Meine Bibliothek
Meine Bibliothek

+ Zur Bibliothek hinzufügen

Support

Ihre Anfragen

Rufen Sie uns an

+7 (495) 789-45-86

Profil

Android.DownLoader.4216

Added to the Dr.Web virus database: 2019-03-08

Virus description added:

Technical information

Malicious functions:
Downloads the following detected threats from the Internet:
  • Android.Spy.127.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) log.mo####.cn:80
  • TCP(HTTP/1.1) p####.mo####.cn:80
  • TCP(HTTP/1.1) ip.ta####.com:80
  • TCP(HTTP/1.1) t####.mo####.cn:9312
  • TCP(HTTP/1.1) img.cdn.mo####.cn:80
  • TCP(HTTP/1.1) dla.cdn.mo####.cn:80
  • TCP(HTTP/1.1) a####.tv.m####.cn:80
  • TCP(HTTP/1.1) a.appj####.com:80
  • TCP(HTTP/1.1) ad.mo####.cn:80
  • TCP(HTTP/1.1) f####.ott.c####.####.net:80
  • TCP(HTTP/1.1) cdn.jindo####.com.####.com:80
  • TCP(HTTP/1.1) 1####.205.163.87:80
  • TCP(HTTP/1.1) 42.96.2####.141:80
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) my.mo####.cn:80
  • TCP(HTTP/1.1) img.tv.m####.cn:80
  • TCP(HTTP/1.1) a####.a####.m.####.com:80
  • UDP(NTP) p####.ntp.org:123
  • TCP(TLS/1.0) w.jindo####.com:443
  • TCP(TLS/1.0) u1.mo####.cn:443
  • TCP(TLS/1.0) msg.umengc####.com:443
  • TCP 1####.205.160.76:443
  • TCP openj####.m.ta####.com:80
DNS requests:
  • a####.m.ta####.com
  • a####.tv.m####.cn
  • a####.u####.com
  • a.appj####.com
  • ad.mo####.cn
  • ag####.m.ta####.com
  • cdn.jindo####.com
  • dla.cdn.mo####.cn
  • f####.ott.c####.####.net
  • img.cdn.mo####.cn
  • img.tv.m####.cn
  • ip.ta####.com
  • log.mo####.cn
  • log.tv.m####.cn
  • msg.umengc####.com
  • my.mo####.cn
  • p####.mo####.cn
  • p####.ntp.org
  • t####.mo####.cn
  • u1.mo####.cn
  • umengj####.m.ta####.com
  • w.jindo####.com
  • www.b####.com
HTTP GET requests:
  • a####.tv.m####.cn/moli20/moli-tv/LightExercise.aspx
  • a####.tv.m####.cn/moli20/moli-tv/ipinfo.aspx?redirect=####
  • a####.tv.m####.cn/moli20/moli-tv/libupgrade?type=####&v=####&u=####&app=...
  • a####.tv.m####.cn/moli20/moli-tv/setting?sv=####&v=####&u=####&app=####&...
  • a####.tv.m####.cn/moli20/moli-tv/tvhome?fv=####&def=####&defw=####&v=###...
  • a####.tv.m####.cn/moli20/moli-tv/videolive-light?time=####&v=####&u=####...
  • ad.mo####.cn/getad.aspx?p=####&v=####&u=####&app=####&os=####&c=####&bt=...
  • cdn.jindo####.com.####.com/pandamanjar/pdmsdk_v3_2018-10-10-01.jar
  • cdn.jindo####.com.####.com/pandamansource/pdm_sdk_v3_v7a_2018-10-11-03.zip
  • dla.cdn.mo####.cn/download/lib/201608120/43e6603d82d2312f94665ff6055f012...
  • dla.cdn.mo####.cn/download/lib/201608260/db9fc391613abde161eed2a83b9bf2f...
  • dla.cdn.mo####.cn/download/lib/201608300/9f6a1500647d731dd8e882b5b3e60a1...
  • dla.cdn.mo####.cn/download/lib/201706230/b16e4e4e9185a7b49f827d952ebec58...
  • dla.cdn.mo####.cn/download/partner/LiteApp_v1.2_Moli.apk
  • dla.cdn.mo####.cn/plugin/201507140/19b0c6a4f3c83827d3f4ab4b8f4ca485/UIPl...
  • dla.cdn.mo####.cn/plugin/201707260/65d443326057e8cf7fa48c9e381559d8/LuaV...
  • dla.cdn.mo####.cn/plugin/201803150/eb1dc711ead1eb764a3e3a73fd4b775a/Defa...
  • dla.cdn.mo####.cn/plugin/201805280/a7014e2311fa9fb08142513f626e35ed/Moli...
