Meine Bibliothek
Meine Bibliothek

+ Zur Bibliothek hinzufügen

Support

Ihre Anfragen

Rufen Sie uns an

+7 (495) 789-45-86

Profil

Android.DownLoader.4809

Added to the Dr.Web virus database: 2020-01-17

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.DownLoader.906.origin
  • Android.DownLoader.909.origin
  • Android.RemoteCode.256.origin
  • Android.Triada.4276
  • Android.Triada.477.origin
  • Android.Triada.482.origin
  • Android.Triada.483.origin
Downloads the following detected threats from the Internet:
  • Android.DownLoader.906.origin
  • Android.DownLoader.909.origin
  • Android.Triada.4276
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) cdn.info####.me:80
  • TCP(HTTP/1.1) ti####.c####.l####.####.com:80
  • TCP(HTTP/1.1) 60.1####.57.72:8080
  • TCP(HTTP/1.1) ff.s####.com:8080
  • TCP(HTTP/1.1) jx####.em####.com:10519
  • TCP(HTTP/1.1) p####.api.adoc####.com:80
  • TCP(HTTP/1.1) pco####.ta####.com:80
  • TCP(HTTP/1.1) r.ist####.com:8071
  • TCP(HTTP/1.1) ni####.bugse####.com:3001
  • TCP(HTTP/1.1) d####.c####.l####.####.com:80
  • TCP(HTTP/1.1) s####.x####.com.cn:80
  • TCP(HTTP/1.1) d0.x####.com.cn:80
  • TCP(HTTP/1.1) d.bjsd####.com:80
  • TCP(HTTP/1.1) s####.al####.com:80
  • TCP(HTTP/1.1) 1####.75.92.94:80
  • TCP(HTTP/1.1) ym####.89####.com:34656
  • TCP(HTTP/1.1) ott.h####.com:8071
  • TCP(HTTP/1.1) a.bjsd####.com:80
  • TCP(HTTP/1.1) cdn.clou####.xyz:80
  • TCP(HTTP/1.1) ad.l####.com:3001
  • TCP(HTTP/1.1) yb.bugse####.com:3002
  • TCP(HTTP/1.1) im####.uc.cn:80
  • TCP(HTTP/1.1) yun.b####.com:80
  • TCP(HTTP/1.1) b####.bugse####.com:3001
  • TCP(HTTP/1.1) 1142864####.cn-hang####.fc.####.com:80
  • TCP(HTTP/1.1) b####.bugse####.com:80
  • TCP(HTTP/1.1) yq####.jn####.ltd:80
  • TCP(HTTP/1.1) i.ist####.com:8071
  • TCP(HTTP/1.1) qiniust####.jom####.com:80
  • TCP(HTTP/1.1) ne####.x####.com.cn:80
  • TCP(HTTP/1.1) api.adoc####.com:80
  • TCP(HTTP/1.1) sdk####.come2c####.com:80
  • TCP(HTTP/1.1) xua####.bugse####.com:80
  • TCP(HTTP/1.1) r1.baiyuns####.com:80
  • TCP(HTTP/1.1) api.yunco####.com:80
  • TCP(HTTP/1.1) ad.l####.com:80
  • TCP(HTTP/1.1) yb.bugse####.com:80
  • TCP(HTTP/1.1) 1713464####.cn-hang####.fc.####.com:80
  • TCP(HTTP/1.1) err.ta####.com:80
  • TCP(HTTP/1.1) gm.mm####.com:80
  • TCP(HTTP/1.1) www.f####.com:80
  • TCP(HTTP/1.1) 1####.201.175.19:80
  • TCP(HTTP/1.1) mh####.b0.a####.com:80
  • TCP(HTTP/1.1) ni####.bugse####.com:80
  • TCP(HTTP/1.1) z.c####.com:80
  • TCP(HTTP/1.1) etc.jiguang####.com.####.com:80
  • TCP(HTTP/1.1) api####.tiantia####.com:80
  • TCP(HTTP/1.1) d####.dd7####.com:80
  • TCP(HTTP/1.1) down####.baiyuns####.com:80
  • TCP(HTTP/1.1) sl.ggve####.com:80
  • TCP(HTTP/1.1) luozias####.b0.a####.com:80
  • TCP(HTTP/1.1) p.ist####.com:8071
  • TCP(HTTP/1.1) v.sho####.com:80
  • TCP(HTTP/1.1) ad.l####.com:3002
  • TCP(HTTP/1.1) g.cn.miao####.com:80
  • TCP(HTTP/1.1) ad.l####.com:3000
