Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.Packed.19876

Added to the Dr.Web virus database: 2017-03-22

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Backdoor.269.origin
  • Android.Mixi.13.origin
Network activity:
Connecting to:
  • s####.####.com
  • t####.####.com
  • v####.####.com
  • g####.####.com
  • zhuan####.name
  • p####.####.com
  • l####.####.com
  • c####.####.com
  • d####.####.com
  • n####.####.cn
  • m####.####.name
  • w####.####.com
  • z####.####.com
  • y####.com
  • i####.####.cn
  • f####.####.cn
  • a####.####.com
  • ub####.####.com
HTTP GET requests:
  • zhuan####.name/d/file/titlepic/2016/10/03/1fvun0551li.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/xdu50exel1b.png
  • z####.####.com/ztd/w%3D350%3Bq%3D70/sign=d248b23b03d162d985ee641921e4d8d1/ca1349540923dd54860e5b97d809b3de9d8248d4.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/4n0lu1fmkjq.jpg
  • m####.####.name/images/dd.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/luojlj1qwls.jpg
  • g####.####.com/cr/sdk/goplaysdk_statistics_method.dat
  • m####.####.name/images/hdx.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/r2f5u1zgrvt.jpg
  • s####.####.com/s.htm?cproid=####&t=####
  • m####.####.name/d/js/acmsd/thea13.js
  • l####.####.com/jquery/1.4.1/jquery.min.js
  • c####.####.com/cpro/ui/noexpire/img/chapin/look2.png
  • c####.####.com/cpro/ui/noexpire/img/mob_adicon.png
  • f####.####.cn/focus/conf?device_type=####&height=####&dpi=####&android_id=####&width=####&cid=####&networkType=####&version=####&conn=####&imei=####&o...
  • zhuan####.name/d/file/titlepic/2016/10/03/pi0iejyjmi2.jpg
  • m####.####.name/images/qmx.jpg
  • a####.####.com/goapk/gp_tenqq.7z
  • z####.####.com/ztd/w%3D350%3Bq%3D70/sign=e77913b67b8b4710ce2ffbc9f3f5b2c0/d6ca7bcb0a46f21fe3d1b5c4ff246b600d33ae44.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/2izznq0kzhv.png
  • m####.####.name/images/app/ListMenu.png
  • zhuan####.name/d/file/titlepic/2016/10/03/qy440uauqob.png
  • d####.####.com/ymian/index-3.html
  • m####.####.name/images/aa.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/dvlbxdbcezj.png
  • zhuan####.name/d/file/titlepic/2016/10/03/hl50igo04y3.jpg
  • m####.####.name/images/grey.png
  • zhuan####.name/d/file/titlepic/2016/10/03/mwz0sra4i10.png
  • zhuan####.name/d/file/titlepic/2016/10/03/j0jx0b5b4ds.png
  • m####.####.name/js/27270App.js
  • f####.####.cn/focus/st?status=####&cid=####&source=####&requestid=####
  • c####.####.com/cpro/ui/noexpire/img/chapin/stand.png
  • m####.####.name/word/gaoxiaoqutu/
  • m####.####.name/images/hdx2.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/uzz3i53cw1z.png
  • c####.####.com/sync.htm?cproid=####
  • m####.####.name/images/app/logo.png
  • zhuan####.name/d/file/titlepic/2016/10/03/qjvneb0pb0k.png
  • d####.####.com/ymian/index-4.html
  • t####.####.com/it/u=903168626,204005588&fm=76
  • zhuan####.name/d/file/ztpic/2016/09/12/tiudyvdisd5.jpg
  • t####.####.com/it/u=3593248742,1654771676&fm=76
  • zhuan####.name/d/file/titlepic/2016/10/03/yuaoldbpr32.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/xaotlrp43v2.png
  • zhuan####.name/d/file/titlepic/2016/10/03/pl01ov4o1ny.png
  • z####.####.com/ztd/w%3D350%3Bq%3D70/sign=44ea466d6581800a6ee58f0b810e42c7/63d9f2d3572c11df3c5e00c16a2762d0f603c241.jpg
  • p####.####.com/vclm?sz=####&rdid=####&dc=####&di=####&dri=####&dis=####&dai=####&ps=####&dcb=####&dtm=####&dvi=####&dci=####&dpt=####&tsr=####&tpr=###...
