Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.SmsSpy.6421

Added to the Dr.Web virus database: 2018-04-05

Virus description added:

Technical information

Malicious functions:
Sends SMS messages:
  • 106904006189121: myqxt<IMSI>
Executes code of the following detected threats:
  • Android.DownLoader.441.origin
  • Android.SmsSend.21305
  • Android.SmsSend.23889
  • Android.Spy.398.origin
  • Android.Triada.235.origin
  • Android.Triada.236.origin
  • Android.Triada.243
  • Android.Triada.248.origin
  • Android.Triada.351.origin
  • Android.Triada.373.origin
Sends data on received text messages to remote host.
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) c####.baidust####.com:80
  • TCP(HTTP/1.1) pay.lik####.com:7820
  • TCP(HTTP/1.1) wn.pos.b####.com:80
  • TCP(HTTP/1.1) crs.b####.com:80
  • TCP(HTTP/1.1) t.y####.com.####.com:80
  • TCP(HTTP/1.1) dws.you####.com.####.com:8080
  • TCP(HTTP/1.1) jx.ha####.com:80
  • TCP(HTTP/1.1) hm.b####.com:80
  • TCP(HTTP/1.1) dup.baidust####.com:80
  • TCP(HTTP/1.1) cm.pos.b####.com:80
  • TCP(HTTP/1.1) a####.xctr####.com:12580
  • TCP(HTTP/1.1) pos.b####.com:80
  • TCP(HTTP/1.1) si####.jom####.com:80
  • TCP(HTTP/1.1) c####.jd.com:80
  • TCP(HTTP/1.1) t####.y####.com:80
  • TCP(HTTP/1.1) 1####.27.154.102:1234
  • TCP(HTTP/1.1) hpd.b####.com:80
  • TCP(HTTP/1.1) h5.y####.y####.com:80
  • TCP(HTTP/1.1) pay.lik####.com:7830
  • TCP(HTTP/1.1) i####.y####.cc####.####.cn:80
  • TCP(HTTP/1.1) pus####.to####.net:80
  • TCP(HTTP/1.1) pay.lik####.com:7840
  • TCP(HTTP/1.1) s####.ha####.com:9999
  • TCP(HTTP/1.1) s.c####.b####.com:80
  • TCP(HTTP/1.1) m.b####.com:80
  • TCP(HTTP/1.1) x####.ha####.com:80
  • TCP(HTTP/1.1) jx####.ha####.com:9999
  • TCP(HTTP/1.1) h5.www.y####.####.com:80
  • TCP(HTTP/1.1) supermo####.jom####.com:80
  • TCP(TLS/1.0) www.a.sh####.com:443
  • TCP(TLS/1.0) dup.baidust####.com:443
  • TCP(TLS/1.0) c####.baidust####.com:443
  • TCP(TLS/1.0) c####.b####.com:443
  • TCP(TLS/1.0) hpd.b####.com:443
  • TCP(TLS/1.0) ec####.b####.com:443
  • TCP(TLS/1.0) m.b####.com:443
  • TCP(TLS/1.0) t.y####.cn.####.com:443
  • TCP(TLS/1.0) ss0.b####.com:443
  • TCP(TLS/1.0) i####.y####.cn.####.com:443
  • TCP(TLS/1.0) t####.y####.com:443
  • TCP(TLS/1.0) hm.b####.com:443
  • TCP(TLS/1.0) pos.b####.com:443
  • TCP(TLS/1.0) ss0.bdst####.com:443
  • TCP(TLS/1.0) g####.bdst####.com:443
  • TCP(TLS/1.0) si####.jom####.com:443
  • TCP(TLS/1.0) ti####.jom####.com:443
DNS requests:
  • a####.xctr####.com
  • api.lik####.com
  • c####.b####.com
  • c####.b####.com
  • c####.baidust####.com
  • c####.baidust####.com
  • c####.jd.com
  • cm.pos.b####.com
  • crs.b####.com
  • do####.abc####.info
  • dup.baidust####.com
  • dws.you####.com
  • ec####.b####.com
  • f10.b####.com
  • f11.b####.com
  • f12.b####.com
  • g####.bdst####.com
  • g####.bdst####.com
  • h5.www.y####.com
  • h5.y####.y####.com
  • hm.b####.com
  • hpd.b####.com
  • i####.y####.cn
  • i####.y####.com
  • i####.y####.com
  • i####.y####.com
  • jx####.ha####.com
  • jx.ha####.com
  • m.b####.com
  • mt####.go####.com
  • pay.lik####.com
  • pos.b####.com
  • pus####.to####.net
  • pus####.tou####.cn
  • r####.b####.com
  • r####.y####.com