  • TCP(HTTP/1.1) co####.ssp.adoc####.com:80
  • TCP(HTTP/1.1) vvv.focusd####.cn:80
  • TCP(HTTP/1.1) i####.xca####.com.####.cn:80
  • TCP(HTTP/1.1) j####.g####.vip:80
  • TCP(HTTP/1.1) tt####.vni####.com:20147
  • TCP(HTTP/1.1) ssph####.cn-hang####.log.####.com:80
  • TCP(HTTP/1.1) b####.bugse####.com:3002
  • TCP(HTTP/1.1) c.c####.com:80
  • TCP(HTTP/1.1) b####.bugse####.com:3000
  • TCP(HTTP/1.1) 1####.75.90.218:80
  • TCP(HTTP/1.1) pc.b####.com:80
  • TCP(HTTP/1.1) dl.bu####.vip:80
  • TCP(HTTP/1.1) cs.and####.com:80
  • TCP(HTTP/1.1) c####.x####.com.cn:80
  • TCP(HTTP/1.1) e4####.0r####.com:10293
  • TCP(HTTP/1.1) ni####.bugse####.com:3002
  • UDP(NTP) 2.and####.p####.####.org:123
  • TCP(SSL/3.0) api.c####.info####.cn:443
  • TCP(TLS/1.0) z.c####.com:443
  • TCP(TLS/1.0) gm.mm####.com:443
  • TCP(TLS/1.0) a####.d####.com:443
  • TCP(TLS/1.0) err.ta####.com:443
  • TCP(TLS/1.0) gd.a.s####.com:443
  • TCP(TLS/1.0) log.mm####.com:443
  • TCP(TLS/1.0) ad####.cp####.cn:443
  • TCP(TLS/1.0) et2.wagbr####.adverti####.####.com:443
  • TCP(TLS/1.0) i####.u####.cn:443
  • TCP(TLS/1.0) etc.jiguang####.com.####.com:443
  • TCP(TLS/1.0) p####.ou####.com:4433
  • TCP(TLS/1.0) i####.d####.com:443
  • TCP(TLS/1.0) c.fw####.com:8888
  • TCP(TLS/1.0) api.g####.vip:443
  • TCP(TLS/1.0) m.u####.cn:443
  • TCP(TLS/1.0) i####.51.la:443
  • TCP(TLS/1.0) s####.d####.com:443
  • TCP(TLS/1.0) p####.api.adoc####.com:443
  • TCP(TLS/1.0) n####.uc.cn:443
  • TCP(TLS/1.0) st3.wagbr####.adverti####.####.com:443
  • TCP(TLS/1.0) c.c####.com:443
  • TCP(TLS/1.0) b####.face####.com:443
  • TCP(TLS/1.0) hm.b####.com:443
  • TCP(TLS/1.0) api.c####.info####.cn:443
  • TCP(TLS/1.0) s####.al####.com:443
  • TCP(TLS/1.0) na61-####.wagbr####.ali####.####.com:443
  • TCP(TLS/1.0) im####.uc.cn:443
  • TCP(TLS/1.0) h####.cn:443
  • TCP(TLS/1.0) api.adoc####.com:443
  • TCP(TLS/1.0) api.info####.me:443
  • TCP gw.adx####.com:8080
  • TCP 39.97.1####.60:9091
  • TCP 1####.249.20.4:87
  • TCP gu####.feiyip####.com:87
DNS requests:
  • 2.and####.p####.####.org
  • 4v####.8m####.com
  • a####.d####.com
  • a####.m.sm.cn
  • a.bjsd####.com
  • ad####.cp####.cn
  • ad.l####.com
  • api####.tiantia####.com
  • api.adoc####.com
  • api.c####.info####.cn
  • api.g####.vip
  • api.info####.me
  • api.m2g.adoc####.com
  • api.yunco####.com
  • ass####.xca####.com
  • b####.bugse####.com
  • b####.bugse####.com
  • b####.face####.com
  • c####.mm####.com
  • c####.s####.com
  • c####.x####.com.cn
  • c.c####.com
  • c.fw####.com
  • cdn.clou####.xyz
  • cdn.info####.me
  • co####.ssp.adoc####.com
  • cs.and####.com
  • d####.dd7####.com
  • d.bjsd####.com
  • d0.x####.com.cn
  • dl.bu####.vip
  • down####.baiyuns####.com
  • e4####.0r####.com
  • err.ta####.com
  • etc.jiguang####.com
  • fc.b####.com
  • ff.s####.com
  • fou####.ta####.com
  • g.al####.com
