Meine Bibliothek
Meine Bibliothek

+ Zur Bibliothek hinzufügen

Support

Ihre Anfragen

Rufen Sie uns an

+7 (495) 789-45-86

Profil

Android.Locker.17987

Added to the Dr.Web virus database: 2024-03-22

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Locker.1476.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) retarge####.com:443
  • TCP(TLS/1.0) analy####.go####.com:443
  • TCP(TLS/1.0) ads.traffic####.net:443
  • TCP(TLS/1.0) app.launchd####.com:443
  • TCP(TLS/1.0) rr9---s####.g####.com:443
  • TCP(TLS/1.0) www.por####.com:443
  • TCP(TLS/1.0) tgp.spice####.com:443
  • TCP(TLS/1.0) a.a####.com:443
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.0) a####.at####.com:443
  • TCP(TLS/1.0) s####.g.doublec####.net:443
  • TCP(TLS/1.0) u####.com:443
  • TCP(TLS/1.0) connect####.gst####.com:443
  • TCP(TLS/1.0) bend-me####.com:443
  • TCP(TLS/1.0) ev####.launchd####.com:443
  • TCP(TLS/1.0) cdn1-sm####.ph####.com:443
  • TCP(TLS/1.0) static2####.project####.com:443
  • TCP(TLS/1.0) bestcas####.life:443
  • TCP(TLS/1.0) f####.google####.com:443
  • TCP(TLS/1.0) clients####.launchd####.com:443
  • TCP(TLS/1.0) and####.a####.go####.com:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) 1####.250.150.139:443
  • TCP(TLS/1.0) www.go####.ru:443
  • TCP(TLS/1.0) p####.google####.com:443
  • TCP(TLS/1.0) h####.por####.com:443
  • TCP(TLS/1.0) longst####.com:443
  • TCP(TLS/1.0) bts.ins####.com:443
  • TCP(TLS/1.2) and####.a####.go####.com:443
  • TCP(TLS/1.2) p####.google####.com:443
  • UDP p####.google####.com:443
DNS requests:
  • a####.at####.com
  • a.a####.com
  • ads.traffic####.net
  • analy####.go####.com
  • and####.a####.go####.com
  • and####.google####.com
  • app.launchd####.com
  • bend-me####.com
  • bestcas####.life
  • bts.ins####.com
  • cdn1-sm####.ph####.com
  • clients####.launchd####.com
  • connect####.gst####.com
  • ei.ph####.com
  • ev####.launchd####.com
  • f####.google####.com
  • gmscomp####.google####.com
  • h####.por####.com
  • imagese####.project####.com
  • longst####.com
  • m####.traffic####.net
  • navigat####.project####.com
  • onenavi####.project####.com
  • p####.google####.com
  • retarge####.com
  • rr9---s####.g####.com
  • s####.g.doublec####.net
  • static-####.project####.com
  • static2####.project####.com
  • tgp.spice####.com
  • u####.com
  • www.go####.com
  • www.go####.ru
  • www.google####.com
  • www.google-####.com
  • www.googlet####.com
  • www.por####.com
File system changes:
Creates the following files:
  • /data/data/####/0059d4c61ef7bea0_0
  • /data/data/####/005b41e0a41f6dba_0 (deleted)
  • /data/data/####/0126430789fcad18_0
  • /data/data/####/02b5688d95f9fba8_0
  • /data/data/####/0381e936a2ac8f76_0
  • /data/data/####/05a1065be13e57f5_0
  • /data/data/####/06ba2b66939515a5_0
  • /data/data/####/091770d4d798b659_0
  • /data/data/####/0a364fb28e1eff70_0
  • /data/data/####/0b745730fa37557e_0
  • /data/data/####/0baea7948606e3b1_0
  • /data/data/####/0d41a63d89aa6a58_0
  • /data/data/####/0d54daffe4eeecee_0
  • /data/data/####/0da394a66704db47_0
  • /data/data/####/0dc5a9c73d4c02c0_0 (deleted)
