Meine Bibliothek
Meine Bibliothek

+ Zur Bibliothek hinzufügen

Support

Ihre Anfragen

Rufen Sie uns an

+7 (495) 789-45-86

Profil

Android.Locker.17940

Added to the Dr.Web virus database: 2024-03-17

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Locker.1474.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • UDP(DNS) 8####.8.4.4:53
  • TCP(TLS/1.0) bng####.com:443
  • TCP(TLS/1.0) www.por####.com:443
  • TCP(TLS/1.0) bend-me####.com:443
  • TCP(TLS/1.0) h####.por####.com:443
  • TCP(TLS/1.0) retarge####.com:443
  • TCP(TLS/1.0) pla####.google####.com:443
  • TCP(TLS/1.0) longst####.com:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) bongaca####.com:443
  • TCP(TLS/1.0) o####.vk.com:443
  • TCP(TLS/1.0) s####.g.doublec####.net:443
  • TCP(TLS/1.0) i.bgm####.com:443
  • TCP(TLS/1.0) analy####.go####.com:443
  • TCP(TLS/1.0) bts.ins####.com:443
  • TCP(TLS/1.0) ads.traffic####.net:443
  • TCP(TLS/1.0) sto####.google####.com:443
  • TCP(TLS/1.0) rr9---s####.g####.com:443
  • TCP(TLS/1.0) rr2---s####.g####.com:443
  • TCP(TLS/1.0) ei.ph####.com:443
  • TCP(TLS/1.0) u####.com:443
  • TCP(TLS/1.0) st####.vk.com:443
  • TCP(TLS/1.0) i.bn####.com:443
  • TCP(TLS/1.0) n####.abimim####.com:443
  • TCP(TLS/1.0) cdn1-sm####.ph####.com:443
  • TCP(TLS/1.0) www.go####.ru:443
  • TCP(TLS/1.0) p####.google####.com:443
  • TCP(TLS/1.0) a####.vk.com:443
  • TCP(TLS/1.0) rr6---s####.g####.com:443
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.2) 74.1####.131.102:443
  • TCP(TLS/1.2) gmscomp####.google####.com:443
  • UDP p####.google####.com:443
DNS requests:
  • a####.vk.com
  • ads.traffic####.net
  • analy####.go####.com
  • bend-me####.com
  • bng####.com
  • bongaca####.com
  • bongaca####.com
  • bts.ins####.com
  • cdn1-sm####.ph####.com
  • connect####.gst####.com
  • ei.ph####.com
  • gmscomp####.google####.com
  • h####.por####.com
  • i####.vk.com
  • i.bgm####.com
  • i.bn####.com
  • l####.vk.com
  • longst####.com
  • m####.traffic####.net
  • o####.vk.com
  • p####.google####.com
  • pla####.google####.com
  • retarge####.com
  • rr2---s####.g####.com
  • rr6---s####.g####.com
  • rr9---s####.g####.com
  • s####.g.doublec####.net
  • st####.vk.com
  • sto####.google####.com
  • u####.com
  • www.go####.com
  • www.go####.ru
  • www.google####.com
  • www.google-####.com
  • www.googlet####.com
  • www.por####.com
  • xo####.metlcul####.net
File system changes:
Creates the following files:
  • /data/data/####/000001.dbtmp
  • /data/data/####/002bb419cd345ec6_0 (deleted)
  • /data/data/####/0059d4c61ef7bea0_0
  • /data/data/####/026cd701d25b9c56_0
  • /data/data/####/028f9deedc39a0f5_0
  • /data/data/####/0344846568edff1b_0
  • /data/data/####/035f11932fdaacbd_0
  • /data/data/####/0381e936a2ac8f76_0
  • /data/data/####/04ca1207673f84d9_0
  • /data/data/####/05e4321c3549cc51_0
  • /data/data/####/078d0deab856d770_0
  • /data/data/####/091770d4d798b659_0
  • /data/data/####/0a364fb28e1eff70_0
  • /data/data/####/0bb9c6076f070ff9_0
  • /data/data/####/0bdb7fd61cf6a42a_0
  • /data/data/####/0ce153fe0c38db33_0
  • /data/data/####/0dfa4a20444e25ea_0