  • zhuan####.name/d/file/titlepic/2016/10/03/i4ae4qcjlr0.jpg
  • z####.####.com/ztd/w%3D350%3Bq%3D70/sign=b47332668b26cffc692ab9b7893a3bad/8c1001e93901213fbb380a235de736d12e2e95c1.jpg
  • p####.####.com/ycdm?rdid=####&dc=####&di=####&dri=####&dis=####&dai=####&ps=####&coa=####&dcb=####&dtm=####&dvi=####&dci=####&dpt=####&tsr=####&tpr=##...
  • ub####.####.com/media/v1/0f000rT87Hk1Ld3_7MGVa6.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/calnevtlwcb.jpg
  • f####.####.cn/focus/st?count=####&status=####&cid=####&source=####&viewid0=####
  • p####.####.com/ma_icon/0/icon_10936_1490086759/256
  • zhuan####.name/d/file/titlepic/2016/10/03/jofgnef40mq.png
  • zhuan####.name/d/file/ztpic/2016/09/12/swftgyoz3qv.jpg
  • z####.####.com/ztd/w%3D350%3Bq%3D70/sign=ef474bcd53afa40f3cc6c8d89b5f7272/96dda144ad3459822e00196d05f431adcaef8443.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/irgs0wfvxol.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/ewrh4cwlnxa.png
  • zhuan####.name/d/file/titlepic/2016/10/03/a5qveslexvt.png
  • n####.####.cn/?s=####&t=####&g=####
  • i####.####.cn/iplookup/iplookup.php?format=####
  • zhuan####.name/d/file/titlepic/2016/10/03/3wero3qk22e.png
  • z####.####.com/ztd/w%3D350%3Bq%3D70/sign=f0bd8b5cbbfb43161a1f7c7f109f371e/a71ea8d3fd1f41345adaeee92c1f95cad0c85ebc.jpg
  • m####.####.name/js/ArticleSlide.js
  • zhuan####.name/d/file/titlepic/2016/10/03/vjn4zvylr0x.jpg
  • m####.####.name/d/js/acmsd/thea11.js
  • t####.####.com/it/u=680562940,21965488&fm=76
  • p####.####.com/ycdm?di=####&dri=####&dis=####&dai=####&ps=####&dcb=####&dtm=####&dvi=####&dci=####&dpt=####&tsr=####&tpr=####&ti=####&ari=####&dbv=###...
  • c####.####.com/cpro/ui/noexpire/img/chapin/shrink2.png
  • z####.####.com/ztd/w%3D350%3Bq%3D70/sign=6b5054b46a2762d0803ea2ba90d779c7/b2de9c82d158ccbfae3d5ead10d8bc3eb03541a0.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/5ryvelly1ra.png
  • z####.####.com/ztd/w%3D350%3Bq%3D70/sign=4764c3860023dd542173a16de132c2e3/b999a9014c086e0691e280a90b087bf40bd1cb8e.jpg
  • p####.####.com/sync_pos.htm?cproid=####&t=####
  • zhuan####.name/d/file/titlepic/2016/10/03/4io4clu55xi.jpg
  • zhuan####.name/d/file/p/2016-10-04/dabade4a1cfb76c87a2d15a002304d5f.jpg
  • t####.####.com/it/u=4139712021,1947734414&fm=76
  • m####.####.name/d/js/acmsd/thea14.js
  • t####.####.com/it/u=1460541777,1854292848&fm=76
  • c####.####.com/pixel?sspid=####&local_cookie=####&ver=####&ext=####
  • zhuan####.name/d/file/titlepic/2016/10/03/nbpweuhsbij.png
  • c####.####.com/cpro/expire/time2.js
  • t####.####.com/it/u=325217858,2035764721&fm=76
  • zhuan####.name/d/file/titlepic/2016/10/03/gi14pwcwijv.jpg
  • m####.####.name/images/fbb.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/wdxunzhnw2z.png
  • m####.####.name/css/NewApp.css
  • zhuan####.name/d/file/titlepic/2016/10/03/j1h11bjm1iz.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/a2k41xc3n4n.png
  • zhuan####.name/d/file/ztpic/2016/09/12/nmzzkztyouf.jpg
  • p####.####.com/vclm?di=####&dri=####&dis=####&dai=####&ps=####&dcb=####&dtm=####&dvi=####&dci=####&dpt=####&tsr=####&tpr=####&ti=####&ari=####&dbv=###...
