Meine Bibliothek
Meine Bibliothek

+ Zur Bibliothek hinzufügen

Support

Ihre Anfragen

Rufen Sie uns an

+7 (495) 789-45-86

Profil

Android.Locker.16828

Added to the Dr.Web virus database: 2023-06-10

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Locker.14669
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(TLS/1.0) www.go####.ru:443
  • TCP(TLS/1.0) st####.traffic####.com:443
  • TCP(TLS/1.0) m####.traffic####.net:443
  • TCP(TLS/1.0) i.dy####.com:443
  • TCP(TLS/1.0) and####.a####.go####.com:443
  • TCP(TLS/1.0) www.por####.com:443
  • TCP(TLS/1.0) pla####.google####.com:443
  • TCP(TLS/1.0) i.bimbo####.com:443
  • TCP(TLS/1.0) gmscomp####.google####.com:443
  • TCP(TLS/1.0) ads.traffic####.net:443
  • TCP(TLS/1.0) sto####.google####.com:443
  • TCP(TLS/1.0) s####.g.doublec####.net:443
  • TCP(TLS/1.0) h####.por####.com:443
  • TCP(TLS/1.0) di.ph####.com:443
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.0) cdn1-sm####.ph####.com:443
  • TCP(TLS/1.0) rr13---####.g####.com:443
  • TCP(TLS/1.0) ht-####.a####.com:443
  • TCP(TLS/1.0) dy####.com:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) hw-####.a####.com:443
  • TCP(TLS/1.0) 1####.251.1.94:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.2) 1####.251.1.94:443
  • TCP(TLS/1.2) gmscomp####.google####.com:443
DNS requests:
  • ads.traffic####.net
  • and####.a####.go####.com
  • and####.google####.com
  • cdn1-sm####.ph####.com
  • di.ph####.com
  • dy####.com
  • ei.ph####.com
  • gmscomp####.google####.com
  • h####.por####.com
  • ht-####.a####.com
  • hw-####.a####.com
  • i.bimbo####.com
  • i.dy####.com
  • m####.go####.com
  • m####.traffic####.net
  • p####.google####.com
  • pla####.google####.com
  • rr13---####.g####.com
  • s####.g.doublec####.net
  • st####.traffic####.com
  • sto####.google####.com
  • sto####.google####.com.####.8
  • v.dy####.com
  • www.go####.com
  • www.go####.ru
  • www.google####.com
  • www.google-####.com
  • www.googlet####.com
  • www.por####.com
File system changes:
Creates the following files:
  • /data/data/####/026c5ac38d0b116b_0
  • /data/data/####/02890334b8122584_0
  • /data/data/####/02e3c39ae5f24289_0
  • /data/data/####/03ebf3f1c1d80cf6_0
  • /data/data/####/03ebf3f1c1d80cf6_1
  • /data/data/####/04923e306fd910c3_0
  • /data/data/####/05f1eefea6853f57_0 (deleted)
  • /data/data/####/06a4176da8bf0e29_0
  • /data/data/####/07a36df2c2255f84_0
  • /data/data/####/07a36df2c2255f84_1
  • /data/data/####/09d049d308a0e18d_0 (deleted)
  • /data/data/####/0a364fb28e1eff70_0
  • /data/data/####/0a364fb28e1eff70_1
  • /data/data/####/0c19aad176b2548e_0
  • /data/data/####/0cbd88b66d85230c_0
  • /data/data/####/0d9975b3de7882e3_0 (deleted)
  • /data/data/####/0e07ec3c043221d0_0
  • /data/data/####/0e6cf2aff85c4423_0
  • /data/data/####/0f99e1c1983f8435_0
  • /data/data/####/0fdc46ae17a68cf7_0
  • /data/data/####/1036711d31eaa79a_0
  • /data/data/####/10f12b947c815431_0
  • /data/data/####/118691574369e928_0
  • /data/data/####/123e9b02f277eb0b_0
  • /data/data/####/1251c9deb44f08a1_0