  • /data/data/####/0e5352403d946edd_0
  • /data/data/####/0e5352403d946edd_1
  • /data/data/####/0e5525ad6f8a7616_0
  • /data/data/####/0f22edf1a51f75af_0
  • /data/data/####/11954de1c68a3aac_0
  • /data/data/####/11954de1c68a3aac_1
  • /data/data/####/11d75f4536d7ed49_0
  • /data/data/####/11e6d0c100ef6553_0
  • /data/data/####/11e6d0c100ef6553_1
  • /data/data/####/13b53e57478e4448_0 (deleted)
  • /data/data/####/140091e78ced528d_0
  • /data/data/####/17035ffa4fe9bbce_0
  • /data/data/####/17035ffa4fe9bbce_1
  • /data/data/####/175b1b452710f14f_0
  • /data/data/####/183bc42e227e1b6c_0
  • /data/data/####/183bc42e227e1b6c_1
  • /data/data/####/1a2dd6623901f0e2_0
  • /data/data/####/1a73a35e34dc0e25_0
  • /data/data/####/1b23fcbd91ab083d_0
  • /data/data/####/1c51e192d205be56_0
  • /data/data/####/1fda99d0c2eaf8cb_0
  • /data/data/####/1fda99d0c2eaf8cb_1
  • /data/data/####/21893a60d11db178_0 (deleted)
  • /data/data/####/24bca6cc08323bda_0
  • /data/data/####/25309ccf291f06fb_0
  • /data/data/####/253adf8c1e670d24_0
  • /data/data/####/25553bdabf0c6377_0
  • /data/data/####/2684c927891aeb44_0
  • /data/data/####/2940195bd9870d6e_0
  • /data/data/####/2940195bd9870d6e_1
  • /data/data/####/29fd4c2fe85218e1_0
  • /data/data/####/2a1ac2855cb07f3c_0
  • /data/data/####/2a89e85e375d3490_0
  • /data/data/####/2c73936b3b43214e_0
  • /data/data/####/2cc80dabc69f58b6_0
  • /data/data/####/2d1ab6a36f4a3379_0
  • /data/data/####/2d692dc02629ecc1_0
  • /data/data/####/2da5704dc250e0b5_0
  • /data/data/####/2e56ae2b907de178_0
  • /data/data/####/2e56ae2b907de178_1
  • /data/data/####/2f05532f3feb5c83_0
  • /data/data/####/3193bb40239444b5_0
  • /data/data/####/3307a47066940109_0
  • /data/data/####/331e373f6aa531f4_0
  • /data/data/####/33310e186eee3708_0
  • /data/data/####/33792c0994c66578_0
  • /data/data/####/34c6330fe881daac_0
  • /data/data/####/3691ac931d551cf8_0
  • /data/data/####/37677645b9a4fdc6_0
  • /data/data/####/3b585071f7fa0da1_0
  • /data/data/####/3b596f27fa059cc0_0
  • /data/data/####/3c5c7155ad1d6273_0
  • /data/data/####/3db90b6ff1681f41_0
  • /data/data/####/3db90b6ff1681f41_1
  • /data/data/####/3ea4d78ea985ea67_0
  • /data/data/####/3f68736e57ffefcf_0
  • /data/data/####/3f73c1528099363b_0
  • /data/data/####/409300efaa7d3b27_0
  • /data/data/####/40979483527bac85_0
  • /data/data/####/41e007fd4700d87e_0
  • /data/data/####/42ed76d44d4feb0b_0
  • /data/data/####/438c05330753b200_0
  • /data/data/####/43a55f941e9f02fe_0
  • /data/data/####/43d01cff72467a0d_0
  • /data/data/####/440d53a968c7f1c5_0
  • /data/data/####/44aab34f93bec303_0
  • /data/data/####/454a11e8855b60b1_0
  • /data/data/####/461b605a9f07e4d2_0
  • /data/data/####/46771d1102b6c57b_0
  • /data/data/####/478c84f0c7cba2b7_0
  • /data/data/####/49e0fc1db4a16fdc_0
  • /data/data/####/49f5ba5b3357a1d6_0
  • /data/data/####/4a0f848ce09f9b9d_0
  • /data/data/####/4a92ce6438577866_0
  • /data/data/####/4b497c5c5056211f_0
  • /data/data/####/4b913c7e653da06f_0 (deleted)
  • /data/data/####/4b9e40bc343ddfbf_0
  • /data/data/####/4baac7b2158954a0_0
  • /data/data/####/4cb013792b196a35_0
  • /data/data/####/4cb013792b196a35_1