  • dla.cdn.mo####.cn/plugin/201806051/ff7e34082a39a77a3f7bdd25b7ac293f/Data...
  • f####.ott.c####.####.net/update/TVSports-release-V3.1.2_6523f17_230025_m...
  • img.cdn.mo####.cn/other/fenlei/fenlei_shenghuo147.jpg
  • img.cdn.mo####.cn/other/fenlei/fenlei_youxi_201607211432.jpg
  • img.cdn.mo####.cn/other/qidongye/huabuqi.jpg?v=####
  • img.cdn.mo####.cn/other/qidongye/qidongye_jiehunweishenme_201608221448.j...
  • img.cdn.mo####.cn/other/tvhome/1529479564151.jpg
  • img.cdn.mo####.cn/other/tvhome/1530261154766.jpg
  • img.cdn.mo####.cn/other/tvhome/1530261172448.jpg
  • img.cdn.mo####.cn/other/tvhome/1530261185743.jpg
  • img.cdn.mo####.cn/other/tvhome/1533110599239.jpg
  • img.cdn.mo####.cn/other/tvhome/1533111436955.jpg
  • img.cdn.mo####.cn/other/tvhome/1543556527277.jpg
  • img.cdn.mo####.cn/other/tvhome/1543556738876.jpg
  • img.cdn.mo####.cn/other/tvhome/1545385777905.jpg
  • img.cdn.mo####.cn/other/tvhome/1545894481683.jpg
  • img.cdn.mo####.cn/other/tvhome/1545894678027.jpg
  • img.cdn.mo####.cn/other/tvhome/1545894735930.jpg
  • img.cdn.mo####.cn/other/tvhome/1545894800530.jpg
  • img.cdn.mo####.cn/other/tvhome/1545894864562.jpg
  • img.cdn.mo####.cn/other/tvhome/1545894881578.jpg
  • img.cdn.mo####.cn/other/tvhome/1545894896450.jpg
  • img.cdn.mo####.cn/other/tvhome/1545894934379.jpg
  • img.cdn.mo####.cn/other/tvhome/1545894985001.jpg
  • img.cdn.mo####.cn/other/tvhome/1545895016978.jpg
  • img.cdn.mo####.cn/other/tvhome/1545895037297.jpg
  • img.cdn.mo####.cn/other/tvhome/1545895052177.jpg
  • img.cdn.mo####.cn/other/tvhome/1545895067393.jpg
  • img.cdn.mo####.cn/other/tvhome/1545898315450.jpg
  • img.cdn.mo####.cn/other/tvhome/1545898447531.jpg
  • img.cdn.mo####.cn/other/tvhome/1545899383288.jpg
  • img.cdn.mo####.cn/other/tvhome/1545900496963.jpg
  • img.cdn.mo####.cn/other/tvhome/1545901217378.jpg
  • img.cdn.mo####.cn/other/tvhome/1546856740420.jpg
  • img.cdn.mo####.cn/other/tvhome/1546944608514.jpg
  • img.cdn.mo####.cn/other/tvhome/1547461040784.jpg
  • img.cdn.mo####.cn/other/tvhome/1547547675197.jpg
  • img.cdn.mo####.cn/other/tvhome/1547722188804.jpg
  • img.cdn.mo####.cn/other/tvhome/1548227505896.jpg
  • img.cdn.mo####.cn/other/tvhome/1548912803477.jpg
  • img.cdn.mo####.cn/other/tvhome/1550540913687.jpg
  • img.cdn.mo####.cn/other/tvhome/1550544785434.jpg
  • img.cdn.mo####.cn/other/tvhome/1550544816107.jpg
  • img.cdn.mo####.cn/other/tvhome/1550545080831.jpg
  • img.cdn.mo####.cn/other/tvhome/1551069056220.jpg
  • img.cdn.mo####.cn/other/tvhome/1551421398062.jpg
  • img.cdn.mo####.cn/other/tvhome/1551424346821.jpg
  • img.cdn.mo####.cn/other/tvhome/1551424452953.jpg
  • img.cdn.mo####.cn/other/youku_0002/cibnpreviewload2018101701.txt.gz
  • img.cdn.mo####.cn/resource/ts190202095311/TvHome-ManualUpdate-light-v116...
  • img.tv.m####.cn/other/qidongye/huabuqi.jpg
  • img.tv.m####.cn/other/qidongye/qidongye_jiehunweishenme_201608221448.jpg
  • ip.ta####.com/service/getIpInfo.php?ip=####
  • my.mo####.cn/api/syncchannel.aspx?userid=####&deviceid=####&action=####&...
  • p####.mo####.cn/ipinfo.aspx
  • p####.mo####.cn/ipinfo.aspx?redirect=####