  • res.y####.com
  • s####.ha####.com
  • s.bdst####.com
  • s.c####.b####.com
  • sm.b####.com
  • sp0.b####.com
  • sp1.b####.com
  • ss0.b####.com
  • ss0.bdst####.com
  • ss1.b####.com
  • ss2.b####.com
  • t####.y####.com
  • t.y####.cn
  • t.y####.com
  • t10.b####.com
  • t11.b####.com
  • t12.b####.com
  • timg####.b####.com
  • up####.abc####.info
  • wn.pos.b####.com
  • www.y####.com
  • x####.ha####.com
HTTP GET requests:
  • a####.xctr####.com:12580/log2?c=####
  • c####.baidust####.com/cpro/ui/cm.js
  • c####.baidust####.com/cpro/ui/noexpire/img/2.0.1/bd-logo4.png
  • c####.baidust####.com/sync.htm?cproid=####
  • c####.jd.com/du?&baidu_error=####&timestamp=####
  • c####.jd.com/du?&baidu_user_id=####&cookie_version=####&timestamp=####&e...
  • cm.pos.b####.com/pixel?dspid=####
  • crs.b####.com/jsonp.js?siteId=####&planId=####&referer=####&title=####&p...
  • crs.b####.com/tapi.js?planId=####&siteId=####
  • crs.b####.com/tj.gif?si=####&st=####&nv=####&et=####&ep=####&at=####&rnd...
  • dup.baidust####.com/js/dm.js
  • dup.baidust####.com/js/om.js
  • dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.damai_p2018032...
  • dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.miwan_p2017090...
  • dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.myadv_p2017052...
  • dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.mysdk_p2018032...
  • dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.qipa_p20171206...
  • dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.shangan_p20180...
  • dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.taiku_p2017120...
  • dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.utadv_p2017081...
  • dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.yufeng_p201711...
  • dws.you####.com.####.com:8080/upload/plugin/net.tt.plugin.zhongzhi_p2017...
  • h5.www.y####.####.com/
  • h5.www.y####.####.com/index.html
  • h5.y####.y####.com/
  • h5.y####.y####.com/2018/04/05/1085106t2827.html
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&ep=####&et=#...
  • hm.b####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&vl=####&et=####&ja=#...
  • hm.b####.com/hm.gif?si=####&st=####&nv=####&et=####&ep=####&rnd=####
  • hm.b####.com/hm.js?0fbac86####
  • hpd.b####.com/v.gif?tid=####&ct=####&cst=####&logFrom=####&logInfo=####&...
  • i####.y####.cc####.####.cn/2018/03/02/7dfd8b599e26ddac4c00e916f64060d3_7...
  • i####.y####.cc####.####.cn/2018/03/28/1696cadffb9124b29f6bb1038be01953_2...
  • i####.y####.cc####.####.cn/2018/03/28/790128bbead6acd1912ee729f2af5324_2...
  • i####.y####.cc####.####.cn/2018/03/30/33e68a7a6df4e8ff653923981bd213b6_1...
  • i####.y####.cc####.####.cn/2018/03/30/4e9c1361b1ff71853bfa9b359eda3626_2...
  • i####.y####.cc####.####.cn/2018/03/30/5c241011c9ba756431fa5dacce5fbf85_1...
  • i####.y####.cc####.####.cn/2018/03/30/6b1be9b6bbba7e25549cd3ba76e8f503_1...
  • i####.y####.cc####.####.cn/2018/03/30/7c0bfea62239523729e8a4117112a50b_2...
  • i####.y####.cc####.####.cn/2018/03/30/889516efe8017afbbb701537b9c2c7e2_1...
  • i####.y####.cc####.####.cn/2018/03/30/92f0875ea8b5b5f14b59c0979652cad4_2...
  • i####.y####.cc####.####.cn/2018/03/30/9a50353b803228ce3f41bb1f3114d7e2_2...