  • zhuan####.name/d/file/titlepic/2016/10/03/4rt5pjl5j0g.png
  • zhuan####.name/d/file/titlepic/2016/10/03/g5ezkrcyogp.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/y5f5lljw4mb.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/fangxgh5tpt.png
  • zhuan####.name/d/file/titlepic/2016/10/03/i52dnhhi33d.png
  • t####.####.com/it/u=1388841688,512282784&fm=76
  • t####.####.com/it/u=3977759114,3573193565&fm=76
  • zhuan####.name/d/file/titlepic/2016/10/03/2o5q3pbx0st.png
  • m####.####.name/js/global.js
  • l####.####.com/timg?pacomp####&imgtype=####&sec=####&di=####&quality=####&size=####&src=####
  • p####.####.com/sync_pos.htm?cproid=####
  • t####.####.com/it/u=2195457806,928786945&fm=76
  • z####.####.com/ztd/w%3D350%3Bq%3D70/sign=af4cc0389952982205333fc6e7f10af6/94cad1c8a786c9179651aec6c03d70cf3ac757fb.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/qmtgblcteya.png
  • zhuan####.name/d/file/titlepic/2016/10/03/hk2ueoav4ga.png
  • c####.####.com/cpro/ui/noexpire/img/2.0.1/bd-logo4.png
  • w####.####.com/adx.php?c=####
  • zhuan####.name/d/file/ztpic/2016/09/12/54fzp4py2wy.jpg
  • t####.####.com/cm.gif?ver=####&mid=####&uid=####
  • zhuan####.name/d/file/titlepic/2016/10/03/fgtgzaquow5.png
  • t####.####.com/it/u=1043586457,172880515&fm=76
  • z####.####.com/ztd/w%3D350%3Bq%3D70/sign=cce5506643ed2e73fce98029b73ad0b6/91ef76c6a7efce1b67897728a651f3deb58f65b6.jpg
  • zhuan####.name/d/file/ztpic/2016/09/12/jwq5rzrfa15.jpg
  • m####.####.name/images/app/HomeIco.png
  • zhuan####.name/d/file/titlepic/2016/10/03/0otbbmapiwf.png
  • zhuan####.name/d/file/titlepic/2016/10/03/arzq4nci11u.png
  • c####.####.com/cpro/ui/cm.js
  • zhuan####.name/d/file/titlepic/2016/10/03/lz3mtqfr5jl.png
  • zhuan####.name/d/file/titlepic/2016/10/03/nkfy1jqa3my.jpg
  • m####.####.name/d/js/acmsd/thea15.js
  • zhuan####.name/d/file/titlepic/2016/10/03/5c4vqxfz40u.png
  • zhuan####.name/d/file/ztpic/2016/09/12/xmrp1ieajb0.jpg
  • zhuan####.name/d/file/titlepic/2016/10/03/t51e4l3grrr.png
  • zhuan####.name/d/file/titlepic/2016/10/03/doe0ki4loru.png
  • zhuan####.name/d/file/ztpic/2016/09/12/phdc3a2re4v.jpg
  • c####.####.com/cpro/ui/noexpire/img/chapin/blank.png
HTTP POST requests:
  • w####.####.com/api/getCfg.jsp
  • a####.####.com/v1/cfg
  • w####.####.com/api/uploadInstallApps.jsp
  • w####.####.com/api/getInAppFull.jsp
  • w####.####.com/api/getAlist.jsp
  • w####.####.com/api/getLauncher.jsp
  • y####.com/cu.ashx
  • f####.####.cn/focus/atex
  • w####.####.com/api/getSI.jsp
  • w####.####.com/api/getFallDown.jsp
  • a####.####.com/v1/bind
  • f####.####.cn/focus/req
  • g####.####.com/cr/sv/getEP
  • w####.####.com/api/getStartPop.jsp
  • w####.####.com/api/getStartDialog.jsp
  • a####.####.com/v1/ins/apps
  • w####.####.com/api/uploadSaleInfo.jsp
  • w####.####.com/api/getInAppNonFull.jsp
  • w####.####.com/api/getInAppFloat.jsp
  • w####.####.com/api/getSlidingScreen.jsp
  • w####.####.com/api/getStartNonFull.jsp
  • w####.####.com/adx.php?c=####&ext=####
  • w####.####.com/api/getAreaId.jsp
  • w####.####.com/api/getStartFull.jsp
  • w####.####.com/api/getDtk.jsp
  • v####.####.com/gdt_stats.fcg
  • w####.####.com/api/getNotification.jsp
  • w####.####.com/api/getExit.jsp
  • w####.####.com/api/getStartWin.jsp
  • w####.####.com/api/getFloat.jsp
Modified file system:
Creates the following files:
  • /data/data/####/shared_prefs/online.xml.bak
  • /data/data/####/cache/webviewCacheChromium/f_00002f