  • t####.mo####.cn:9312/session?stype=####&evt=####&action=####&ctime=####&...
  • t####.mo####.cn:9312/session?stype=####&evt=####&fv=####&time=####&v=###...
  • t####.mo####.cn:9312/session?stype=####&evt=####&value=####&fromvalue=##...
  • t####.mo####.cn:9312/session?stype=####&evt=####&ver2=####&ver1=####&tim...
HTTP POST requests:
  • a####.a####.m.####.com/amdc/mobileDispatch?appkey=####&platform=####&v=#...
  • a####.u####.com/app_logs
  • a.appj####.com/ad-service/ad/mark
  • a.appj####.com/jiagu/check/upgrade
  • log.mo####.cn/log2.aspx?f=####&v=####&u=####&app=####&os=####&c=####&bt=...
File system changes:
Creates the following files:
  • /data/data/####/.imprint
  • /data/data/####/.jg.ic
  • /data/data/####/063db4e253c24eefb248c2f2978dde6e
  • /data/data/####/100
  • /data/data/####/1529479564151.jpg
  • /data/data/####/1529479564151.jpg.tmp
  • /data/data/####/1530261154766.jpg
  • /data/data/####/1530261154766.jpg.tmp
  • /data/data/####/1530261172448.jpg
  • /data/data/####/1530261172448.jpg.tmp
  • /data/data/####/1530261185743.jpg
  • /data/data/####/1530261185743.jpg.tmp
  • /data/data/####/1533110599239.jpg
  • /data/data/####/1533110599239.jpg.tmp
  • /data/data/####/1533111436955.jpg
  • /data/data/####/1533111436955.jpg.tmp
  • /data/data/####/1543556527277.jpg
  • /data/data/####/1543556527277.jpg.tmp
  • /data/data/####/1543556738876.jpg
  • /data/data/####/1543556738876.jpg.tmp
  • /data/data/####/1545385777905.jpg
  • /data/data/####/1545385777905.jpg.tmp
  • /data/data/####/1545894481683.jpg
  • /data/data/####/1545894481683.jpg.tmp
  • /data/data/####/1545894678027.jpg
  • /data/data/####/1545894678027.jpg.tmp
  • /data/data/####/1545894735930.jpg
  • /data/data/####/1545894735930.jpg.tmp
  • /data/data/####/1545894800530.jpg
  • /data/data/####/1545894800530.jpg.tmp
  • /data/data/####/1545894864562.jpg
  • /data/data/####/1545894864562.jpg.tmp
  • /data/data/####/1545894881578.jpg
  • /data/data/####/1545894881578.jpg.tmp
  • /data/data/####/1545894896450.jpg
  • /data/data/####/1545894896450.jpg.tmp
  • /data/data/####/1545894934379.jpg
  • /data/data/####/1545894934379.jpg.tmp
  • /data/data/####/1545894985001.jpg
  • /data/data/####/1545894985001.jpg.tmp
  • /data/data/####/1545895016978.jpg
  • /data/data/####/1545895016978.jpg.tmp
  • /data/data/####/1545895037297.jpg
  • /data/data/####/1545895037297.jpg.tmp
  • /data/data/####/1545895052177.jpg
  • /data/data/####/1545895052177.jpg.tmp
  • /data/data/####/1545895067393.jpg
  • /data/data/####/1545895067393.jpg.tmp
  • /data/data/####/1545898315450.jpg
  • /data/data/####/1545898315450.jpg.tmp
  • /data/data/####/1545898447531.jpg
  • /data/data/####/1545898447531.jpg.tmp
  • /data/data/####/1545899383288.jpg
  • /data/data/####/1545899383288.jpg.tmp
  • /data/data/####/1545900496963.jpg
  • /data/data/####/1545900496963.jpg.tmp
  • /data/data/####/1545901217378.jpg
  • /data/data/####/1545901217378.jpg.tmp
  • /data/data/####/1546856740420.jpg
  • /data/data/####/1546856740420.jpg.tmp
  • /data/data/####/1546944608514.jpg
  • /data/data/####/1546944608514.jpg.tmp
  • /data/data/####/1547461040784.jpg