  • i####.y####.cc####.####.cn/2018/03/30/a9f828f7739d0eb9535cb2def9c35c5d_2...
  • i####.y####.cc####.####.cn/2018/03/30/bf99071cb509e8ecbeedfbe452b849f9_2...
  • i####.y####.cc####.####.cn/2018/03/30/c223dbb620992685bdecfcb71b48f9a2_2...
  • i####.y####.cc####.####.cn/2018/03/30/cf5191b92892e996da2bb03b851163f2_1...
  • i####.y####.cc####.####.cn/2018/03/30/e05fda047c83baa660ac4d4eee379170.jpg
  • i####.y####.cc####.####.cn/2018/03/30/e87a20c9594fba4405ef44766c9f575a_2...
  • i####.y####.cc####.####.cn/2018/03/30/fc60446ff76a9bfd31105e5c50129767_1...
  • i####.y####.cc####.####.cn/2018/04/02/d96f8fe185f59ba8dc98c3a5d276e215.jpg
  • i####.y####.cc####.####.cn/2018/04/03/37b21988ac3d17d29298b16debcc862e.jpg
  • i####.y####.cc####.####.cn/2018/04/03/9a0cba431750ab34637e1d2cafab77ae.jpg
  • i####.y####.cc####.####.cn/2018/04/04/42959b020ede4cb875c10ab3e3291334.jpg
  • i####.y####.cc####.####.cn/2018/04/04/8729793c40eb7a1c97f40b2f2a33e9f4.jpg
  • i####.y####.cc####.####.cn/2018/04/05/02c14fc9833da84eeafafb2c65b29157_5...
  • i####.y####.cc####.####.cn/2018/04/05/02c27661ad0a3753d85068e3f850c6cd.jpg
  • i####.y####.cc####.####.cn/2018/04/05/102766b2c21e675a022809e9933798ef.jpg
  • i####.y####.cc####.####.cn/2018/04/05/38170efabd5ff6d56cdc053ec1eb7141.jpg
  • i####.y####.cc####.####.cn/2018/04/05/41a3dc536bf3785da75f103111404e31.jpg
  • i####.y####.cc####.####.cn/2018/04/05/4a5b3c9a392b47c8cefb2c8e6a80abd8.jpg
  • i####.y####.cc####.####.cn/2018/04/05/5c7ccd59c0d633881ab00f2dbd7262f3.jpg
  • i####.y####.cc####.####.cn/2018/04/05/613c443c01e054e284e4ff3c1981cc74.jpg
  • i####.y####.cc####.####.cn/2018/04/05/7c88bdfe1a08171d6d367cf14269287c.jpg
  • i####.y####.cc####.####.cn/2018/04/05/871e84d59a776125ea07e27330ed5e9e.jpg
  • i####.y####.cc####.####.cn/2018/04/05/8f9b5d2ff6c6ee233d0b622a67381bd2.jpg
  • i####.y####.cc####.####.cn/2018/04/05/91bb81510f19c416d705476156691c36.jpg
  • i####.y####.cc####.####.cn/2018/04/05/94ee85163c6191f916344d0b5ac72ec2.jpg
  • i####.y####.cc####.####.cn/2018/04/05/9684f51d929e82c091688d1b007cfb8d.jpg
  • i####.y####.cc####.####.cn/2018/04/05/a21ee02664d9bdd0636b56ebbb866b74.jpg
  • i####.y####.cc####.####.cn/2018/04/05/aa0a781217101742d1dbf3651ff78523.jpg
  • i####.y####.cc####.####.cn/2018/04/05/abd793ef4cd3d880424a44cff28368ec.jpg
  • i####.y####.cc####.####.cn/2018/04/05/b6780ebb7a5dc98086c4d2752d5d2f55.jpg
  • i####.y####.cc####.####.cn/2018/04/05/be436fa70e8b995ec9b3c048eb5331a5.jpg
  • i####.y####.cc####.####.cn/2018/04/05/c4ff0ad7a9989cb48ef6f297c740a4af.jpg
  • i####.y####.cc####.####.cn/2018/04/05/d29ba30b463c622c88fbb7ff37b50837.jpg
  • i####.y####.cc####.####.cn/2018/04/05/d3ef585d36b0d251ece45ad65ae3023e.jpg
  • i####.y####.cc####.####.cn/2018/04/05/e1844c1dde250000823f5b425742ee6a.jpg
  • jx####.ha####.com:9999/main/checkAppInfo.do?IMSI=####&V=####&mobile=####...
