Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.Packed.39719

Added to the Dr.Web virus database: 2018-09-21

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.DownLoader.570.origin
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) cn-bj-m####.ufi####.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) j####.a####.com.####.com:80
  • TCP(HTTP/1.1) idu####.qini####.com:80
  • TCP(HTTP/1.1) as.ju####.com:80
  • TCP(HTTP/1.1) api.er####.com:80
  • TCP(HTTP/1.1) www.hao####.top:80
  • TCP(TLS/1.0) av1.x####.com:443
  • TCP(TLS/1.0) regi####.xm####.xi####.com:443
  • TCP v.m####.com:7701
  • TCP v.m####.com:7702
DNS requests:
  • a####.er####.com
  • and####.b####.qq.com
  • api.er####.com
  • as.ju####.com
  • av1.x####.com
  • ergedd-####.c####.ufi####.com
  • i.t####.com
  • img####.er####.com
  • j####.a####.com
  • regi####.xm####.xi####.com
  • v.m####.com
  • www.h####.online
  • www.hao####.top
HTTP GET requests:
  • api.er####.com/api/v1/album_categories/4/albums?channel=####&offset=####...
  • api.er####.com/api/v1/album_categories?channel=####&offset=####&limit=##...
  • api.er####.com/api/v1/albums/33
  • api.er####.com/api/v1/albums/33/videos?channel=####&offset=####&limit=####
  • api.er####.com/api/v1/albums/home_recommended?channel=####&offset=####&l...
  • api.er####.com/api/v1/app_configs?types=####
  • api.er####.com/api/v1/audio_categories/1/playlists?channel=####&offset=#...
  • api.er####.com/api/v1/audio_categories?channel=####
  • api.er####.com/api/v1/audio_playlists/excellent?channel=####
  • api.er####.com/api/v1/home_items?type=####&channel=####&offset=####&limi...
  • api.er####.com/api/v1/magnets
  • as.ju####.com/as?m=####&v=####&av=####&ch=####&k=####&pkg=####&action=##...
  • as.ju####.com/as?m=####&v=####&k=####&c=####&pkg=####&json=####
  • cn-bj-m####.ufi####.com/ad2_test.json
  • idu####.qini####.com/admin/promotion/16637780581_1496917594014.png?image...
  • idu####.qini####.com/admin/promotion/25378914878_1521510270505.png?image...
  • idu####.qini####.com/admin/promotion/29685805033_1501747602660.png?image...
  • idu####.qini####.com/admin/promotion/35759371598_1494378317053.jpg?image...
  • idu####.qini####.com/admin/promotion/36688080337_1493808597896.jpg?image...
  • idu####.qini####.com/admin/promotion/92290537011_1493808527428.jpg?image...
  • idu####.qini####.com/album/10_1492578783440.png?imageVi####
  • idu####.qini####.com/album/175_1506333512989.png?imageVi####
  • idu####.qini####.com/album/175_20170414114454_jj9q.jpg?imageVi####
  • idu####.qini####.com/album/225_1506045647794.png?imageVi####
  • idu####.qini####.com/album/232_1496835163183.jpg?imageVi####
  • idu####.qini####.com/album/233_1496835226736.jpg?imageVi####
  • idu####.qini####.com/album/24_1492578803640.png?imageVi####
  • idu####.qini####.com/album/28_1492578758731.png?imageVi####
  • idu####.qini####.com/album/29_20170414114416_wkcm.jpg?imageVi####
  • idu####.qini####.com/album/33_1493977102106.png?imageVi####
  • idu####.qini####.com/album/33_1500456911360.png?imageVi####
  • idu####.qini####.com/album/375_1506045623572.png?imageVi####
  • idu####.qini####.com/album/398_1524895210589.png?imageVi####
  • idu####.qini####.com/album/532_1537497054130.jpg?imageVi####
  • idu####.qini####.com/album/7519106771_1537445376716.jpg?imageVi####
  • idu####.qini####.com/audio_playlist/13711963478_1493868665752.jpg?imageV...
  • idu####.qini####.com/audio_playlist/16701174224_1493809754226.jpg?imageV...
  • idu####.qini####.com/audio_playlist/32676900831_1495419112739.png?imageV...
  • idu####.qini####.com/audio_playlist/41000576111_1493881448109.jpg?imageV...
  • idu####.qini####.com/audio_playlist/45978963753_1493809269607.jpg?imageV...
  • idu####.qini####.com/audio_playlist/4999061041_1493868643040.jpg?imageVi...
  • idu####.qini####.com/audio_playlist/50703415533_1493811206063.jpg?imageV...
  • idu####.qini####.com/audio_playlist/55204008224_1495519153175.png?imageV...
  • idu####.qini####.com/audio_playlist/60846442240_1493809357744.jpg?imageV...
  • idu####.qini####.com/audio_playlist/66562931040_1493868622457.jpg?imageV...
  • idu####.qini####.com/audio_playlist/7031319402_1495518998898.png?imageVi...