  • /data/data/####/1547461040784.jpg.tmp
  • /data/data/####/1547547675197.jpg
  • /data/data/####/1547547675197.jpg.tmp
  • /data/data/####/1547722188804.jpg
  • /data/data/####/1547722188804.jpg.tmp
  • /data/data/####/1548227505896.jpg
  • /data/data/####/1548227505896.jpg.tmp
  • /data/data/####/1548912803477.jpg
  • /data/data/####/1548912803477.jpg.tmp
  • /data/data/####/1550540913687.jpg
  • /data/data/####/1550540913687.jpg.tmp
  • /data/data/####/1550544785434.jpg
  • /data/data/####/1550544785434.jpg.tmp
  • /data/data/####/1550544816107.jpg
  • /data/data/####/1550544816107.jpg.tmp
  • /data/data/####/1550545080831.jpg
  • /data/data/####/1550545080831.jpg.tmp
  • /data/data/####/1551069056220.jpg
  • /data/data/####/1551069056220.jpg.tmp
  • /data/data/####/1551421398062.jpg
  • /data/data/####/1551421398062.jpg.tmp
  • /data/data/####/1551424346821.jpg
  • /data/data/####/1551424346821.jpg.tmp
  • /data/data/####/1551424452953.jpg
  • /data/data/####/1551424452953.jpg.tmp
  • /data/data/####/1552075851892
  • /data/data/####/ACCS_BIND.xml
  • /data/data/####/ACCS_SDK.xml
  • /data/data/####/ACCS_SDK.xml.bak (deleted)
  • /data/data/####/ACCS_SDK_CHANNEL.xml
  • /data/data/####/AGOO_BIND.xml
  • /data/data/####/Agoo_AppStore.xml
  • /data/data/####/Alvin2.xml
  • /data/data/####/ContextData.xml
  • /data/data/####/DaemonServer
  • /data/data/####/DataPlugin.jar
  • /data/data/####/DataPlugin.jar (deleted)
  • /data/data/####/DefaultVideoParser.jar
  • /data/data/####/EpisodeItem.ExportJson
  • /data/data/####/Flip3DImageView.ExportJson
  • /data/data/####/Index_1.ExportJson
  • /data/data/####/Index_2.ExportJson
  • /data/data/####/Index_3.ExportJson
  • /data/data/####/Index_4.ExportJson
  • /data/data/####/Index_5.ExportJson
  • /data/data/####/Index_6.ExportJson
  • /data/data/####/Index_tab.ExportJson
  • /data/data/####/Index_top.ExportJson
  • /data/data/####/InfoBtn.ExportJson
  • /data/data/####/InfoBtnWithSubTitle.ExportJson
  • /data/data/####/InnerLiveLoading.ExportJson
  • /data/data/####/InnerLiveLoading0.plist
  • /data/data/####/InnerLiveLoading0.png
  • /data/data/####/LocalRecordVideoList.ExportJson
  • /data/data/####/LogoAnimation.ExportJson
  • /data/data/####/LogoAnimation0.plist
  • /data/data/####/LogoAnimation0.png
  • /data/data/####/LuaVideoParser.pkg
  • /data/data/####/MessageStore.db-journal
  • /data/data/####/MoliTVCocoUI0.plist
  • /data/data/####/MoliTVCocoUI0.png
  • /data/data/####/MoliTVP2PPlayer.jar
  • /data/data/####/MoliTVUI.zip
  • /data/data/####/MoliTVUI0.plist
  • /data/data/####/MoliTVUI0.png
  • /data/data/####/MoliTVUI1.plist
  • /data/data/####/MoliTVUI1.png
  • /data/data/####/MoliTVUI2.plist
  • /data/data/####/MoliTVUI2.png
  • /data/data/####/MoliTVUI3.plist
  • /data/data/####/MoliTVUI3.png
  • /data/data/####/MsgLogStore.db-journal
  • /data/data/####/RelatedVideoItem.ExportJson
  • /data/data/####/SearchKeyword.ExportJson
  • /data/data/####/SearchRelatedAlbumItem.ExportJson
  • /data/data/####/SearchRelatedVideoItem.ExportJson
  • /data/data/####/SearchScene.ExportJson
  • /data/data/####/StarInfoScene.ExportJson