  • jx####.ha####.com:9999/main/uploadDeviceInfo.do?IMSI=####&V=####&mobile=...
  • jx####.ha####.com:9999/page/getPageContent.do?IMSI=####&V=####&imei=####...
  • jx####.ha####.com:9999/sms/submit.do?imsi=####&feechanid=####&sms=####&f...
  • jx.ha####.com/SdkNotity.aspx?i=####&v=####&c=####&av=####&dm=####&t=####...
  • m.b####.com/
  • m.b####.com/?action=####&ms=####&version=####&callback=####&r=####&sid=#...
  • m.b####.com/bdlogo/qmjgy_6179513d51c9992a9e8cb5fe7038a0ad.png
  • m.b####.com/bdlogo/qmwise_18dfd4dcf49aa9989ad4eac2444324b7.png
  • m.b####.com/se/static/img/iphone/tab_loading__bg_logo.png
  • m.b####.com/static/index/plus/public/icon_police.png
  • pay.lik####.com:7820/?igtcmd=####&gameid=####
  • pay.lik####.com:7830/openplg?appid=####&channelid=####
  • pay.lik####.com:7840/gselfc?iccid=####&price=####&imsi=####&imei=####&ap...
  • pay.lik####.com:7840/gselfpi?appid=####&channel=####
  • pos.b####.com/sync_pos.htm?cproid=####
  • pos.b####.com/sync_pos.htm?cproid=####&t=####
  • pos.b####.com/ucum?conwid=####&conhei=####&rdid=####&dc=####&di=####&dri...
  • pos.b####.com/ucum?di=####&dri=####&dis=####&dai=####&ps=####&enu=####&d...
  • pus####.to####.net/czfiles/plugindp
  • s####.ha####.com:9999/log/stat.do?i=####&v=####&c=####&av=####&dm=####&t...
  • s.c####.b####.com/s.htm?cproid=####&t=####
  • si####.jom####.com/it/u=1014260128,4274202071&fm=76
  • si####.jom####.com/it/u=1032900291,1217870125&fm=76
  • si####.jom####.com/it/u=1145801320,1185074761&fm=76
  • si####.jom####.com/it/u=1238473782,3380408131&fm=76
  • si####.jom####.com/it/u=1266901818,1571942497&fm=76
  • si####.jom####.com/it/u=1271812375,1800886581&fm=76
  • si####.jom####.com/it/u=141280030,2128901918&fm=76
  • si####.jom####.com/it/u=142807972,1612084263&fm=76
  • si####.jom####.com/it/u=1455254543,3767948233&fm=72
  • si####.jom####.com/it/u=1465472999,559006739&fm=72
  • si####.jom####.com/it/u=14856931,1316731940&fm=76
  • si####.jom####.com/it/u=149422776,1709806606&fm=76
  • si####.jom####.com/it/u=1509353045,2141455756&fm=76
  • si####.jom####.com/it/u=1516363882,992119733&fm=76
  • si####.jom####.com/it/u=1529036868,2532813979&fm=76
  • si####.jom####.com/it/u=1618113894,2025205360&fm=76
  • si####.jom####.com/it/u=1631351167,2277467734&fm=76
  • si####.jom####.com/it/u=1679769638,2107798621&fm=76
  • si####.jom####.com/it/u=169307292,2100741207&fm=76
  • si####.jom####.com/it/u=1704559318,2640183734&fm=76
  • si####.jom####.com/it/u=1737862050,2793596382&fm=76
  • si####.jom####.com/it/u=1923903031,2800632518&fm=76
  • si####.jom####.com/it/u=1930688815,2328993146&fm=76
  • si####.jom####.com/it/u=1979261942,2618700678&fm=76
  • si####.jom####.com/it/u=2014683734,2249451056&fm=76
  • si####.jom####.com/it/u=2323666498,1393217187&fm=76
  • si####.jom####.com/it/u=238347009,768213251&fm=76
  • si####.jom####.com/it/u=2727531841,3215966691&fm=76
  • si####.jom####.com/it/u=2836050815,719608802&fm=72
  • si####.jom####.com/it/u=2853537058,1203804266&fm=76
  • si####.jom####.com/it/u=2936737713,2874521693&fm=76
  • si####.jom####.com/it/u=293861890,4137998022&fm=76
  • si####.jom####.com/it/u=3019896137,309398461&fm=76