  • g.cn.miao####.com
  • gu####.feiyip####.com
  • gw.adx####.com
  • h####.c####.com
  • h####.cn
  • hm.b####.com
  • i####.51.la
  • i####.d####.com
  • i####.u####.cn
  • i####.x####.com.cn
  • i####.xca####.com
  • i####.xca####.com
  • i.ist####.com
  • im####.uc.cn
  • j####.g####.vip
  • js.x####.com.cn
  • jx####.em####.com
  • l####.m.sm.cn
  • lg.ca####.com
  • log.mm####.com
  • m.u####.cn
  • ma####.m.ta####.com
  • n####.uc.cn
  • ne####.x####.com.cn
  • ni####.bugse####.com
  • oi####.kenanta####.com
  • ott.h####.com
  • p####.api.adoc####.com
  • p####.b####.com
  • p####.bugse####.com
  • p####.ou####.com
  • p.ist####.com
  • pc.b####.com
  • pco####.c####.com
  • pco####.sm.cn
  • php.clou####.xyz
  • php.sho####.com
  • pv.s####.com
  • px####.jueco####.com
  • r.ist####.com
  • r1.baiyuns####.com
  • s####.al####.com
  • s####.d####.com
  • s####.d####.com
  • s####.m.sm.cn
  • s####.x####.com.cn
  • s13.c####.com
  • s2.z####.cn
  • s23.c####.com
  • s9.c####.com
  • s96.c####.com
  • sdk####.come2c####.com
  • sl.ggve####.com
  • ssph####.cn-hang####.log.####.com
  • t.clou####.xyz
  • tt####.vni####.com
  • v.sho####.com
  • vvv.focusd####.cn
  • w.i####.com
  • www.f####.com
  • xua####.bugse####.com
  • y####.m.sm.cn
  • yb.bugse####.com
  • ym####.89####.com
  • yq####.jn####.ltd
  • yun.b####.com
  • z12.c####.com
  • z2.c####.com
  • z3.c####.com
  • z5.c####.com
  • z6.c####.com
  • z7.c####.com
  • z9.c####.com
HTTP GET requests:
  • 1142864####.cn-hang####.fc.####.com/qs/?pa=####
  • 1142864####.cn-hang####.fc.####.com/xqs/?pa=####
  • 1713464####.cn-hang####.fc.####.com/lg/?lg="0E"55si"55"4F"55hsobuXtcl"55...
  • 1713464####.cn-hang####.fc.####.com/lg/?lg="0E"55si"55"4F"55khfcbu"55"5D...
  • ad.l####.com/ad
  • ad.l####.com:3000/api?rdtime=####&id=####&osv=####&imei=####&adid=####&m...
  • ad.l####.com:3001/api?rdtime=####&id=####&osv=####&imei=####&adid=####&m...
  • ad.l####.com:3002/api?osv=####&imei=####&adid=####&mac=####&density=####...
  • api.adoc####.com/titan/monitor/device_info
  • b####.bugse####.com/ad
  • b####.bugse####.com:3000/api?rdtime=####&id=####&osv=####&imei=####&adid...
  • b####.bugse####.com:3001/api?rdtime=####&id=####&osv=####&imei=####&adid...
  • b####.bugse####.com:3002/api?rdtime=####&id=####&osv=####&imei=####&adid...
  • c####.x####.com.cn/push/adv.php?pid=####&id=####&oid=####&m=####&pv=####...
  • c.c####.com/core.php?web_id=####&t=####
  • c.c####.com/z_stat.php?id=####
  • cdn.clou####.xyz/jar/365admob.jar
  • cdn.clou####.xyz/jar/ad367.jar
  • cdn.clou####.xyz/jar/bixx1126.jar
  • cdn.clou####.xyz/jar/js1202.jar
  • cdn.clou####.xyz/jar/la0116huo.jar
  • cdn.clou####.xyz/jar/so0117.jar
  • cdn.clou####.xyz/jar/wals0923.jar
  • cdn.info####.me/files/3ad950fbff616113801785ca55b88e8c
  • co####.ssp.adoc####.com/api/v2/SDKCommonConfig?channelCode=####&version=...
