558b_0 (deleted)
  • /data/data/####/82bc092945fc4186_0
  • /data/data/####/83f2c743e7cdffd4_0
  • /data/data/####/8555d33f05907af2_0
  • /data/data/####/882fe43a4abc4c44_0 (deleted)
  • /data/data/####/8832d1ec0338b110_0 (deleted)
  • /data/data/####/887065dcc9d80f13_0
  • /data/data/####/8888bac454c36fa6_0
  • /data/data/####/8888bac454c36fa6_1
  • /data/data/####/88bcbbf9f00bd2e7_0
  • /data/data/####/8a8c11d8b5a980c9_0
  • /data/data/####/8c7af6cc9d01dad8_0
  • /data/data/####/8ca2787823d0a3c2_0
  • /data/data/####/8ca3609561f02643_0
  • /data/data/####/8d0348dab3d26146_0
  • /data/data/####/8d277d67a5d539e4_0
  • /data/data/####/8d66f7b0ea146f1a_0
  • /data/data/####/8e52202d69aff8de_0
  • /data/data/####/8e81b8ce9036d9cd_0
  • /data/data/####/8f34f906002afe3c_0
  • /data/data/####/9108717da30fae4b_0
  • /data/data/####/93754b2cd16b0cec_0
  • /data/data/####/938d05e234fc9d92_0
  • /data/data/####/93b289e14440ed98_0
  • /data/data/####/9402ef73a016ffbb_0
  • /data/data/####/94085a974ec95abc_0
  • /data/data/####/94188fe3f0078e0f_0
  • /data/data/####/95a4c068f1e6d1d1_0
  • /data/data/####/95a4c068f1e6d1d1_1
  • /data/data/####/95cae56d052c205b_0
  • /data/data/####/96145e55af38c07c_0
  • /data/data/####/9638ec7c083e6c2e_0 (deleted)
  • /data/data/####/96b10ef137b95940_0
  • /data/data/####/9773d0296b8dbbf0_0
  • /data/data/####/97d8928f5a8e8521_0
  • /data/data/####/9951053e7bc9c0c8_0
  • /data/data/####/9951053e7bc9c0c8_1
  • /data/data/####/9a54d55e7bdd3237_0
  • /data/data/####/9a54d55e7bdd3237_1
  • /data/data/####/9b8b8356be03d1e8_0
  • /data/data/####/9c69027e25fc542c_0
  • /data/data/####/9dbcd4ab83cc6f91_0
  • /data/data/####/9ed80db94e551edc_0
  • /data/data/####/9f3a683f78705003_0
  • /data/data/####/9fee0448286141e3_0
  • /data/data/####/CURRENT
  • /data/data/####/Cookies-journal
  • /data/data/####/Databases.db-journal
  • /data/data/####/MANIFEST-000001
  • /data/data/####/PazhFWcymHNc.dex
  • /data/data/####/PazhFWcymHNc.dex.flock (deleted)
  • /data/data/####/QQacdBeEtRpd.dex
  • /data/data/####/QQacdBeEtRpd.dex.flock (deleted)
  • /data/data/####/QuotaManager-journal
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a03d0ee575e34485_0
  • /data/data/####/a13f203477941833_0
  • /data/data/####/a1a0eb390b604316_0
  • /data/data/####/a1a0eb390b604316_1
  • /data/data/####/a1af947b462f9074_0
  • /data/data/####/a361765e5a0dc00c_0
  • /data/data/####/a37b38fae3a3eecf_0
  • /data/data/####/a4d5f224d1edf181_0 (deleted)
  • /data/data/####/a62f3a5e91caf7cc_0
  • /data/data/####/a8442524169968a8_0
  • /data/data/####/a9c3fdb0dbe80f7a_0
  • /data/data/####/aa88e9253c4c929a_0
  • /data/data/####/aabb57a3d575734c_0
  • /data/data/####/ab79da6c3854873c_0
  • /data/data/####/ab79da6c3854873c_1
  • /data/data/####/ab7dc6e48fd31f99_0
  • /data/data/####/ac538bfdb5450af9_0
  • /data/data/####/ac715d024b0b77ed_0
  • /data/data/####/ac952f81ac50ea31_0
  • /data/data/####/ad129c4a18faa8fc_0
  • /data/data/####/ad2ac679ba31d740_0
  • /data/data/####/ad582fdd06fb34fd_0
  • /data/data/####/aeafe34adc808330_0
  • /data/data/####/aeafe34adc808330_1
  • /data/data/####/aec3ad517f801a65_0
  • /data/data/####/af16a83d1c8a42e2_0
  • /data/data/####/af16a83d1c8a42e2_0 (deleted)
  • /data/data/####/afb65cc5fda8f444_0
  • /data/data/####/b0392531bd52d474_0
  • /data/data/####/b213848c284bb250_0
  • /data/data/####/b2b3617238101ca4_0
  • /data/data/####/b2b3617238101ca4_1
  • /data/data/####/b35ec17b7804f676_0
  • /data/data/####/b3bfd5c254d7bebe_0
  • /data/data/####/b5570a187c86ca16_0