  • si####.jom####.com/it/u=3125407249,2754445183&fm=76
  • si####.jom####.com/it/u=313897942,2092942122&fm=76
  • si####.jom####.com/it/u=318374857,3929161983&fm=76
  • si####.jom####.com/it/u=3273166152,3669273582&fm=76
  • si####.jom####.com/it/u=3305470135,204473189&fm=72
  • si####.jom####.com/it/u=3325708883,3447449742&fm=72
  • si####.jom####.com/it/u=3335963470,2980791554&fm=76
  • si####.jom####.com/it/u=3488686093,4212017451&fm=76
  • si####.jom####.com/it/u=3523049830,57637029&fm=76
  • si####.jom####.com/it/u=358217677,2041524938&fm=76
  • si####.jom####.com/it/u=3712825453,692518663&fm=76
  • si####.jom####.com/it/u=3742576461,667660528&fm=76
  • si####.jom####.com/it/u=3843156552,393794034&fm=76
  • si####.jom####.com/it/u=392755225,3177156847&fm=76
  • si####.jom####.com/it/u=4111294463,800650790&fm=76
  • si####.jom####.com/it/u=4118240130,1757104600&fm=76
  • si####.jom####.com/it/u=4205540018,301274603&fm=76
  • si####.jom####.com/it/u=4217225789,1351466848&fm=76
  • si####.jom####.com/it/u=4230538281,4276484403&fm=76
  • si####.jom####.com/it/u=479632626,2202661393&fm=76
  • si####.jom####.com/it/u=504771841,3107578222&fm=76
  • si####.jom####.com/it/u=539282721,1894900225&fm=76
  • si####.jom####.com/it/u=63668761,3765968540&fm=76
  • si####.jom####.com/it/u=74015320,1762226157&fm=76
  • si####.jom####.com/it/u=754424741,1456601020&fm=76
  • si####.jom####.com/it/u=835083876,4174223895&fm=76
  • si####.jom####.com/it/u=902205862,2763371060&fm=76
  • si####.jom####.com/it/u=930603290,4001058994&fm=76
  • si####.jom####.com/it/u=933289105,65835159&fm=76
  • si####.jom####.com/it/u=948154899,483532071&fm=72
  • supermo####.jom####.com/static/wiseindex/iconfont/iconfont_2681c2d.ttf
  • supermo####.jom####.com/static/wiseindex/img/ns_diff_color_v3_991d8b3.png
  • t####.y####.com/tj_tool.js?ref=####&title=####
  • t.y####.com.####.com/
  • t.y####.com.####.com/119/b1.jpg
  • t.y####.com.####.com/119/back.png
  • t.y####.com.####.com/119/bqt.png
  • t.y####.com.####.com/119/fengxiang.png
  • t.y####.com.####.com/119/loadnews.gif
  • t.y####.com.####.com/119/logo.png
  • t.y####.com.####.com/119/logo_h5view.png
  • t.y####.com.####.com/119/next.jpg
  • t.y####.com.####.com/119/pindao.png
  • t.y####.com.####.com/119/prev.jpg
  • t.y####.com.####.com/119/share.jpg
  • t.y####.com.####.com/119/wb.jpg
  • t.y####.com.####.com/119/wx.jpg
  • t.y####.com.####.com/122/ad_footer_ynet.js
  • t.y####.com.####.com/122/ad_middle_ynet.js
  • t.y####.com.####.com/122/ad_top_ynet.js
  • t.y####.com.####.com/122/app_ynet.js
  • t.y####.com.####.com/122/h5app.js
  • t.y####.com.####.com/122/h5public.js
  • t.y####.com.####.com/122/iscroll.js
  • t.y####.com.####.com/122/jquery.min.js
  • t.y####.com.####.com/122/navbarscroll.js
  • t.y####.com.####.com/122/public_ynet.js
  • t.y####.com.####.com/20/down_paper.png
  • t.y####.com.####.com/20/gban.png
  • t.y####.com.####.com/20/share_close.png
  • t.y####.com.####.com/20/share_logo.png
  • t.y####.com.####.com/20/share_success.png
  • t.y####.com.####.com/37/articleStyle.css
  • t.y####.com.####.com/37/h5N.css
  • t.y####.com.####.com/37/h5_home.css
  • t.y####.com.####.com/37/header_new_h5.css