  • /data/data/####/0f55aebab0744f1c_0
  • /data/data/####/11900f928bb642a1_0
  • /data/data/####/11e6d0c100ef6553_0
  • /data/data/####/11e6d0c100ef6553_1
  • /data/data/####/12c52c6fba8b5f47_0
  • /data/data/####/12c6e07b7f6660c7_0
  • /data/data/####/12c6e07b7f6660c7_1
  • /data/data/####/13b53e57478e4448_0 (deleted)
  • /data/data/####/15088d4c1506eda8_0
  • /data/data/####/15088d4c1506eda8_1
  • /data/data/####/152d558e7bdd33fc_0
  • /data/data/####/15d961bb5f094a0d_0
  • /data/data/####/168b8d1077e8f849_0
  • /data/data/####/1b0cabd38defd9f2_0 (deleted)
  • /data/data/####/1b57e9a0e92112a8_0
  • /data/data/####/1c51e192d205be56_0
  • /data/data/####/1c736a4af618eb33_0
  • /data/data/####/1c736a4af618eb33_1
  • /data/data/####/1d3424421500aa30_0
  • /data/data/####/1d58629511a89bf9_0
  • /data/data/####/1ecf4e4d63dfe6af_0
  • /data/data/####/1f4083e14aaf2f8b_0
  • /data/data/####/1f5d1ae90cc190dd_0
  • /data/data/####/1fda99d0c2eaf8cb_0
  • /data/data/####/1fda99d0c2eaf8cb_1
  • /data/data/####/1ff722b3a38744ee_0
  • /data/data/####/20458886645f1949_0
  • /data/data/####/217176e4733141e4_0
  • /data/data/####/22e07dc2c2b18f4b_0
  • /data/data/####/2398aaa0fc0a419b_0
  • /data/data/####/23dc6557657da308_0
  • /data/data/####/25e2ae58a488cea1_0
  • /data/data/####/262bc7bafb6cf6dc_0
  • /data/data/####/267c5ad279cf616a_0
  • /data/data/####/275c182eedd05a5b_0
  • /data/data/####/2940195bd9870d6e_0
  • /data/data/####/2940195bd9870d6e_1
  • /data/data/####/2aa8c64fafbc645c_0
  • /data/data/####/2b14b476d7d8b6f6_0
  • /data/data/####/2b50071db951b078_0
  • /data/data/####/2be2ca1c9968bb7d_0
  • /data/data/####/2be2ca1c9968bb7d_1
  • /data/data/####/2bf14484135729cd_0
  • /data/data/####/2c5e92b4d672edfd_0
  • /data/data/####/2d692dc02629ecc1_0
  • /data/data/####/2d8484dc6784c7a7_0
  • /data/data/####/2e3c5922b96645fc_0 (deleted)
  • /data/data/####/2e56ae2b907de178_0
  • /data/data/####/2e56ae2b907de178_1
  • /data/data/####/2fc6a9fd9a97a9c1_0
  • /data/data/####/2fd38243a7946951_0
  • /data/data/####/2fd39fa451651e9f_0
  • /data/data/####/30ad7df4a8cbb9d8_0 (deleted)
  • /data/data/####/313da557feb73d43_0
  • /data/data/####/322312923680b1ca_0 (deleted)
  • /data/data/####/33722cf88a938c86_0
  • /data/data/####/343ed422d02fe9ac_0
  • /data/data/####/343ed422d02fe9ac_s
  • /data/data/####/3928fc901b529297_0
  • /data/data/####/39362e6494ed19cc_0
  • /data/data/####/39362e6494ed19cc_1
  • /data/data/####/3a31d6041484cb8a_0
  • /data/data/####/3a31d6041484cb8a_1
  • /data/data/####/3a669c908d2b0914_0
  • /data/data/####/3b6e84b53ae6c5c0_0
  • /data/data/####/3e9cc8a6384a7bc6_0
  • /data/data/####/3ea4d78ea985ea67_0
  • /data/data/####/3eca10eb93420525_0
  • /data/data/####/40beb0ad5d29023c_0
  • /data/data/####/42c062a1061074bf_0
  • /data/data/####/43d01cff72467a0d_0
  • /data/data/####/45572931ecbedad8_0
  • /data/data/####/45d7b329c4921572_0
  • /data/data/####/46618695e86f2d0a_0
  • /data/data/####/482f58354005718a_0
  • /data/data/####/482f58354005718a_1
  • /data/data/####/484cbfc2acf20a56_0
  • /data/data/####/488fc84fd245f3fb_0
  • /data/data/####/4941d6697a4e6b13_0