  • idu####.qini####.com/audio_playlist/72349241275_1493809307637.jpg?imageV...
  • idu####.qini####.com/audio_playlist/78941936855_1493809723252.jpg?imageV...
  • idu####.qini####.com/audio_playlist/88872158933_1493809852104.jpg?imageV...
  • idu####.qini####.com/audio_playlist/91214627592_1493885676444.png?imageV...
  • idu####.qini####.com/audio_playlist/9204811878_1493885423812.jpg?imageVi...
  • idu####.qini####.com/audio_playlist/93286566976_1493811151557.jpg?imageV...
  • idu####.qini####.com/audio_playlist/98792568364_1493809977390.jpg?imageV...
  • idu####.qini####.com/slide/10407896160_1493801623909.png?imageVi####
  • idu####.qini####.com/slide/40403107807_1493797230459.png?imageVi####
  • idu####.qini####.com/slide/54446175068_1493797199844.png?imageVi####
  • idu####.qini####.com/video/10091_20170413122531_hjxk.jpg?imageVi####
  • idu####.qini####.com/video/11777_1508303319421.png?imageVi####
  • idu####.qini####.com/video/15011_1500878340555.png?imageVi####
  • idu####.qini####.com/video/15096_1501217331767.png?imageVi####
  • idu####.qini####.com/video/18745_1528860887570.jpg?imageVi####
  • idu####.qini####.com/video/2653_20170413120729_qp5r.png?imageVi####
  • idu####.qini####.com/video/3194_20170413120901_eqxh.jpg?imageVi####
  • idu####.qini####.com/video/3211_20170413120904_nru9.jpg?imageVi####
  • idu####.qini####.com/video/40_1495179422720.jpg?imageVi####
  • idu####.qini####.com/video/4562_1510023121479.png?imageVi####
  • idu####.qini####.com/video/4617_1508297636493.png?imageVi####
  • idu####.qini####.com/video/6361_1495179605129.jpg?imageVi####
  • idu####.qini####.com/video/9848_20170413122441_4mxu.jpg?imageVi####
  • idu####.qini####.com/video/9849_20170413122441_maqc.jpg?imageVi####
  • idu####.qini####.com/video/9850_20170413122441_unu0.jpg?imageVi####
  • idu####.qini####.com/video/9851_20170413122442_lk7r.jpg?imageVi####
  • idu####.qini####.com/video/9852_20170413122442_xhht.jpg?imageVi####
  • idu####.qini####.com/video/9966_20170413122505_p455.jpg?imageVi####
  • idu####.qini####.com/video/9967_20170413122505_vjra.jpg?imageVi####
  • idu####.qini####.com/video/9968_20170413122505_ggkt.jpg?imageVi####
  • idu####.qini####.com/videos/10482_20171114162642.jpg?imageVi####
  • idu####.qini####.com/videos/11234_20170425171923.jpg?imageVi####
  • idu####.qini####.com/videos/19143_20180807191642.jpg?imageVi####
  • idu####.qini####.com/videos/19225_20180813162513.jpg?imageVi####
  • j####.a####.com.####.com/lib/hbs0911-971d82b2eb5b5e50477bd77f262aa767.jar
  • www.hao####.top/MP_QD_001_md5.txt
  • www.hao####.top/MP_QD_001_real.jar
HTTP POST requests:
  • and####.b####.qq.com/rqd/async?aid=####
  • api.er####.com/getRefererKey
Modified file system:
Creates the following files:
  • /data/data/####/000.xml
  • /data/data/####/02e5a9e15ea994c63eb302ca991ee55235b3ec93a30aa40....0.tmp
  • /data/data/####/0abcdb0916b7c4ba953b2497502b40b1c7aa6365ab25b33....0.tmp
  • /data/data/####/0bab0c07f943d4cb830f50b8bdc62f11c65f83dc3e34d90....0.tmp
  • /data/data/####/0cfb24a269f36ca13b8f923ed492f6a1545aa9db5200c89....0.tmp
  • /data/data/####/1004
  • /data/data/####/13acae557f4ba43eb1ed40e7fa554cab9cdb2ef6ff78477....0.tmp
  • /data/data/####/1537526591391_2264
  • /data/data/####/1537526591421_2264
  • /data/data/####/1537526591444_2264
  • /data/data/####/1537526591554_2264
  • /data/data/####/1537526591815_2330
  • /data/data/####/1537526591838_2330
  • /data/data/####/1537526592096_2264
  • /data/data/####/1537526592196_2330
  • /data/data/####/1537526593525_2264
  • /data/data/####/1537526594134_2264
  • /data/data/####/1537526594195_2264
  • /data/data/####/1537526594195_2264 (deleted)
  • /data/data/####/1537526594301_2264
  • /data/data/####/1537526594301_2264 (deleted)
  • /data/data/####/1537526595209_2264
  • /data/data/####/1537526595209_2264 (deleted)
  • /data/data/####/1537526595633_2264