  • /data/data/####/b5aa2122b1bda3d7_0
  • /data/data/####/b6005ed34a8f2253_0
  • /data/data/####/b81038b40c149ec9_0
  • /data/data/####/b81038b40c149ec9_1
  • /data/data/####/b82b6c621984153e_0
  • /data/data/####/bWWsD.dex
  • /data/data/####/bWWsD.dex.flock (deleted)
  • /data/data/####/bafb83cf3137be60_0
  • /data/data/####/be97427b03d8575a_0
  • /data/data/####/bf4343bf9c2135ec_0
  • /data/data/####/bfa561fba22614c5_0
  • /data/data/####/c0d61b8193844cb7_0
  • /data/data/####/c1342ddef36eb86f_0
  • /data/data/####/c173777a09029b83_0
  • /data/data/####/c2d5f34c7bdeaf79_0
  • /data/data/####/c2e206ac2748cc7d_0 (deleted)
  • /data/data/####/c34210d5d3517aa6_0
  • /data/data/####/c6a2d25ec1c7891d_0
  • /data/data/####/c7370a4f2cdece78_0
  • /data/data/####/c8ac1f13953d0a25_0 (deleted)
  • /data/data/####/c8efeb5863309bea_0
  • /data/data/####/ca7d520125763a9a_0
  • /data/data/####/cba9c646ad404a91_0
  • /data/data/####/cc00c613e8042efe_0
  • /data/data/####/ccb6ae163afebfc0_0
  • /data/data/####/cdf895802933e204_0
  • /data/data/####/ce926d7d15a75ba1_0
  • /data/data/####/cef8523a2f371821_0
  • /data/data/####/cefef5e7094a86e3_0
  • /data/data/####/com.rhmwvhh_preferences.xml
  • /data/data/####/d00157ff6d6f7e67_0
  • /data/data/####/d25c8e4ac76e72b3_0
  • /data/data/####/d41673381c81e938_0
  • /data/data/####/d70c61e0693f884e_0
  • /data/data/####/d7ce659225279147_0
  • /data/data/####/ddab88b3537af79b_0
  • /data/data/####/de3639d875b13394_0
  • /data/data/####/dea4fb08bb0da6f1_0
  • /data/data/####/dfa13625d9166180_0
  • /data/data/####/dfb04b550f94b669_0
  • /data/data/####/e0ef55be7a3637a4_0
  • /data/data/####/e2456485c63f7ec4_0
  • /data/data/####/e335a106c094e7c1_0
  • /data/data/####/e3f48607bc00f654_0
  • /data/data/####/e4e5ddb495ff0a18_0
  • /data/data/####/e5af8aefe7b8c11e_0
  • /data/data/####/e67b77316227682c_0
  • /data/data/####/e822ee86ebc849e5_0
  • /data/data/####/e833af0d5d78ae38_0
  • /data/data/####/e9439ffb9dfa322e_0
  • /data/data/####/e952c73061d3d892_0
  • /data/data/####/e952c73061d3d892_1
  • /data/data/####/eaa6ea5b5a3877ab_0
  • /data/data/####/eafeab17688597c9_0
  • /data/data/####/eafeab17688597c9_1
  • /data/data/####/ec451c01919ac984_0
  • /data/data/####/ecaadf166bf6d571_0
  • /data/data/####/ecf7560c0b11201a_0
  • /data/data/####/ed9740e982709b5f_0
  • /data/data/####/efd9c412c37cca6b_0
  • /data/data/####/effd37cf07a9b470_0 (deleted)
  • /data/data/####/f02bf79635ab7673_0
  • /data/data/####/f04dfd2bf9575409_0
  • /data/data/####/f1cdccba37924bda_0
  • /data/data/####/f1cdccba37924bda_1
  • /data/data/####/f3573168d42a3151_0
  • /data/data/####/f49148ceb34a7117_0
  • /data/data/####/f537354abb242bc6_0
  • /data/data/####/f5fa9c6556e1c73b_0
  • /data/data/####/f5fa9c6556e1c73b_1
  • /data/data/####/f7c2c77cae515c79_0
  • /data/data/####/f7c2c77cae515c79_1
  • /data/data/####/fa2ffae46e9c01b6_0
  • /data/data/####/fa2ffae46e9c01b6_1
  • /data/data/####/fabfdac260200926_0
  • /data/data/####/fb42df99782e2f0b_0
  • /data/data/####/fc475aae8d1bda4c_0
  • /data/data/####/fc4970b776326822_0
  • /data/data/####/fd5dc2b7eae46f1c_0
  • /data/data/####/fdf107292074fa2b_0
  • /data/data/####/fffcf600ca8d6b65_0
  • /data/data/####/fffedbd5c41208ad_0
  • /data/data/####/index
  • /data/data/####/metrics_guid
  • /data/data/####/temp-index
  • /data/data/####/the-real-index
  • /data/data/####/xGcwSvFOAAuEm.dex
  • /data/data/####/xGcwSvFOAAuEm.dex.flock (deleted)
  • /data/misc/####/primary.prof
Miscellaneous:
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android