  • /data/data/####/4985f7c2ae10db03_0
  • /data/data/####/4baac7b2158954a0_0
  • /data/data/####/4bcd0c66adc69813_0
  • /data/data/####/4bcd0c66adc69813_1
  • /data/data/####/4c81836fa21b7f48_0
  • /data/data/####/4e54ba40b5b8a4f5_0
  • /data/data/####/4ed0070704a56e97_0
  • /data/data/####/4ff6412c853da0e5_0
  • /data/data/####/50d7624cdb0f43b4_0
  • /data/data/####/5107d8b8b3e1fd3c_0
  • /data/data/####/518fac0b5057aba6_0
  • /data/data/####/518fac0b5057aba6_1
  • /data/data/####/521d1ace6d566c67_0
  • /data/data/####/554fc100bf62286d_0
  • /data/data/####/56199bc988541b73_0
  • /data/data/####/56199bc988541b73_1
  • /data/data/####/5675426d887a623d_0
  • /data/data/####/56c5d77ae254a86f_0
  • /data/data/####/57086f58d8589ebd_0
  • /data/data/####/570accf37ea34b0e_0
  • /data/data/####/570accf37ea34b0e_1
  • /data/data/####/58246537f2bb0f4e_0
  • /data/data/####/5939cd2cbedd7140_0
  • /data/data/####/5a2aa172a5dcdf98_0
  • /data/data/####/5a6ec868f2ae9749_0
  • /data/data/####/5b00a3b9392af891_0
  • /data/data/####/5b3c9faadf07966b_0
  • /data/data/####/5b3c9faadf07966b_1
  • /data/data/####/5c06d465bccfdfb5_0
  • /data/data/####/5ca5d0b6a1b4e269_0
  • /data/data/####/5cd3e66222b7aa34_0
  • /data/data/####/5ce862dea72d7faf_0
  • /data/data/####/5ce862dea72d7faf_1
  • /data/data/####/5fa35c56c4f1ca2d_0
  • /data/data/####/60bd2626a74130a9_0
  • /data/data/####/638d7a99b00798eb_0
  • /data/data/####/64c9cbb28868be6a_0
  • /data/data/####/64d99c4c77f64b1e_0
  • /data/data/####/6506c78553535cbc_0
  • /data/data/####/658fe53a637619ce_0
  • /data/data/####/658fe53a637619ce_1
  • /data/data/####/6658b0d61aa8c7bf_0
  • /data/data/####/66f53875ef135f74_0
  • /data/data/####/68c4dad70735f4e7_0
  • /data/data/####/6b44d6a66a589119_0
  • /data/data/####/6b44d6a66a589119_1
  • /data/data/####/6b548c6b944f9959_0
  • /data/data/####/6b65190a968af642_0
  • /data/data/####/6e0e18b6803538da_0
  • /data/data/####/6e9e73610fd80fb0_0
  • /data/data/####/6e9e73610fd80fb0_1
  • /data/data/####/6ea6687ec6b96dce_0
  • /data/data/####/70fc6d057ae6906b_0
  • /data/data/####/72a80c29e7e4b304_0
  • /data/data/####/72f79cb21f6b814e_0
  • /data/data/####/73df3fe3f889fc8c_0
  • /data/data/####/74317f94aa15fca0_0
  • /data/data/####/74e952e675561c87_0
  • /data/data/####/778f0be82918bea5_0
  • /data/data/####/78583c0e6c6a97f1_0
  • /data/data/####/78583c0e6c6a97f1_1
  • /data/data/####/788cb1db5b971757_0
  • /data/data/####/79b35c779f605ad7_0
  • /data/data/####/79fbda025aa6fb4c_0
  • /data/data/####/7a8d7594b004fdef_0
  • /data/data/####/7baf3fe32ae7dbe3_0
  • /data/data/####/7baf3fe32ae7dbe3_1
  • /data/data/####/7cfab5cfdb4360b2_0
  • /data/data/####/7d2f483fb21b60f2_0
  • /data/data/####/7d35a9d5863c713e_0
  • /data/data/####/7dfdadc8a25373b1_0
  • /data/data/####/7ea1472df485f545_0
  • /data/data/####/7ea1472df485f545_1
  • /data/data/####/7ebfe61fa105dcba_0
  • /data/data/####/7f67230712f25f00_0
  • /data/data/####/7f90b0d4bcdcda13_0
  • /data/data/####/7fb1224f011e4c60_0
  • /data/data/####/81a3020cae17f77c_0
  • /data/data/####/81cd740284fa0219_0
  • /data/data/####/82691b748d9f9bf0_0