  • /data/data/####/1251c9deb44f08a1_s
  • /data/data/####/12a6ab2820351259_0
  • /data/data/####/13d2472b524bec67_0
  • /data/data/####/13e77088e80af0e8_0
  • /data/data/####/13e77088e80af0e8_1
  • /data/data/####/146d06d154de130f_0
  • /data/data/####/14dc3643edb5cac8_0
  • /data/data/####/15e9d41dc03a159a_0
  • /data/data/####/161847e389b9d487_0
  • /data/data/####/1625b1931ef5e9cc_0
  • /data/data/####/165905e40d9c993e_0
  • /data/data/####/16ae955e945828d7_0
  • /data/data/####/172ec0e8d581f021_0
  • /data/data/####/17cbda359bffdc36_0
  • /data/data/####/184e71c0a7239ee5_0
  • /data/data/####/1b38d859cc6a9415_0
  • /data/data/####/1c1bbf6f796987d8_0
  • /data/data/####/1d0e9963c2252ac0_0
  • /data/data/####/1f2710207c06c3b0_0
  • /data/data/####/206602e689df3bc8_0
  • /data/data/####/206602e689df3bc8_1
  • /data/data/####/219ffa6b9bc7627b_0
  • /data/data/####/22150f5d8fa95cfb_0
  • /data/data/####/22df6d9420b9045f_0 (deleted)
  • /data/data/####/2316776b4dbdc1d0_0
  • /data/data/####/23ea731994757fc7_0
  • /data/data/####/27392fac809846f5_0
  • /data/data/####/2826dc3c1d940873_0
  • /data/data/####/2940195bd9870d6e_0
  • /data/data/####/2940195bd9870d6e_1
  • /data/data/####/29a7c599521f84a6_0
  • /data/data/####/2cc80dabc69f58b6_0
  • /data/data/####/2d03fa58cb42ded8_0
  • /data/data/####/2f331e719c109258_0
  • /data/data/####/30307017f43d2bf6_0
  • /data/data/####/30307017f43d2bf6_s
  • /data/data/####/30ea6b083013208c_0
  • /data/data/####/312e5a6d01ad236c_0
  • /data/data/####/31d78452ff4ba372_0
  • /data/data/####/32f345e088b7199c_0
  • /data/data/####/33474d826c1f993c_0
  • /data/data/####/335402b2dc819f78_0
  • /data/data/####/351c3786664ea538_0
  • /data/data/####/36cdb1adee788ae0_0
  • /data/data/####/377c58adebfd0868_0
  • /data/data/####/38013ca1a34ee189_0
  • /data/data/####/38c2f74e17e2cd2b_0
  • /data/data/####/3b51363e1df356ab_0
  • /data/data/####/3b6d79609a754296_0
  • /data/data/####/3c7672350eddce59_0
  • /data/data/####/3ce8ab1b4442720c_0
  • /data/data/####/3d3d7b95d5294be4_0
  • /data/data/####/3dffa0d619383ef3_0
  • /data/data/####/3e35e5c55b8d924b_0
  • /data/data/####/3ea4d78ea985ea67_0
  • /data/data/####/403cce35f7ea2965_0
  • /data/data/####/403cce35f7ea2965_1
  • /data/data/####/429ab561e8b444c2_0
  • /data/data/####/4394e604188b7447_0
  • /data/data/####/471ed88e4effab76_0
  • /data/data/####/48a6c16d964f8cc3_0
  • /data/data/####/48c81bd5e649515b_0
  • /data/data/####/491a3c44efc5eb0f_0
  • /data/data/####/4951300844370f4f_0
  • /data/data/####/4a4782b27fcb86c6_0
  • /data/data/####/4aa848688fbc3fef_0
  • /data/data/####/4aa848688fbc3fef_1
  • /data/data/####/4ace52891f5c04e0_0
  • /data/data/####/4ae7a31d3753dc5c_0
  • /data/data/####/4b0fae0b979d09ae_0
  • /data/data/####/4b29cb2b9a3491cf_0
  • /data/data/####/4bcaefcf4dd1a396_0
  • /data/data/####/4c8addb23b524704_0
  • /data/data/####/4cb013792b196a35_0
  • /data/data/####/4cb013792b196a35_1
  • /data/data/####/4d334f3867b406a8_0
  • /data/data/####/4ea14878dcfd3b80_0
  • /data/data/####/4ed92342b9895a0f_0