  • t.y####.com.####.com/37/weixin.css
  • t.y####.com.####.com/40/baiduTj.js
  • t.y####.com.####.com/40/global.js
  • t.y####.com.####.com/40/h5home.js
  • t.y####.com.####.com/40/h5rdzj.js
  • t.y####.com.####.com/40/recommend-popup.js
  • t.y####.com.####.com/40/tj.js
  • t.y####.com.####.com/40/touch_scale_image.js
  • t.y####.com.####.com/40/wechat-1.0.js
  • t.y####.com.####.com/YnetView/jhtj.json
  • t.y####.com.####.com/YnetView/rttj.json
  • t.y####.com.####.com/h5/kuaixun.json?timeStamp=####
  • t.y####.com.####.com/js/jweixin-1.2.0.js
  • wn.pos.b####.com/adx.php?c=####
  • x####.ha####.com/getconfig.aspx
  • x####.ha####.com/getjar.aspx?pno=####
  • x####.ha####.com/versioncheck.aspx
HTTP POST requests:
  • pay.lik####.com:7820/
Modified file system:
Creates the following files:
  • /data/data/####/57CSXG4AkRf8mBYZ.zip
  • /data/data/####/64525f51-5ecc-4be8-8c29-9a8b0332f20e.zip
  • /data/data/####/67FrdcF4gl2hImERCnpAug==.new
  • /data/data/####/6e448dd2-d724-4595-a622-3d5b9054ff51.zip
  • /data/data/####/74810aca28597c3c5b2402c6689e5e91.apk
  • /data/data/####/DATA_DB-journal
  • /data/data/####/KooVrmclnZxDD3BodBEzDw==.new
  • /data/data/####/LGXEUljdGWi27Y-ctaxaHg==
  • /data/data/####/Signature_0.key
  • /data/data/####/a0c175d0.apk
  • /data/data/####/appStatus.xml
  • /data/data/####/base-1.apk
  • /data/data/####/base-1.dex
  • /data/data/####/base-1.dex (deleted)
  • /data/data/####/config.xml
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/dbinfo.xml
  • /data/data/####/done
  • /data/data/####/dp.apk
  • /data/data/####/eOaNAKS7ZFL-EL5m7K1DVQ==
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/f_000003
  • /data/data/####/f_000004
  • /data/data/####/f_000005
  • /data/data/####/f_000006
  • /data/data/####/f_000007
  • /data/data/####/f_000008
  • /data/data/####/f_000009
  • /data/data/####/f_00000a
  • /data/data/####/f_00000b
  • /data/data/####/f_00000c
  • /data/data/####/f_00000d
  • /data/data/####/f_00000e
  • /data/data/####/f_00000f
  • /data/data/####/f_000010
  • /data/data/####/f_000011
  • /data/data/####/f_000012
  • /data/data/####/f_000013
  • /data/data/####/f_000014
  • /data/data/####/f_000015
  • /data/data/####/f_000016
  • /data/data/####/f_000017
  • /data/data/####/f_000018
  • /data/data/####/f_000019
  • /data/data/####/f_00001a
  • /data/data/####/f_00001b
  • /data/data/####/f_00001c
  • /data/data/####/f_00001d
  • /data/data/####/f_00001e
  • /data/data/####/f_00001f
  • /data/data/####/f_000020
  • /data/data/####/f_000021
  • /data/data/####/f_000022
  • /data/data/####/f_000023
  • /data/data/####/f_000024
  • /data/data/####/f_000025
  • /data/data/####/f_000026
  • /data/data/####/f_000027
  • /data/data/####/f_000028
  • /data/data/####/f_000029
  • /data/data/####/f_00002a
  • /data/data/####/f_00002b
  • /data/data/####/f_00002c
  • /data/data/####/f_00002d
  • /data/data/####/f_00002e
  • /data/data/####/f_00002f
  • /data/data/####/f_000030
  • /data/data/####/f_000031
  • /data/data/####/f_000032
  • /data/data/####/f_000033
  • /data/data/####/f_000034
  • /data/data/####/f_000035
  • /data/data/####/f_000036
  • /data/data/####/f_000037
  • /data/data/####/f_000038