  • /data/data/####/4ed0070704a56e97_0
  • /data/data/####/4efb51164db6be3f_0
  • /data/data/####/4f339779106045cf_0
  • /data/data/####/5107d8b8b3e1fd3c_0
  • /data/data/####/515b6e193c7bcc62_0
  • /data/data/####/51601d3d55b76398_0
  • /data/data/####/5272a549515cdd58_0
  • /data/data/####/52de6b2c22d44461_0
  • /data/data/####/52de6b2c22d44461_1
  • /data/data/####/53e336962895ac34_0
  • /data/data/####/53e336962895ac34_1
  • /data/data/####/55928a00bcb3c492_0
  • /data/data/####/55928a00bcb3c492_1
  • /data/data/####/55fdbaa9389ca747_0
  • /data/data/####/56199bc988541b73_0
  • /data/data/####/56199bc988541b73_1
  • /data/data/####/5628245793eede06_0
  • /data/data/####/568db1c8201e647f_0
  • /data/data/####/56d7f599dbdcf9e7_0
  • /data/data/####/57086f58d8589ebd_0
  • /data/data/####/575273229827cffe_0 (deleted)
  • /data/data/####/58246537f2bb0f4e_0
  • /data/data/####/58b30bc08e758eae_0
  • /data/data/####/5a6ec868f2ae9749_0
  • /data/data/####/5adc33531b68b7a7_0
  • /data/data/####/5b8e498d769b2c74_0
  • /data/data/####/5c26398721a255fd_0
  • /data/data/####/5ccc31855ffdc121_0
  • /data/data/####/5ccc31855ffdc121_1
  • /data/data/####/5ea0fda0f4411583_0
  • /data/data/####/5f021f109ed1c1a2_0
  • /data/data/####/5fe0a1324e7c1980_0
  • /data/data/####/60a652f8d78f3054_0
  • /data/data/####/62c7a4b13f61aac3_0
  • /data/data/####/6701d3f518e1040a_0
  • /data/data/####/6750bde6e7c0df08_0
  • /data/data/####/6750bde6e7c0df08_1
  • /data/data/####/6a99ca621f469030_0
  • /data/data/####/6b44d6a66a589119_0
  • /data/data/####/6b44d6a66a589119_1
  • /data/data/####/6c5ab3d3b77d0df3_0
  • /data/data/####/6d2b1920660b91a3_0
  • /data/data/####/6d467ada594cd778_0
  • /data/data/####/6da0ab2b7b0d1b14_0
  • /data/data/####/6e7afba5f213a003_0
  • /data/data/####/6f404f5e9ab41dc1_0
  • /data/data/####/700441978ec0336c_0
  • /data/data/####/704114333bdd3c81_0
  • /data/data/####/70cdcdc860267edd_0
  • /data/data/####/72b14750d8674382_0
  • /data/data/####/72f79cb21f6b814e_0
  • /data/data/####/72f94cf6a77fbc0d_0
  • /data/data/####/72f94cf6a77fbc0d_1
  • /data/data/####/74ff48da6135b9c3_0
  • /data/data/####/75b372ba8b3ac08e_0
  • /data/data/####/75cdd6d4f3bf1d4b_0
  • /data/data/####/765fcbe3546d14df_0
  • /data/data/####/783003eb1e2b502a_0
  • /data/data/####/7848d8f61a956a99_0
  • /data/data/####/79f078e9f94e85ca_0
  • /data/data/####/7abed74745d16bcd_0
  • /data/data/####/7b0aee4ac2c556c3_0
  • /data/data/####/7b0aee4ac2c556c3_1
  • /data/data/####/7d0e4646ae712910_0
  • /data/data/####/7e48091a74668621_0
  • /data/data/####/82334ac20a779ee9_0
  • /data/data/####/833fb3cd17a0eb00_0 (deleted)
  • /data/data/####/84be2348d4044b29_0
  • /data/data/####/85d1a37f3cd6598c_0
  • /data/data/####/873619e3b1917ad0_0
  • /data/data/####/881c7bdeb06e98b4_0
  • /data/data/####/881c7bdeb06e98b4_1
  • /data/data/####/887065dcc9d80f13_0
  • /data/data/####/8888bac454c36fa6_0
  • /data/data/####/8888bac454c36fa6_1
  • /data/data/####/8a17fbdec00c3cbf_0
  • /data/data/####/8c7215a9c322a981_0
  • /data/data/####/8ca2787823d0a3c2_0
  • /data/data/####/8ca3609561f02643_0