  • /data/data/####/4ed92342b9895a0f_1
  • /data/data/####/4f04788890c77407_0 (deleted)
  • /data/data/####/4f7905df7b11e22d_0
  • /data/data/####/50389600af89dbf1_0
  • /data/data/####/506ee205b5f80705_0
  • /data/data/####/506ee205b5f80705_1
  • /data/data/####/50a682da6b8803b5_0
  • /data/data/####/50a79368b9e0e47a_0
  • /data/data/####/51108c6e70620b95_0
  • /data/data/####/515fa18f5edf7a71_0
  • /data/data/####/51f3f0813fa64901_0 (deleted)
  • /data/data/####/52983f169916d921_0
  • /data/data/####/53d278a8ad6a58df_0
  • /data/data/####/55566cf0b9ad6cc9_0
  • /data/data/####/579217891453e1a7_0
  • /data/data/####/581ad5bf72b4f675_0 (deleted)
  • /data/data/####/595d7afc5de73671_0
  • /data/data/####/5a7fa10fd447979a_0 (deleted)
  • /data/data/####/5bc29b3e78662aa7_0
  • /data/data/####/5ce0a901e1891288_0
  • /data/data/####/5d3548319559860f_0 (deleted)
  • /data/data/####/5dd50c269c563b1d_0
  • /data/data/####/5ddaf861d7dfe2b9_0
  • /data/data/####/5efcee14b6ba6bad_0
  • /data/data/####/5f0f9c4c9d7c7a29_0
  • /data/data/####/60ce06867852e691_0
  • /data/data/####/60ce06867852e691_1
  • /data/data/####/62c7a4b13f61aac3_0
  • /data/data/####/64508fa1cd46b0ab_0
  • /data/data/####/64508fa1cd46b0ab_1
  • /data/data/####/64dd982d14cd866a_0 (deleted)
  • /data/data/####/6532647e414fe5b7_0
  • /data/data/####/6532647e414fe5b7_1
  • /data/data/####/66e7834481663201_0
  • /data/data/####/66e7834481663201_1
  • /data/data/####/688fa380e3fede15_0
  • /data/data/####/6b98a68681711d75_0
  • /data/data/####/6ba05c123b8c53f8_0
  • /data/data/####/6c74f21d5401a6ec_0
  • /data/data/####/6e2ec2e30f357e51_0
  • /data/data/####/7087f32d69ece070_0
  • /data/data/####/7132114861a4cb90_0 (deleted)
  • /data/data/####/736647aca8f96357_0
  • /data/data/####/7515a93d4ca9069c_0
  • /data/data/####/76389455faf298af_0
  • /data/data/####/76a2dad8fd00ebac_0
  • /data/data/####/76a2dad8fd00ebac_1
  • /data/data/####/79f860392a8973e3_0
  • /data/data/####/7c11e330ac30cc42_0
  • /data/data/####/7c36fcfeed892bef_0
  • /data/data/####/7c36fcfeed892bef_1
  • /data/data/####/7d5969f107923b57_0
  • /data/data/####/7daf53d96b278a9a_0
  • /data/data/####/7daf53d96b278a9a_s
  • /data/data/####/7dc3b494b6708ff7_0
  • /data/data/####/7eab279cfd35219b_0
  • /data/data/####/7ec224298c55c3e2_0
  • /data/data/####/802abd7996b6bd72_0
  • /data/data/####/80f468ecf75b6b3f_0
  • /data/data/####/811cbc401a52f06f_0 (deleted)
  • /data/data/####/81f20af281320436_0
  • /data/data/####/81fd0b9dc3543a31_0
  • /data/data/####/85e4309438e95191_0
  • /data/data/####/88868591a4c077ae_0
  • /data/data/####/8888bac454c36fa6_0
  • /data/data/####/8888bac454c36fa6_1
  • /data/data/####/88c3e1330adafd16_0
  • /data/data/####/8a0d1c6a88ee4d03_0
  • /data/data/####/8a19cd95135de0be_0
  • /data/data/####/8b022a1d76f2f134_0
  • /data/data/####/8b2fb0c1bd50c739_0
  • /data/data/####/8c765efd11bfbc1f_0
  • /data/data/####/8c8921e8e5c81b9a_0
  • /data/data/####/8c9ac5fa6c6dc171_0
  • /data/data/####/8cf1270ae6e124bd_0
  • /data/data/####/92206d673b348ef3_0
  • /data/data/####/927c81f49c686279_0