  • co####.ssp.adoc####.com/api/v2/fwConfig?channelCode=####&version=####
  • co####.ssp.adoc####.com/api/v2/fwWebviewRatioConfig?channelCode=####&ver...
  • co####.ssp.adoc####.com/api/v2/mgmConfig?channelCode=####&version=####
  • co####.ssp.adoc####.com/api/v2/mgmWebviewRatioConfig?channelCode=####&ve...
  • d####.c####.l####.####.com/TTT052_0015.y
  • d####.dd7####.com//upload/sdk2/SDK442dex20200106.jar
  • d####.dd7####.com//upload/sdk2/modex20191212.jar
  • d####.dd7####.com/upload/plog/mfgz.jar
  • d####.dd7####.com/upload/sdk2/inlanddex20200114.jar
  • d####.dd7####.com/upload/sdk2/rq02dex20190829.jar
  • d####.dd7####.com/upload/sdk2/zawdex20200106.jar
  • d####.dd7####.com/upload/sdk3/kzddex20191224.jar
  • d0.x####.com.cn/adpush/push/ad.php?pid=####&pushtype=####&cid=####&style...
  • d0.x####.com.cn/pvlog/ad_count.php?t=####
  • dl.bu####.vip/pptv_1.3.jar
  • dl.bu####.vip/wa_v210.jar
  • down####.baiyuns####.com/cy.js
  • down####.baiyuns####.com/jquery.min.js
  • down####.baiyuns####.com/static/default.css
  • down####.baiyuns####.com/static/index.js
  • down####.baiyuns####.com/static/logo.png
  • err.ta####.com/error1.html?c=404&u=/hz.aplus.taobao.org/app.gif?&cna=uGO...
  • etc.jiguang####.com.####.com/chijian_qd001.html
  • etc.jiguang####.com.####.com/chijian_qd001.js
  • ff.s####.com:8080/ttad/api/getAd/HOoKYok4gMkH1gXDnyW1FQ==
  • ff.s####.com:8080/ttad/api/jv5/HOoKYok4gMkH1gXDnyW1FQ==/c159657daa503498...
  • g.cn.miao####.com/x/k=2148838&p=7V9gw&dx=__IPDX__&rt=2&ns=__IP__&ni=__IE...
  • g.cn.miao####.com/x/k=2153864&p=7WRep&dx=__IPDX__&rt=2&ns=__IP__&ni=__IE...
  • g.cn.miao####.com/x/k=2153864&p=7WReq&dx=__IPDX__&rt=2&ns=__IP__&ni=__IE...
  • g.cn.miao####.com/x/k=2153864&p=7WRer&dx=__IPDX__&rt=2&ns=__IP__&ni=__IE...
  • g.cn.miao####.com/x/k=2153864&p=7WRes&dx=__IPDX__&rt=2&ns=__IP__&ni=__IE...
  • gm.mm####.com/9.gif?abc=####&rnd=####
  • i####.xca####.com.####.cn/b105/s10235/m_20180921003549337191204872501.jpg
  • i####.xca####.com.####.cn/b105/s10235/s_20180330145641401407657471741.jpg
  • i####.xca####.com.####.cn/b105/s10235/s_20180921003547308319519213413.jpg
  • i####.xca####.com.####.cn/b105/s10235/s_20180921003549337191204872501.jpg
  • i####.xca####.com.####.cn/b105/s10235/s_20180921003601037837850283604.jpg
  • i####.xca####.com.####.cn/b85/s9703/m_20181029113027275239670792231.jpg
  • i####.xca####.com.####.cn/b85/s9703/s_20181029113027275239670792231.jpg
  • i####.xca####.com.####.cn/b85/s9703/s_20181029113135004194068137608.jpg
  • i####.xca####.com.####.cn/b85/s9703/s_20190513115017522730262930905.jpg
  • i####.xca####.com.####.cn/b85/s9703/s_20190513115121757275403063997.jpg
  • i####.xca####.com.####.cn/space/f_zyam.jpg
  • i####.xca####.com.####.cn/space/f_zyjr.jpg
  • i####.xca####.com.####.cn/space/f_zytf.jpg
  • i####.xca####.com.####.cn/space/s10612/e09eb5d1429a2b32621485c96e23bb4e....