  • /data/data/####/8e003f0326ec389b_0 (deleted)
  • /data/data/####/8e52202d69aff8de_0
  • /data/data/####/8e54a62855dce415_0 (deleted)
  • /data/data/####/8e81b8ce9036d9cd_0
  • /data/data/####/8fe655cabbaaad92_0
  • /data/data/####/914b4d546ef0b8b6_0
  • /data/data/####/938b18e8793bc3c7_0
  • /data/data/####/938b18e8793bc3c7_1
  • /data/data/####/938d05e234fc9d92_0
  • /data/data/####/9402ef73a016ffbb_0
  • /data/data/####/95cae56d052c205b_0
  • /data/data/####/9773d0296b8dbbf0_0
  • /data/data/####/997d4ba4cb5ae546_0
  • /data/data/####/9b06f944d82f56bf_0
  • /data/data/####/9b06f944d82f56bf_1
  • /data/data/####/9b49ba033c63b83d_0
  • /data/data/####/9b64de437880cd27_0
  • /data/data/####/9eb401e684c4f15b_0
  • /data/data/####/9eb401e684c4f15b_1
  • /data/data/####/Cookies-journal
  • /data/data/####/Databases.db-journal
  • /data/data/####/JkJyOXOND.dex
  • /data/data/####/JkJyOXOND.dex.flock (deleted)
  • /data/data/####/MANIFEST-000001
  • /data/data/####/MEDrYGId.dex
  • /data/data/####/MEDrYGId.dex.flock (deleted)
  • /data/data/####/QuotaManager-journal
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a03d0ee575e34485_0
  • /data/data/####/a18c5e419bce846c_0
  • /data/data/####/a1a0eb390b604316_0
  • /data/data/####/a1a0eb390b604316_1
  • /data/data/####/a29edc4312d19735_0
  • /data/data/####/a361765e5a0dc00c_0
  • /data/data/####/a5b8cd378a90977a_0
  • /data/data/####/a62f3a5e91caf7cc_0
  • /data/data/####/a7d83db1804c7e0c_0
  • /data/data/####/a8442524169968a8_0
  • /data/data/####/a97da596e5214df1_0
  • /data/data/####/a9b2a86db302774a_0
  • /data/data/####/a9b2a86db302774a_1
  • /data/data/####/a9fb05ac05a9f2cb_0
  • /data/data/####/ac612308a2081165_0
  • /data/data/####/ac612308a2081165_1
  • /data/data/####/ac715d024b0b77ed_0
  • /data/data/####/ad2ac679ba31d740_0
  • /data/data/####/ad582fdd06fb34fd_0
  • /data/data/####/ae780e890c5a9f7f_0
  • /data/data/####/ae780e890c5a9f7f_1
  • /data/data/####/aeafe34adc808330_0
  • /data/data/####/aeafe34adc808330_1
  • /data/data/####/aec3ad517f801a65_0
  • /data/data/####/af0cb7e3c93e0dbb_0
  • /data/data/####/afb65cc5fda8f444_0
  • /data/data/####/b151f00e17d2fdb0_0
  • /data/data/####/b213848c284bb250_0
  • /data/data/####/b35ec17b7804f676_0
  • /data/data/####/b3964c57a9111354_0 (deleted)
  • /data/data/####/b4b9d41aabc22b7f_0
  • /data/data/####/b5aa2122b1bda3d7_0
  • /data/data/####/b61d3c3523e750fe_0
  • /data/data/####/b63ce765f0213f9a_0
  • /data/data/####/b7bda711931af62b_0
  • /data/data/####/b81038b40c149ec9_0
  • /data/data/####/b81038b40c149ec9_1
  • /data/data/####/b82b6c621984153e_0
  • /data/data/####/b9255c638e289c6c_0
  • /data/data/####/b97521682eb94942_0
  • /data/data/####/bafb83cf3137be60_0
  • /data/data/####/be97427b03d8575a_0
  • /data/data/####/bea435a34db2bb21_0
  • /data/data/####/bf28076ee51ac5d9_0
  • /data/data/####/c036eec35a769f8e_0
  • /data/data/####/c34210d5d3517aa6_0
  • /data/data/####/c3ad037f6aa07275_0
  • /data/data/####/c6a2d25ec1c7891d_0
  • /data/data/####/c7370a4f2cdece78_0
  • /data/data/####/c75152099e8c1e8a_0
  • /data/data/####/ca560003ac58100d_0
  • /data/data/####/ca81abc6757c617e_0