  • /data/data/####/cache/webviewCacheChromium/f_00002e
  • /data/data/####/cache/webviewCacheChromium/f_00002d
  • /data/data/####/cache/webviewCacheChromium/f_00002c
  • /data/data/####/cache/webviewCacheChromium/f_00002b
  • /data/data/####/cache/webviewCacheChromium/f_00002a
  • /data/data/####/shared_prefs/LauncherApp.xml
  • /data/data/####/cache/webviewCacheChromium/f_000020
  • /data/data/####/files/lmoevssnujlybeprprfvzkppncuacgdjp
  • /data/data/####/cache/webviewCacheChromium/data_3
  • /data/data/####/cache/webviewCacheChromium/data_2
  • /data/data/####/cache/webviewCacheChromium/data_1
  • /data/data/####/cache/webviewCacheChromium/data_0
  • /data/data/####/databases/webviewCookiesChromium.db-journal
  • /sdcard/.android/data/com.android.db/dataBase/rxdn01/####.db-journal
  • /data/data/####/shared_prefs/pp.xml.bak
  • /data/data/####/shared_prefs/umeng_general_config.xml
  • /data/data/####/cache/webviewCacheChromium/f_00000e
  • /data/data/####/app_cache/####1485418424012.jar
  • /data/data/####/files/wca.jar
  • /data/data/####/app_cache/####1485418422299.jar
  • /data/data/####/files/1485418432270_cgr.so
  • /data/data/####/databases/webview.db-journal
  • /data/data/####/cache/webviewCacheChromium/f_000026
  • /data/data/####/cache/webviewCacheChromium/f_000025
  • /data/data/####/cache/webviewCacheChromium/f_000024
  • /data/data/####/cache/webviewCacheChromium/f_000023
  • /data/data/####/cache/webviewCacheChromium/f_000022
  • /data/data/####/cache/webviewCacheChromium/f_000021
  • /data/data/####/shared_prefs/config.xml
  • /sdcard/Download/images/journal
  • /data/data/####/cache/webviewCacheChromium/f_000029
  • /data/data/####/cache/webviewCacheChromium/f_000028
  • /sdcard/device
  • /data/data/####/app_cache/####1485418421934.jar
  • /data/data/####/cache/webviewCacheChromium/index
  • /data/data/####/shared_prefs/localtime.xml
  • /data/data/####/cache/webviewCacheChromium/f_00000a
  • /data/data/####/cache/webviewCacheChromium/f_00000c
  • /data/data/####/cache/webviewCacheChromium/f_00000b
  • /data/data/####/files/1485418447576.jar
  • /data/data/####/cache/webviewCacheChromium/f_00000d
  • /data/data/####/cache/webviewCacheChromium/f_00000f
  • /data/data/####/cache/webviewCacheChromium/f_000034
  • /sdcard/Android/data/system/cache/.hb/swhm_l_hb_t
  • /data/data/####/cache/webviewCacheChromium/f_000036
  • /data/data/####/cache/webviewCacheChromium/f_000037
  • /data/data/####/cache/webviewCacheChromium/f_000030
  • /data/data/####/cache/webviewCacheChromium/f_000031
  • /data/data/####/cache/webviewCacheChromium/f_000032
  • /data/data/####/cache/webviewCacheChromium/f_000033
  • /data/data/####/cache/webviewCacheChromium/f_000038
  • /data/data/####/cache/webviewCacheChromium/f_000039
  • /sdcard/Android/data/system/cache/.hb/ntbhbm_l_hb_t
  • /data/data/####/files/f6561a5d047a689dd254bf3e046930a6
  • /data/data/####/files/yw.db
  • /data/data/####/cache/webviewCacheChromium/f_00001e
  • /sdcard/Android/data/system/cache/.hb/sfhm_l_hb_t
  • /sdcard/Android/data/system/cache/.hb/fhbm_l_hb_t
  • /sdcard/Android/data/system/cache/.hb/IUhbm_l_hb_t
  • /data/data/####/cache/webviewCacheChromium/f_00003a
  • /data/data/####/cache/webviewCacheChromium/f_00003b
  • /data/data/####/cache/webviewCacheChromium/f_00003c
  • /data/data/####/cache/webviewCacheChromium/f_000009
  • /data/data/####/cache/webviewCacheChromium/f_000008
  • /data/data/####/cache/webviewCacheChromium/f_000001