  • i####.xca####.com.####.cn/space/s10612/f5553bca88426d7a5306e3c527f4a485....
  • i####.xca####.com.####.cn/space/s_ddtj.jpg
  • i####.xca####.com.####.cn/space/s_dlkt.jpg
  • i####.xca####.com.####.cn/space/s_kbtj.jpg
  • i####.xca####.com.####.cn/space/s_zyam.jpg
  • i####.xca####.com.####.cn/space/s_zyjr.jpg
  • i####.xca####.com.####.cn/space/s_zytf.jpg
  • im####.uc.cn/ims?kt=####&at=####&key=aHR####&sign=yx####&tv=####&x####
  • j####.g####.vip/fd.js
  • j####.g####.vip/ggx3.js
  • luozias####.b0.a####.com/ip/lw/qd001.html
  • luozias####.b0.a####.com/ip/lw/qd001.js
  • mh####.b0.a####.com/ad/jb003.js
  • mh####.b0.a####.com/sdk/wk_207.html
  • ne####.x####.com.cn/images/np_ps_bj.jpg
  • ne####.x####.com.cn/images/r_map.gif
  • ne####.x####.com.cn/images/rl_bj.gif
  • ne####.x####.com.cn/js/Jump.js?v=####
  • ne####.x####.com.cn/jsinclude/jquery.js
  • ne####.x####.com.cn/new_ol_config1.html
  • ne####.x####.com.cn/new_ol_news15.html
  • ne####.x####.com.cn/new_ol_photo13.html
  • ne####.x####.com.cn/new_ol_photo4.html
  • ne####.x####.com.cn/new_ol_space8.html
  • ne####.x####.com.cn/xcarjump/new_jump_other.php
  • ni####.bugse####.com/ad
  • ni####.bugse####.com:3001/api?rdtime=####&id=####&osv=####&imei=####&adi...
  • ni####.bugse####.com:3002/api?rdtime=####&id=####&osv=####&imei=####&adi...
  • p####.api.adoc####.com/ip
  • pc.b####.com/v
  • pco####.ta####.com/app.gif?&cna=####
  • qiniust####.jom####.com/common/1.7.2.min.js
  • qiniust####.jom####.com/source/search/search.r.js?v=####
  • qiniust####.jom####.com/source/search/search_emptyfns.r.js
  • qiniust####.jom####.com/source/search/search_exec.r.js?v=####
  • qiniust####.jom####.com/source/search/search_tpl_c1.r.js?v=####
  • qiniust####.jom####.com/source/search/search_tpl_c2.r.js?v=####
  • qiniust####.jom####.com/tools/jq/1.9-nol.js
  • qiniust####.jom####.com/tools/requirejs/2.3.js?v=####
  • s####.al####.com/L1/272/6837/static/wap/img/uc-32.png
  • s####.al####.com/L1/272/6837/static/wap/img/uc.png
  • s####.x####.com.cn/flow/flow.php?m=####
  • s####.x####.com.cn/flow/flow.php?t=####
  • sl.ggve####.com/eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ4NjQiOmZhbHNlLCJ...
  • ssph####.cn-hang####.log.####.com/logstores/system/track_ua.gif?APIVersi...