  • /data/data/####/cb9cde24f5b096f9_0
  • /data/data/####/ccb6ae163afebfc0_0
  • /data/data/####/cd1860cc1264f113_0
  • /data/data/####/cd4766294f7c0974_0
  • /data/data/####/ce0828a8b7865632_0
  • /data/data/####/ce0828a8b7865632_1
  • /data/data/####/cef8523a2f371821_0
  • /data/data/####/com.mpv_preferences.xml
  • /data/data/####/d07831d9f5acc41e_0
  • /data/data/####/d1ca85f5e2058fba_0
  • /data/data/####/d3bb34d7a0c81781_0
  • /data/data/####/d41673381c81e938_0
  • /data/data/####/d51a17c5f833cd7b_0
  • /data/data/####/d51a17c5f833cd7b_1
  • /data/data/####/d63f51ef9e6f585e_0
  • /data/data/####/d7ce659225279147_0
  • /data/data/####/d82435f16019a704_0
  • /data/data/####/d9e38d510d568732_0
  • /data/data/####/da2fe947adeaab4f_0 (deleted)
  • /data/data/####/da656b5775b93a3c_0
  • /data/data/####/dd2a948a620c0ad9_0
  • /data/data/####/dd7d99a735211063_0 (deleted)
  • /data/data/####/dda9c1be62dcb303_0
  • /data/data/####/ddab88b3537af79b_0
  • /data/data/####/dea4fb08bb0da6f1_0
  • /data/data/####/e04ecf0bca57320a_0
  • /data/data/####/e0e4f85e7b4722b6_0
  • /data/data/####/e1c091b0dc31941a_0
  • /data/data/####/e20ad25a86104f13_0 (deleted)
  • /data/data/####/e417daa654918a08_0
  • /data/data/####/e4e5ddb495ff0a18_0
  • /data/data/####/e5af8aefe7b8c11e_0
  • /data/data/####/e7faf7dc2de21844_0
  • /data/data/####/e822ee86ebc849e5_0
  • /data/data/####/e93cd3d8bcdfbbfc_0
  • /data/data/####/ea20d54324f5f093_0 (deleted)
  • /data/data/####/ea3e4ae093264954_0 (deleted)
  • /data/data/####/eaa358675e2d30b8_0 (deleted)
  • /data/data/####/ebef35fb2b0f0bf4_0
  • /data/data/####/ec948ba4885d935b_0
  • /data/data/####/ecaadf166bf6d571_0
  • /data/data/####/ee3be127a30eb399_0
  • /data/data/####/ef07203ffda029e2_0
  • /data/data/####/efd9c412c37cca6b_0
  • /data/data/####/effd37cf07a9b470_0 (deleted)
  • /data/data/####/f04dfd2bf9575409_0
  • /data/data/####/f125b5456e935c53_0
  • /data/data/####/f1a0696347a2a23c_0
  • /data/data/####/f1cdccba37924bda_0
  • /data/data/####/f1cdccba37924bda_1
  • /data/data/####/f28884e0244ccf3f_0
  • /data/data/####/f3573168d42a3151_0
  • /data/data/####/f537354abb242bc6_0
  • /data/data/####/f5953c02b68da025_0 (deleted)
  • /data/data/####/f5fa9c6556e1c73b_0
  • /data/data/####/f5fa9c6556e1c73b_1
  • /data/data/####/f7dd3533cfed2581_0
  • /data/data/####/f7f50188faf58335_0
  • /data/data/####/f8837464383b0097_0
  • /data/data/####/fb42df99782e2f0b_0
  • /data/data/####/fbd3ba0341e0b989_0
  • /data/data/####/fbdc5bf58f472c4e_0
  • /data/data/####/fc4970b776326822_0
  • /data/data/####/fd16679f42f9c828_0
  • /data/data/####/fd6f88466b3ac2f0_0
  • /data/data/####/fd9468a5f59dbadf_0
  • /data/data/####/fd9468a5f59dbadf_1
  • /data/data/####/fde163fba6e6e1da_0
  • /data/data/####/fffedbd5c41208ad_0
  • /data/data/####/index
  • /data/data/####/metrics_guid
  • /data/data/####/temp-index
  • /data/data/####/the-real-index
  • /data/data/####/yuphKULilptg.dex
  • /data/data/####/yuphKULilptg.dex.flock (deleted)
  • /data/misc/####/primary.prof
Miscellaneous:
Gets information about network.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android