  • /data/data/####/f_000039
  • /data/data/####/f_00003a
  • /data/data/####/f_00003b
  • /data/data/####/f_00003c
  • /data/data/####/f_00003d
  • /data/data/####/f_00003e
  • /data/data/####/f_00003f
  • /data/data/####/f_000040
  • /data/data/####/f_000041
  • /data/data/####/f_000042
  • /data/data/####/f_000043
  • /data/data/####/f_000044
  • /data/data/####/f_000045
  • /data/data/####/f_000046
  • /data/data/####/f_000047
  • /data/data/####/f_000048
  • /data/data/####/f_000049
  • /data/data/####/f_00004a
  • /data/data/####/f_00004b
  • /data/data/####/f_00004c
  • /data/data/####/f_00004d
  • /data/data/####/f_00004e
  • /data/data/####/f_00004f
  • /data/data/####/f_000050
  • /data/data/####/f_000051
  • /data/data/####/f_000052
  • /data/data/####/f_000053
  • /data/data/####/f_000054
  • /data/data/####/f_000055
  • /data/data/####/f_000056
  • /data/data/####/f_000057
  • /data/data/####/f_000058
  • /data/data/####/f_000059
  • /data/data/####/f_00005a
  • /data/data/####/f_00005b
  • /data/data/####/f_00005c
  • /data/data/####/f_00005d
  • /data/data/####/heajva_f.zip
  • /data/data/####/index
  • /data/data/####/libcocos2dcpp.so
  • /data/data/####/libcrypt_sign.so
  • /data/data/####/libgoldcoast.so
  • /data/data/####/libkjOnlinePay.so
  • /data/data/####/n2-lXTPq9At8Dxrw
  • /data/data/####/net.tt.plugin.damai (deleted)
  • /data/data/####/net.tt.plugin.damai.apk
  • /data/data/####/net.tt.plugin.miwan (deleted)
  • /data/data/####/net.tt.plugin.miwan.apk
  • /data/data/####/net.tt.plugin.myadv (deleted)
  • /data/data/####/net.tt.plugin.myadv.apk
  • /data/data/####/net.tt.plugin.mysdk (deleted)
  • /data/data/####/net.tt.plugin.mysdk.apk
  • /data/data/####/net.tt.plugin.qipa (deleted)
  • /data/data/####/net.tt.plugin.qipa.apk
  • /data/data/####/net.tt.plugin.shangan (deleted)
  • /data/data/####/net.tt.plugin.shangan.apk
  • /data/data/####/net.tt.plugin.taiku (deleted)
  • /data/data/####/net.tt.plugin.taiku.apk
  • /data/data/####/net.tt.plugin.utadv (deleted)
  • /data/data/####/net.tt.plugin.utadv.apk
  • /data/data/####/net.tt.plugin.yufeng (deleted)
  • /data/data/####/net.tt.plugin.yufeng.apk
  • /data/data/####/net.tt.plugin.zhongzhi (deleted)
  • /data/data/####/net.tt.plugin.zhongzhi.apk
  • /data/data/####/plugin.jar
  • /data/data/####/rdata_comwjkziukz.new
  • /data/data/####/runtimeConfig.xml
  • /data/data/####/smsJx_v4_2.xml
  • /data/data/####/tmp.KI2083
  • /data/data/####/tmp.Pk2083
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/wochi_v4.db-journal
  • /data/media/####/.config
Miscellaneous:
Executes next shell scripts:
  • /system/bin/netcfg
  • chmod -R 755 <Package Folder>/Plugin
  • ls -l /system/bin/su
Loads the following dynamic libraries:
  • byndkhrj
  • jmqfwnlp
Uses the following algorithms to encrypt data:
  • DES-ECB-NoPadding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
  • DESede
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Displays its own windows over windows of other applications.
Parses information from SMS messages.
Gains access to information about sent/received SMS messages.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android