  • /data/data/####/StarNameBtn.ExportJson
  • /data/data/####/TopicContentList.ExportJson
  • /data/data/####/TopicFlipItem.ExportJson
  • /data/data/####/TopicFlipList.ExportJson
  • /data/data/####/TopicListItem.ExportJson
  • /data/data/####/UIPlugin.jar
  • /data/data/####/UIPluginRes.zip
  • /data/data/####/UIPluginRes.zip (deleted)
  • /data/data/####/UIPluginRes.zip.json
  • /data/data/####/UserVideoList.ExportJson
  • /data/data/####/VideoAttribute.ExportJson
  • /data/data/####/VodPlayListItem.ExportJson
  • /data/data/####/WebVideoFilter.ExportJson
  • /data/data/####/WebVideoFilterList.ExportJson
  • /data/data/####/WebVideoInfo.ExportJson
  • /data/data/####/WebVideoItem.ExportJson
  • /data/data/####/WebVideoList.ExportJson
  • /data/data/####/accs.db-journal
  • /data/data/####/agoo.pid
  • /data/data/####/app.xml
  • /data/data/####/applist.xml
  • /data/data/####/bg.jpg
  • /data/data/####/bg_prompt.png
  • /data/data/####/bg_videolist.png
  • /data/data/####/cd6510c1f97857d3c8bb10c21c20e384.tmp
  • /data/data/####/config
  • /data/data/####/config.json
  • /data/data/####/default_index_res.zip
  • /data/data/####/default_index_res_720.zip
  • /data/data/####/demo_tip.png
  • /data/data/####/fenlei_shenghuo147.jpg
  • /data/data/####/fenlei_shenghuo147.jpg.tmp
  • /data/data/####/fenlei_youxi_201607211432.jpg
  • /data/data/####/fenlei_youxi_201607211432.jpg.tmp
  • /data/data/####/fenleidianying_20163211554.jpg
  • /data/data/####/fenleifenzhong_20163171840.jpg
  • /data/data/####/fenleijianshen_20163171937.jpg
  • /data/data/####/fenleitudianshiju_201603211355.jpg
  • /data/data/####/fenleiyinyue_20163171939.jpg
  • /data/data/####/fenleizongyi_20163211414.jpg
  • /data/data/####/filescrash.log
  • /data/data/####/icon_qr_center.png
  • /data/data/####/images.json
  • /data/data/####/index.json
  • /data/data/####/index_tmp_1552075848328.zip
  • /data/data/####/index_tmp_1552075866218.zip
  • /data/data/####/jg_app_update_settings_random.xml
  • /data/data/####/libcde.so
  • /data/data/####/libcde.zip
  • /data/data/####/libjiagu.so
  • /data/data/####/libppbox_jni-armandroid-r4-gcc44-mt-1.1.0.so
  • /data/data/####/libppbox_jni-armandroid-r4-gcc44-mt-1.1.0.zip
  • /data/data/####/liburlauth.so
  • /data/data/####/liburlauth.zip
  • /data/data/####/libvst.so
  • /data/data/####/list
  • /data/data/####/live.json
  • /data/data/####/live.json.bak
  • /data/data/####/live.zip
  • /data/data/####/loading.png
  • /data/data/####/localrecordvideolist.json
  • /data/data/####/main.db
  • /data/data/####/main.db-journal
  • /data/data/####/message_accs_db
  • /data/data/####/message_accs_db-journal
  • /data/data/####/mobclick_agent_cached_com.molitvhd.android122
  • /data/data/####/mobclick_agent_online_setting_com.molitvhd.android.xml
  • /data/data/####/mreliplayer.db
  • /data/data/####/mreliplayer.db-journal
  • /data/data/####/playersports_layout.xml
  • /data/data/####/playersports_overlay_layout.xml
  • /data/data/####/search.json
  • /data/data/####/shared_molitv.xml
  • /data/data/####/sports_bg.png
  • /data/data/####/sports_cost.png
  • /data/data/####/sports_cup.png