  • ti####.c####.l####.####.com/2011newcar/css/space2015fyl.css?version=####
  • ti####.c####.l####.####.com/2011newcar/images/askbg8.png
  • ti####.c####.l####.####.com/2011newcar/images/fdbg11.jpg
  • ti####.c####.l####.####.com/2011newcar/images/first.jpg
  • ti####.c####.l####.####.com/2011newcar/images/hdbg_03.jpg
  • ti####.c####.l####.####.com/2011newcar/images/seat5kg.jpg
  • ti####.c####.l####.####.com/2011newcar/images/seat5pai1.jpg
  • ti####.c####.l####.####.com/2011newcar/images/seat5pai2.jpg
  • ti####.c####.l####.####.com/2011newcar/images/seat5pai21.jpg
  • ti####.c####.l####.####.com/2011newcar/images/seat7icon-n24.png
  • ti####.c####.l####.####.com/2011newcar/images/second.jpg
  • ti####.c####.l####.####.com/2011newcar/images/szface.jpg
  • ti####.c####.l####.####.com/2011newcar/images/topbg.jpg
  • ti####.c####.l####.####.com/2011newcar/images/wb_btn1.jpg
  • ti####.c####.l####.####.com/2015/nav/css/channel_nav.css?v=####
  • ti####.c####.l####.####.com/2015/nav/images/Header_bg.gif?v=####
  • ti####.c####.l####.####.com/2015/nav/images/xcar_logov@2x.png?v=####
  • ti####.c####.l####.####.com/2016/DemioModel/css/common.css?version=####
  • ti####.c####.l####.####.com/2016/DemioModel/css/demion_v1.css?v=####
  • ti####.c####.l####.####.com/2016/DemioModel/images/200.jpg
  • ti####.c####.l####.####.com/2016/DemioModel/images/DemioModel.png
  • ti####.c####.l####.####.com/2016/DemioModel/images/DemioModel.png?v####
  • ti####.c####.l####.####.com/PicLib/logo/pl1_40.jpg
  • ti####.c####.l####.####.com/PicLib/logo/pl2_40.jpg
  • ti####.c####.l####.####.com/min/?f=####&version=####
  • ti####.c####.l####.####.com/resource/common/statistic/iwt-min.js
  • ti####.c####.l####.####.com/ss/newsearch/css/search.css
  • vvv.focusd####.cn/ad/v1/log.action?action=####&package=####&channel=####...
  • www.f####.com/
  • xua####.bugse####.com/ad
  • xua####.bugse####.com/api?rdtime=####&id=####&osv=####&imei=####&adid=##...
  • yb.bugse####.com/ad
  • yb.bugse####.com/api?rdtime=####&id=####&osv=####&imei=####&adid=####&ma...
  • yb.bugse####.com:3002/api?rdtime=####&id=####&osv=####&imei=####&adid=##...
  • yq####.jn####.ltd/c/wlimqseg.zip
  • yq####.jn####.ltd/one/44236jghgvjhbwyf.zip
  • yq####.jn####.ltd/zz/442ghffgtrwyf.zip
  • yun.b####.com/pw/70777777.jpg
  • yun.b####.com/pw/765f73646b.jpg
  • yun.b####.com/tz/6173.jpg
  • yun.b####.com/xpw/736d7373.jx
  • yun.b####.com/xpw/7563.jx
  • yun.b####.com/xtz/741535829.ico
  • z.c####.com/stat.htm?id=####&cnzz_eid=####
  • z.c####.com/stat.htm?id=####&r=####&lg=####&ntime=####&cnzz_eid=####&sho...
HTTP POST requests:
  • a.bjsd####.com/index.php?r=####
  • api####.tiantia####.com/ads
  • api.yunco####.com/service/rest
  • cs.and####.com/ydt826/sv2
  • d.bjsd####.com/index.php?r=####
  • e4####.0r####.com:10293/widlth/
  • i.ist####.com:8071/6.0.2/1510864978/1
  • jx####.em####.com:10519/ntmili/
  • jx####.em####.com:10519/qazggd/
  • jx####.em####.com:10519/xoslvm/
  • ott.h####.com:8071/api/10
  • p.ist####.com:8071/1
  • r.ist####.com:8071/6.0.2/163832107/2
  • r1.baiyuns####.com/service/rest
  • sdk####.come2c####.com/v1/project/sdk
  • tt####.vni####.com:20147/dijc1v/
  • v.sho####.com/index.php?r=####
  • ym####.89####.com:34656/aowbg/
  • ym####.89####.com:34656/ixowf/
  • ym####.89####.com:34656/qdkle/
  • ym####.89####.com:34656/rqiea/
File system changes:
Creates the following files:
  • /data/data/####/.b0637dbb-7ed6-496a-b0bb-e783807d627b
  • /data/data/####/114219
  • /data/data/####/1635348846.dex (deleted)
  • /data/data/####/1635348846.jar