  • /data/data/####/9402ef73a016ffbb_0
  • /data/data/####/94809330e17ff662_0 (deleted)
  • /data/data/####/95cae56d052c205b_0
  • /data/data/####/96f99741015cae9c_0 (deleted)
  • /data/data/####/9a2c1950109801c6_0
  • /data/data/####/9af018e66c7fdd05_0
  • /data/data/####/9c96d4f507a70c98_0
  • /data/data/####/9d16151bd439c4c5_0
  • /data/data/####/CURRENT
  • /data/data/####/Cookies-journal
  • /data/data/####/Databases.db-journal
  • /data/data/####/HJUsma.dex
  • /data/data/####/HJUsma.dex.flock (deleted)
  • /data/data/####/LxsAdBSu.dex
  • /data/data/####/LxsAdBSu.dex.flock (deleted)
  • /data/data/####/MANIFEST-000001
  • /data/data/####/OZEoiCfqq.dex
  • /data/data/####/OZEoiCfqq.dex.flock (deleted)
  • /data/data/####/QuotaManager-journal
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a04fee263a95b658_0 (deleted)
  • /data/data/####/a16286f21165fcea_0
  • /data/data/####/a1a0eb390b604316_0
  • /data/data/####/a1a0eb390b604316_1
  • /data/data/####/a256de6e96055cd3_0
  • /data/data/####/a2a30b83264624d7_0 (deleted)
  • /data/data/####/a3659ba4bee468c6_0 (deleted)
  • /data/data/####/a3f3f163d03ff1f2_0
  • /data/data/####/a5145a0929c18577_0
  • /data/data/####/a882343e9ffb3607_0
  • /data/data/####/a882343e9ffb3607_1
  • /data/data/####/a9d56e07f351f496_0
  • /data/data/####/a9d611e9376b7a17_0
  • /data/data/####/ae6db6211fcaecf0_0
  • /data/data/####/aec5b5f07b0f77ad_0
  • /data/data/####/aefcfe7acccf98ec_0
  • /data/data/####/afc15be1457500bb_0
  • /data/data/####/b057f7b36ad868cd_0
  • /data/data/####/b07956ae9aabca68_0
  • /data/data/####/b0e409785037322b_0
  • /data/data/####/b14d2115336090ab_0
  • /data/data/####/b183b5b769563004_0
  • /data/data/####/b2575f6ecf380ef9_0
  • /data/data/####/b3da61289b965ba5_0
  • /data/data/####/b4ba1508bc7af0f5_0
  • /data/data/####/b564a480d5c13a32_0
  • /data/data/####/b663056c4de99369_0
  • /data/data/####/b758cd9c94b91409_0
  • /data/data/####/b773c9f0e779ff94_0
  • /data/data/####/b86d5aaa935cbac6_0
  • /data/data/####/b905ed819aa2234d_0
  • /data/data/####/b922e6234071619c_0
  • /data/data/####/ba65ed8060117bed_0
  • /data/data/####/ba9aca5d059f8fe5_0
  • /data/data/####/bb2e4ab2957fb0fd_0
  • /data/data/####/bb4d8ffcb8448efb_0
  • /data/data/####/bc579887b2b99985_0
  • /data/data/####/bd49ffa69488246a_0
  • /data/data/####/bea14472f3545b13_0
  • /data/data/####/bf929e38fa5d3493_0
  • /data/data/####/bfd9bcf022ea402b_0
  • /data/data/####/c012af55ae17357e_0
  • /data/data/####/c0ace8959cdb9149_0
  • /data/data/####/c0c5b341f6c8d1fa_0 (deleted)
  • /data/data/####/c100d021f769e7f7_0
  • /data/data/####/c2409c242fb77112_0
  • /data/data/####/c2ea4a38d429b275_0
  • /data/data/####/c2ea4a38d429b275_1
  • /data/data/####/c3566b9563b7cacf_0
  • /data/data/####/c4ae501395ac0727_0
  • /data/data/####/c5774d0074cc309f_0
  • /data/data/####/c60523688961627a_0
  • /data/data/####/c6aecc087fe87fb1_0
  • /data/data/####/c7055a2e0ac21a52_0
  • /data/data/####/c73ef4e4975d0d67_0
  • /data/data/####/c822cb04824ddc82_0
  • /data/data/####/ca656a6680c4aea1_0