  • /data/data/####/sports_loading.png
  • /data/data/####/sports_overlay_bg.png
  • /data/data/####/sports_overlay_cup.png
  • /data/data/####/sports_overlay_light.png
  • /data/data/####/sports_overlay_shadow.png
  • /data/data/####/sports_overlay_title.png
  • /data/data/####/sports_start_logo.png
  • /data/data/####/sports_start_tip.png
  • /data/data/####/sports_strength.png
  • /data/data/####/starinfo.json
  • /data/data/####/start.jpg
  • /data/data/####/stat_1552075846783
  • /data/data/####/stat_1552075848173
  • /data/data/####/stat_1552075864692
  • /data/data/####/stat_1552075865949
  • /data/data/####/stat_1552075884554
  • /data/data/####/tab_default.png
  • /data/data/####/tab_focused.png
  • /data/data/####/time
  • /data/data/####/topiccontentlist.json
  • /data/data/####/topiclist.json
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/uservideolist.json
  • /data/data/####/videolist.json
  • /data/data/####/vodplaylist.json
  • /data/data/####/vr_EpisodeItem.ExportJson
  • /data/data/####/vr_InfoBtn.ExportJson
  • /data/data/####/vr_InfoBtnWithSubTitle.ExportJson
  • /data/data/####/vr_PlayerUI.ExportJson
  • /data/data/####/vr_RelatedVideoItem.ExportJson
  • /data/data/####/vr_VideoAttribute.ExportJson
  • /data/data/####/vr_VodPlayListItem.ExportJson
  • /data/data/####/vr_WebVideoInfo.ExportJson
  • /data/data/####/vr_WebVideoItem.ExportJson
  • /data/data/####/vr_WebVideoList.ExportJson
  • /data/data/####/vr_exit.png
  • /data/data/####/vr_focus.png
  • /data/data/####/vr_player.json
  • /data/data/####/vr_tvparser.json
  • /data/data/####/vr_vodplaylist.json
  • /data/data/####/vr_webvideoinfo.json
  • /data/data/####/vr_webvideolist.json
  • /data/data/####/webvideo.db
  • /data/data/####/webvideo.db-journal
  • /data/data/####/webvideoinfo.json
  • /data/data/####/webvideolist.json
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/webviewCookiesChromiumPrivate.db
  • /data/data/####/webviewCookiesChromiumPrivate.db-journal
  • /data/media/####/.nomedia
  • /data/media/####/249e656cf2944fd59cf1a830a3897378
  • /data/media/####/27844bdfbf1243f6b4c967081070d59c
  • /data/media/####/8eb7d58f1b1e465aabdc2a8a5b5ee62f
  • /data/media/####/Alvin2.xml
  • /data/media/####/ContextData.xml
  • /data/media/####/a1a51a092fca419cae522d24b4aaf142
  • /data/media/####/accs_election
  • /data/media/####/com.letv.android.client_1552075878998.apk.tmp
  • /data/media/####/com.pptv.tvsports_1552075899242.apk.tmp
  • /data/media/####/f673721713f8409bb51cf9a0f6a552da
  • /data/media/####/inapp_20190308.log
Miscellaneous:
Executes the following shell scripts:
  • <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.m.taobao.com/agoo/report -D {"package":"<Package>","appKey":"umeng:53184d9f56240bec3b028ae3","utdid":"XILMRjtBoQcDAGdzx1FinoVT","sdkVersion":"212"} -I agoodm.m.taobao.com -O 80 -T -Z
  • chmod 500 <Package Folder>/files/DaemonServer
  • chmod 755 <Package Folder>/files/libjiagu.so
  • sh
Loads the following dynamic libraries:
  • anchor3jni_v7neon
  • cocos2dcpp_v7neon
  • ffmpeg_v7neon
  • libjiagu
  • tnet-3.1
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android