  • /data/data/####/82ab38f3fdc03709_0
  • /data/data/####/82dd6398a51fd9c1_0
  • /data/data/####/82dd6398a51fd9c1_1
  • /data/data/####/8315bdfff64e96b8_0
  • /data/data/####/83634b22ba1beca4_0 (deleted)
  • /data/data/####/850bdb0d76413f98_0
  • /data/data/####/85ac221e7a921c33_0
  • /data/data/####/8717fac840e146aa_0
  • /data/data/####/87ac86f35d05f0f4_0
  • /data/data/####/8883dc9be7990f76_0
  • /data/data/####/8888bac454c36fa6_0
  • /data/data/####/8888bac454c36fa6_1
  • /data/data/####/89a310f4ba69008f_0
  • /data/data/####/89d5d9ec6eff375c_0
  • /data/data/####/8c8f923ad2f0e033_0
  • /data/data/####/8c8f923ad2f0e033_s
  • /data/data/####/8ca9589409dd0bdf_0
  • /data/data/####/8ca9589409dd0bdf_1
  • /data/data/####/8f16090a019c7a6c_0
  • /data/data/####/8fe8dfffa5691a91_0
  • /data/data/####/91c03514e4436347_0
  • /data/data/####/91c9a413c9a74294_0
  • /data/data/####/92b123ce64d289ec_0
  • /data/data/####/92dda78f19b4482c_0
  • /data/data/####/93cca1217764ff29_0
  • /data/data/####/9402ef73a016ffbb_0
  • /data/data/####/949d0cb185d4e4b1_0
  • /data/data/####/9780efc9eaa8261e_0
  • /data/data/####/983be4f389d08553_0
  • /data/data/####/9882183e18bdf22f_0
  • /data/data/####/9a1bf0afe324c249_0
  • /data/data/####/9ad5934ebe40adcf_0
  • /data/data/####/Cookies-journal
  • /data/data/####/QpQdMtc.dex
  • /data/data/####/QpQdMtc.dex.flock (deleted)
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a1a0eb390b604316_0
  • /data/data/####/a1a0eb390b604316_1
  • /data/data/####/a1c015c8bf0a688e_0
  • /data/data/####/a2decdfde9c96d86_0
  • /data/data/####/a2decdfde9c96d86_1
  • /data/data/####/a317d8b09bea59df_0
  • /data/data/####/a322076a67b8e115_0
  • /data/data/####/a322076a67b8e115_1
  • /data/data/####/a843c17ea6422a27_0
  • /data/data/####/a8442524169968a8_0
  • /data/data/####/a8d76b3c036da53b_0 (deleted)
  • /data/data/####/a97da596e5214df1_0
  • /data/data/####/aab31b6cb16b23e8_0
  • /data/data/####/ac3764da7921ec4e_0 (deleted)
  • /data/data/####/ae97ee15aa894569_0
  • /data/data/####/ae97ee15aa894569_1
  • /data/data/####/aeafe34adc808330_0
  • /data/data/####/aeafe34adc808330_1
  • /data/data/####/b19ff7a7d0e34fb5_0
  • /data/data/####/b213848c284bb250_0
  • /data/data/####/b47a66e11699c9c2_0
  • /data/data/####/b5aa2122b1bda3d7_0
  • /data/data/####/b6005ed34a8f2253_0
  • /data/data/####/b7bda711931af62b_0
  • /data/data/####/b7c74daf294c9e64_0
  • /data/data/####/b81038b40c149ec9_0
  • /data/data/####/b81038b40c149ec9_1
  • /data/data/####/b847531a252dd22e_0
  • /data/data/####/b847531a252dd22e_1
  • /data/data/####/b8dc3c6e672df52f_0
  • /data/data/####/b8dc3c6e672df52f_1
  • /data/data/####/b8faf34b2a19d3d8_0
  • /data/data/####/b97521682eb94942_0
  • /data/data/####/baa4362b716a66cf_0
  • /data/data/####/be97427b03d8575a_0
  • /data/data/####/c07d78cdfd2fcace_0
  • /data/data/####/c07d78cdfd2fcace_1
  • /data/data/####/c0eea2eef45f3bd7_0
  • /data/data/####/c24a544b58357c9f_0
  • /data/data/####/c24a544b58357c9f_1
  • /data/data/####/c3ad037f6aa07275_0
  • /data/data/####/c41f142177a71782_0
  • /data/data/####/c41f142177a71782_1
  • /data/data/####/c42ced0c58dfae8b_0