  • /data/data/####/1635348846.jar (deleted)
  • /data/data/####/44367F39739CCD6BBF960E91E7DB78B2.xml
  • /data/data/####/4B8DB6B83129A65A2EF4DCFC1393C3B0.xml
  • /data/data/####/8EAD111D030291821E19A80E344C340A.xml
  • /data/data/####/9618302918.xml
  • /data/data/####/ApplicationCache.db-journal
  • /data/data/####/IM.xml
  • /data/data/####/SMF.xml
  • /data/data/####/WSsTRq.data-journal
  • /data/data/####/_p.xml
  • /data/data/####/_sh.xml
  • /data/data/####/apkseparate.DoubleBackUpDB.db
  • /data/data/####/apkseparate.DoubleBackUpDB.db-journal
  • /data/data/####/app.manager-journal
  • /data/data/####/atai.jar
  • /data/data/####/c.dat
  • /data/data/####/c.dat.tm
  • /data/data/####/cHB0dl8xLjMuamFy.tmp
  • /data/data/####/cfg.config.service.xml
  • /data/data/####/cfg.database.ad-journal
  • /data/data/####/comngeusjdigqhuid.xml
  • /data/data/####/config.service.xml
  • /data/data/####/d2FfdjIxMC5qYXI=.tmp
  • /data/data/####/data.m
  • /data/data/####/data.zip
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/download.info
  • /data/data/####/download.tmp
  • /data/data/####/dwBYC.data-journal
  • /data/data/####/dwwesGGb.data-journal
  • /data/data/####/dwwsWs.data-journal
  • /data/data/####/edghy6trds.xml
  • /data/data/####/eoaxwqxm.jar
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/f_000003
  • /data/data/####/f_000004
  • /data/data/####/f_000005
  • /data/data/####/f_000006
  • /data/data/####/f_000007
  • /data/data/####/f_000008
  • /data/data/####/f_000009
  • /data/data/####/f_00000a
  • /data/data/####/f_00000b
  • /data/data/####/f_00000c
  • /data/data/####/f_00000d
  • /data/data/####/f_00000e
  • /data/data/####/f_00000f
  • /data/data/####/f_000010
  • /data/data/####/f_000011
  • /data/data/####/f_000012
  • /data/data/####/f_000013
  • /data/data/####/f_000014
  • /data/data/####/f_000015
  • /data/data/####/f_000016
  • /data/data/####/f_000017
  • /data/data/####/f_000018
  • /data/data/####/f_000019
  • /data/data/####/f_00001a
  • /data/data/####/f_00001b
  • /data/data/####/f_00001c
  • /data/data/####/f_00001d
  • /data/data/####/f_00001e
  • /data/data/####/f_00001f
  • /data/data/####/f_000020
  • /data/data/####/f_000021
  • /data/data/####/f_000022
  • /data/data/####/f_000023
  • /data/data/####/f_000024
  • /data/data/####/f_000025
  • /data/data/####/f_000026
  • /data/data/####/f_000027
  • /data/data/####/f_000028
  • /data/data/####/f_000029
  • /data/data/####/f_00002a
  • /data/data/####/f_00002b
  • /data/data/####/f_00002c
  • /data/data/####/f_00002d
  • /data/data/####/f_00002e
  • /data/data/####/f_00002f
  • /data/data/####/f_000030
  • /data/data/####/f_000031
  • /data/data/####/f_000032
  • /data/data/####/f_000033
  • /data/data/####/f_000034
  • /data/data/####/f_000035
  • /data/data/####/f_000036
  • /data/data/####/f_000037
  • /data/data/####/f_000038
  • /data/data/####/f_000039
  • /data/data/####/f_00003a
  • /data/data/####/f_00003b
  • /data/data/####/f_00003c
  • /data/data/####/f_00003d
  • /data/data/####/f_00003e
  • /data/data/####/f_00003f
  • /data/data/####/f_000040
  • /data/data/####/f_000041
  • /data/data/####/f_000042
  • /data/data/####/f_000043
  • /data/data/####/f_000044
  • /data/data/####/f_000045
  • /data/data/####/f_000046
  • /data/data/####/f_000047
  • /data/data/####/fty_fer_zcd_testajkl.txt
  • /data/data/####/fwswsedfrf.data-journal
  • /data/data/####/fwwsf.xml
  • /data/data/####/gameid
  • /data/data/####/gameid.zip
  • /data/data/####/gwwqedws.data-journal
  • /data/data/####/http_newcar.xcar.com.cn_0.localstorage-journal