  • /data/data/####/cache/webviewCacheChromium/f_000003
  • /data/data/####/cache/webviewCacheChromium/f_000002
  • /data/data/####/cache/webviewCacheChromium/f_000005
  • /data/data/####/cache/webviewCacheChromium/f_000004
  • /data/data/####/cache/webviewCacheChromium/f_000007
  • /data/data/####/cache/webviewCacheChromium/f_000006
  • /sdcard/Android/data/system/cache/.hb/sihbm_l_hb_t
  • /data/data/####/files/####_cgr
  • /sdcard/Android/data/system/cache/.hb/exthbm_l_hb_t
  • /data/data/####/app_cache/####1485418421073.jar
  • /sdcard/Android/data/system/cache/.hb/sdhm_l_hb_t
  • /data/data/####/files/80.tmp
  • /sdcard/Android/data/system/cache/.hb/insiohbm_l_hb_t
  • /data/data/####/cache/webviewCacheChromium/f_000018
  • /data/data/####/cache/webviewCacheChromium/f_000019
  • /data/data/####/cache/webviewCacheChromium/f_000016
  • /data/data/####/cache/webviewCacheChromium/f_000017
  • /data/data/####/cache/webviewCacheChromium/f_000014
  • /data/data/####/cache/webviewCacheChromium/f_000015
  • /data/data/####/cache/webviewCacheChromium/f_000012
  • /data/data/####/cache/webviewCacheChromium/f_000013
  • /data/data/####/cache/webviewCacheChromium/f_000010
  • /data/data/####/cache/webviewCacheChromium/f_000011
  • /data/data/####/shared_prefs/pp.xml
  • /sdcard/Android/data/system/cache/.hb/snfhm_l_hb_t
  • /data/data/####/databases/cc/cc.db-journal
  • /sdcard/Android/data/system/cache/.hb/cfghbm_l_hb_t
  • /data/data/####/shared_prefs/localtime.xml.bak
  • /data/data/####/shared_prefs/online.xml
  • /data/data/####/files/hftJcw46N.jar
  • /data/data/####/cache/webviewCacheChromium/f_00001d
  • /data/data/####/shared_prefs/device.xml
  • /data/data/####/cache/webviewCacheChromium/f_00001b
  • /data/data/####/cache/webviewCacheChromium/f_00001c
  • /data/data/####/cache/webviewCacheChromium/f_00001a
  • /data/data/####/shared_prefs/####.xml
  • /sdcard/Android/data/system/cache/.hb/falhbm_l_hb_t
  • /data/data/####/cache/webviewCacheChromium/f_000035
  • /sdcard/Android/data/system/cache/.hb/insiwfhbm_l_hb_t
  • /data/data/####/shared_prefs/####.xml.bak
  • /data/data/####/shared_prefs/####_preferences.xml
  • /sdcard/Android/data/system/cache/.hb/lauhbm_l_hb_t
  • /data/data/####/databases/cc/cc.db
  • /data/data/####/files/us.908GhK3z1XIE6J7u3B4nRKlfEI88s
  • /data/data/####/shared_prefs/areaInfo.xml
  • /data/data/####/cache/webviewCacheChromium/f_00001f
  • /sdcard/Android/data/system/cache/.hb/DtkAdbm_l_hb_t
  • /sdcard/Android/data/system/cache/.hb/sdhbm_l_hb_t
  • /sdcard/Android/data/system/cache/.hb/insifhbm_l_hb_t
  • /data/data/####/files/mobclick_agent_cached_####2
  • /data/data/####/files/webview/localstorage/http_m.zhuangxiu.name_0.localstorage-journal
  • /data/data/####/cache/webviewCacheChromium/f_000027
  • /data/data/####/shared_prefs/umeng_general_config.xml.bak
  • /data/data/####/databases/baidu_guv-journal
  • /sdcard/Android/data/system/cache/.hb/sihm_l_hb_t
Sets the 'executable' attribute to the following files:
  • /data/data/####/files/us.908GhK3z1XIE6J7u3B4nRKlfEI88s
Miscellaneous:
Executes next shell scripts:
  • getenforce
  • /data/data/####/files/us.908GhK3z1XIE6J7u3B4nRKlfEI88s -h a311ca0be36f48fb8e4ab6f6e22481b3 /data/data/####/.syslib-
  • chmod 0771 /data/data/####/.syslib-
  • ping -c 2 -w 5 f####.####.cn
Contains functionality to send SMS messages automatically.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android