  • /data/data/####/c57b6524763fe785_0
  • /data/data/####/c71345ba9b79ac4f_0
  • /data/data/####/c75152099e8c1e8a_0
  • /data/data/####/c79137e2af59753c_0
  • /data/data/####/c7da7fc1fd72af35_0
  • /data/data/####/c96d7944a0933d1f_0
  • /data/data/####/cPoLPiSF.dex
  • /data/data/####/cPoLPiSF.dex.flock (deleted)
  • /data/data/####/ccb6ae163afebfc0_0
  • /data/data/####/cda3446cf7640c41_0
  • /data/data/####/ce9108e7636f8a68_0
  • /data/data/####/ce99954b54aff87b_0
  • /data/data/####/com.mzpk_preferences.xml
  • /data/data/####/d0655a2873de0ed0_0
  • /data/data/####/d479f41ddbccc691_0
  • /data/data/####/d479f41ddbccc691_1
  • /data/data/####/d64de2a0b3cdf4c0_0
  • /data/data/####/d8de5994cbfa3c7c_0
  • /data/data/####/d920c3764ce9d20b_0
  • /data/data/####/d943e1bffc20bdfd_0
  • /data/data/####/da28a6662d437787_0
  • /data/data/####/da656b5775b93a3c_0
  • /data/data/####/dac9d998e0af9cbc_0
  • /data/data/####/dac9d998e0af9cbc_1
  • /data/data/####/dad378f1f69a5264_0
  • /data/data/####/db45d21546710377_0 (deleted)
  • /data/data/####/ddc3ef6b883c5231_0
  • /data/data/####/ddc3ef6b883c5231_1
  • /data/data/####/deacbd6e155e6608_0
  • /data/data/####/deb446e59ad6269d_0
  • /data/data/####/df33f33c7f159d65_0
  • /data/data/####/e1cdb9afa3ca6e9e_0
  • /data/data/####/e372bcc226f82f98_0
  • /data/data/####/e426227ca88887e4_0 (deleted)
  • /data/data/####/e50dcc39d439da14_0
  • /data/data/####/ea3d8d50f8615d85_0
  • /data/data/####/eb04cf63d48c544a_0
  • /data/data/####/ebcbdd115cf1772c_0
  • /data/data/####/ebef35fb2b0f0bf4_0
  • /data/data/####/ec784b3a345a6fa1_0
  • /data/data/####/ecaadf166bf6d571_0
  • /data/data/####/ece6b6e97314b812_0
  • /data/data/####/ee62a3850636e459_0
  • /data/data/####/ee62a3850636e459_1
  • /data/data/####/ee7c567ff5c646ec_0
  • /data/data/####/effd37cf07a9b470_0 (deleted)
  • /data/data/####/f1a0696347a2a23c_0
  • /data/data/####/f2e3ac55102aaa99_0
  • /data/data/####/f3b9acb96c8e8ad4_0
  • /data/data/####/f3bc64089fc60292_0
  • /data/data/####/f3bc64089fc60292_1
  • /data/data/####/f409b8f111702c1d_0
  • /data/data/####/f4c9901f39e64574_0 (deleted)
  • /data/data/####/f537354abb242bc6_0
  • /data/data/####/f59083fab2974a70_0
  • /data/data/####/f5fa9c6556e1c73b_0
  • /data/data/####/f5fa9c6556e1c73b_1
  • /data/data/####/f7500a8851274211_0
  • /data/data/####/f752dc463338e643_0
  • /data/data/####/f752dc463338e643_1
  • /data/data/####/f8095dc0e69b4992_0
  • /data/data/####/f91a4e6edf69664b_0
  • /data/data/####/fa652d60e86fb0f4_0
  • /data/data/####/fb01075d1cc892ed_0
  • /data/data/####/fbd3ba0341e0b989_0
  • /data/data/####/fc4970b776326822_0
  • /data/data/####/fc639a22884e5532_0
  • /data/data/####/fd16679f42f9c828_0
  • /data/data/####/fd6f88466b3ac2f0_0
  • /data/data/####/fe2e4a0046ad19a9_0
  • /data/data/####/fe2e4a0046ad19a9_1
  • /data/data/####/index
  • /data/data/####/metrics_guid
  • /data/data/####/oxBwUD.dex
  • /data/data/####/oxBwUD.dex.flock (deleted)
  • /data/data/####/the-real-index
  • /data/misc/####/primary.prof
Miscellaneous:
Gets information about network.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android