  • /data/data/####/cb21163042d8660e_0
  • /data/data/####/cb21163042d8660e_s
  • /data/data/####/cb89b4931f204e9b_0
  • /data/data/####/cbdbca0830988ca4_0
  • /data/data/####/cbf25d9ed40a61a7_0
  • /data/data/####/cc9bd299d36161c5_0
  • /data/data/####/cc9bd299d36161c5_1
  • /data/data/####/cf5e64602240bd70_0
  • /data/data/####/cf5e64602240bd70_1
  • /data/data/####/com.nyx_preferences.xml
  • /data/data/####/d011ebdb713e5b78_0
  • /data/data/####/d161db50f82eb33f_0
  • /data/data/####/d2dc6e3bc242279a_0
  • /data/data/####/d4243381eadad9bd_0
  • /data/data/####/d47376780ad53931_0
  • /data/data/####/d4e63e6902feb759_0
  • /data/data/####/d53a3157fdc7b7fe_0
  • /data/data/####/d54515e01ebab770_0
  • /data/data/####/d593fe1423edaf19_0
  • /data/data/####/d6006dc20a154f06_0
  • /data/data/####/d74079b08dd16754_0
  • /data/data/####/d9387113e4970fa0_0
  • /data/data/####/da29b751d807944e_0
  • /data/data/####/da4d918d3f07f241_0 (deleted)
  • /data/data/####/daeea62773933f92_0
  • /data/data/####/dcaa211d07ca520d_0
  • /data/data/####/de3263fc09021750_0
  • /data/data/####/de441a27ee5d3631_0
  • /data/data/####/de441a27ee5d3631_1
  • /data/data/####/df1c572479e38130_0
  • /data/data/####/df618664dc95b999_0
  • /data/data/####/e09d44f20deddb8f_0
  • /data/data/####/e3b59f56401a2c34_0
  • /data/data/####/e510693a5e2af912_0
  • /data/data/####/e6033567eeedb896_0
  • /data/data/####/e609e31b4d41e48d_0
  • /data/data/####/e609e31b4d41e48d_1
  • /data/data/####/e6641c86fdc9f4f1_0 (deleted)
  • /data/data/####/e6a686f042c65ee0_0
  • /data/data/####/e6a7127962e31b4a_0
  • /data/data/####/e6fd53d0bd10b2fd_0
  • /data/data/####/e727c4b8f582b78b_0
  • /data/data/####/e9a0dfe405912f2e_0
  • /data/data/####/eab5018faee0f70c_0
  • /data/data/####/eb69f2bd2237d239_0
  • /data/data/####/eb69f2bd2237d239_s
  • /data/data/####/ec24d5446002124a_0
  • /data/data/####/ec2b3b180a837bb6_0
  • /data/data/####/ece9a38a1893ce33_0
  • /data/data/####/ee9b17d19223f60c_0
  • /data/data/####/eebec726c8f50eee_0
  • /data/data/####/eebec726c8f50eee_1
  • /data/data/####/eec21544d6469264_0 (deleted)
  • /data/data/####/effd37cf07a9b470_0 (deleted)
  • /data/data/####/f143a2116cd34b30_0
  • /data/data/####/f1a1da9db0c648eb_0
  • /data/data/####/f1cf4233768decb5_0
  • /data/data/####/f264a1d123ef22eb_0
  • /data/data/####/f401fac982711425_0
  • /data/data/####/f6576ef7214591f7_0
  • /data/data/####/f68635843452f9f4_0
  • /data/data/####/f77b15d559b40e5d_0
  • /data/data/####/f77b15d559b40e5d_1
  • /data/data/####/f7d9566ad738e804_0 (deleted)
  • /data/data/####/f9f6fc8723b81ea3_0
  • /data/data/####/fae3ad2aa1bcce9b_0
  • /data/data/####/fee6ef73fdd6723e_0
  • /data/data/####/ff5520334a111548_0
  • /data/data/####/ff890e53896ed482_0
  • /data/data/####/gbrhHlsI.dex
  • /data/data/####/gbrhHlsI.dex.flock (deleted)
  • /data/data/####/index
  • /data/data/####/metrics_guid
  • /data/data/####/temp-index
  • /data/data/####/the-real-index
  • /data/misc/####/primary.prof
Miscellaneous:
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android