  • /data/data/####/http_www.fnnbt.com_0.localstorage-journal
  • /data/data/####/https_m.uczzd.cn_0.localstorage-journal
  • /data/data/####/https_yz.m.sm.cn_0.localstorage-journal
  • /data/data/####/https_yz.m.sm.cn_0.localstorage-journal (deleted)
  • /data/data/####/im.database.ad-journal
  • /data/data/####/index
  • /data/data/####/libch
  • /data/data/####/libcwzdnq.so
  • /data/data/####/libcwzdnq.so-32
  • /data/data/####/libcwzdnq.so-64
  • /data/data/####/lpl.xml
  • /data/data/####/maclong.xml
  • /data/data/####/nhgbbpxz.xml
  • /data/data/####/nhgbbpxz.xml.bak
  • /data/data/####/oMHea.xml
  • /data/data/####/oMHea.xml.bak
  • /data/data/####/ombjhvs.data-journal
  • /data/data/####/rq_file.xml
  • /data/data/####/sGFdwf.data-journal
  • /data/data/####/spu_ti.xml
  • /data/data/####/sunn.jar
  • /data/data/####/sunn.tmp (deleted)
  • /data/data/####/sunn.x
  • /data/data/####/suytgf.data-journal
  • /data/data/####/ttff.xml
  • /data/data/####/ugr5trds.data-journal
  • /data/data/####/vpef.xml
  • /data/data/####/wESUTYe.xml
  • /data/data/####/wWAys.xml
  • /data/data/####/wWAys.xml.bak
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/wiuhgf.xml
  • /data/data/####/wry6reww322.xml
  • /data/data/####/wwwsedwwws.xml
  • /data/data/####/wwwsedwwws.xml.bak
  • /data/data/####/wwwwx.xml
  • /data/data/####/yd_config_c.xml
  • /data/data/####/ywsMJwa.xml
  • /data/data/####/ywsMJwa.xml.bak
  • /data/data/####/zrhzaf.png
  • /data/media/####/.6173.apk
  • /data/media/####/.70777777.apk
  • /data/media/####/.765f73646b.apk
  • /data/media/####/.eiz
  • /data/media/####/.nid
  • /data/media/####/.nomedia
  • /data/media/####/.qosu
  • /data/media/####/.usdis
  • /data/media/####/03A1149AD0C3BB08FF3316A3475BA1B9
  • /data/media/####/080994405B5F97DB28AA509CC05FA2F5.jar
  • /data/media/####/080994405B5F97DB28AA509CC05FA2F5.temp
  • /data/media/####/2b0ef4b7755665fcbd73e5a65e6837ad.xml
  • /data/media/####/6CDE2987B4E4E3A475F2D96F9B35372A.temp
  • /data/media/####/6CDE2987B4E4E3A475F2D96F9B35372A.zip
  • /data/media/####/9088D7915D2BC2DEE6562BDECE89F3E2
  • /data/media/####/961EA7E2036C89A047B08219D658170F
  • /data/media/####/AC4DA29A2257772085362C088DC64606.jar
  • /data/media/####/AC4DA29A2257772085362C088DC64606.temp
  • /data/media/####/SDK442dex20200106.jar
  • /data/media/####/_pn
  • /data/media/####/_shn
  • /data/media/####/date40003000700
  • /data/media/####/fty_fer_zcd_testajkl.txt
  • /data/media/####/inlanddex20200114.jar
  • /data/media/####/js1202.jar
  • /data/media/####/kzddex20191224.jar
  • /data/media/####/la0116huo.jar
  • /data/media/####/mfgz.jar
  • /data/media/####/modex20191212.jar
  • /data/media/####/ottpid.txt
  • /data/media/####/pidfile.txt
  • /data/media/####/rq02dex20190829.jar
  • /data/media/####/so0117.jar
  • /data/media/####/zawdex20200106.jar
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/cat /proc/cpuinfo
  • cat /proc/version
  • cat /sys/class/net/wlan0/address
  • getprop
Loads the following dynamic libraries:
  • httphttps
  • libch
  • libcwzdnq
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • DES-CBC-PKCS5Padding
  • Des-ECB-NoPadding
  • RSA-None-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-CFB-NoPadding
  • AES-ECB-PKCS5Padding
  • DES
  • DES-CBC-PKCS5Padding
  • Des-ECB-NoPadding
  • RSA-None-PKCS1Padding
Accesses the ITelephony private interface.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Gets information about running apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android