  • /data/data/####/1537526595633_2264 (deleted)
  • /data/data/####/1537526595656_2264
  • /data/data/####/1537526595656_2264 (deleted)
  • /data/data/####/1537526595679_2264
  • /data/data/####/1537526595679_2264 (deleted)
  • /data/data/####/1537526597140_2330
  • /data/data/####/1537526597446_2264
  • /data/data/####/1537526597876_2264
  • /data/data/####/1537526598190_2264
  • /data/data/####/1537526598464_2264
  • /data/data/####/1537526598489_2264
  • /data/data/####/1537526598502_2264
  • /data/data/####/1537526598550_2264
  • /data/data/####/1537526598560_2264
  • /data/data/####/1537526598586_2264
  • /data/data/####/1537526598603_2264
  • /data/data/####/1537526598672_2264
  • /data/data/####/1537526598689_2264
  • /data/data/####/1537526599065_2264
  • /data/data/####/1537526625169_2264
  • /data/data/####/1537526625204_2264
  • /data/data/####/1537526625297_2264
  • /data/data/####/1537526625630_2264
  • /data/data/####/1537526625645_2264
  • /data/data/####/1537526625656_2264
  • /data/data/####/1537526627247_2264
  • /data/data/####/1537526637499_2264
  • /data/data/####/1537526637889_2264
  • /data/data/####/1537526638517_2264
  • /data/data/####/1537526638571_2264
  • /data/data/####/1537526638623_2264
  • /data/data/####/1537526638666_2264
  • /data/data/####/1537526638705_2264
  • /data/data/####/1537526638726_2264
  • /data/data/####/1537526638918_2264
  • /data/data/####/1537526638937_2264
  • /data/data/####/1537526639006_2264
  • /data/data/####/1537526639061_2264
  • /data/data/####/1537526639104_2264
  • /data/data/####/1537526639314_2264
  • /data/data/####/1537526639334_2264
  • /data/data/####/1537526639412_2264
  • /data/data/####/1537526639495_2264
  • /data/data/####/1537526639683_2264
  • /data/data/####/1537526639927_2264
  • /data/data/####/1537526640037_2264
  • /data/data/####/1537526640072_2264
  • /data/data/####/1537526640108_2264
  • /data/data/####/1537526640229_2264
  • /data/data/####/1537526640345_2264
  • /data/data/####/1537526640709_2264
  • /data/data/####/1537526640750_2264
  • /data/data/####/1537526640809_2264
  • /data/data/####/1537526643744_2264
  • /data/data/####/1537526643774_2264
  • /data/data/####/1537526643796_2264
  • /data/data/####/1537526643814_2264
  • /data/data/####/1537526643832_2264
  • /data/data/####/1537526648246_2264
  • /data/data/####/179d0f7254b95934ab20d34f5ea5a2ef4728c6401b9b59e....0.tmp
  • /data/data/####/1c34c865ff3225f5eadcda22ffe205f7.0.tmp
  • /data/data/####/1c34c865ff3225f5eadcda22ffe205f7.1.tmp
  • /data/data/####/1d1c36217dabb56f7b6ea36ae12dbf640e23eaf6c000d4a....0.tmp
  • /data/data/####/2151f26516c1285d32477900bace42c4.0.tmp
  • /data/data/####/2151f26516c1285d32477900bace42c4.1.tmp
  • /data/data/####/221674d5a14501c6e354e4a3dc82aed68c6182b58b4f5a0....0.tmp
  • /data/data/####/23.xml
  • /data/data/####/23356507059351895.xml
  • /data/data/####/23356507059351895.xml.bak
  • /data/data/####/24356507059351895.xml
  • /data/data/####/248cef7be0265b3a10a33d6e1dad3f538fce163c34151d8....0.tmp
  • /data/data/####/25356507059351895.xml
  • /data/data/####/28ebf8d678cce90b5dd768a59960ca7e4e6c20ff6192cbb....0.tmp
  • /data/data/####/29a4bfc0dd244d3e5e8c132b5a964c19c1fb3be1cb5880a....0.tmp
  • /data/data/####/2f0d9a44c4e40c0f9930dbcca8b595d5.0.tmp
  • /data/data/####/2f0d9a44c4e40c0f9930dbcca8b595d5.1.tmp
  • /data/data/####/306abf48fdaa7825f4a9cc7965ed8de8d5d5a46efefca31....0.tmp
  • /data/data/####/3b4675e2e25110cefefdea8cda9a1b723e40feff69f5e9f....0.tmp
  • /data/data/####/3ef25a24395e832e8c9077a1f18bec0f9c4e3da690040c8....0.tmp
  • /data/data/####/3ef9f3eb6025bad78aadb2750399786b3c4214f240bd24e....0.tmp
  • /data/data/####/41e8d09c1e80f1b1a3efd0fe56110936a6634b3c62dc65d....0.tmp
  • /data/data/####/42971d365f26b93152b214f37065955dedd817b85123998....0.tmp
  • /data/data/####/44828b56d2f1c57f9c3aeed435951ffd66de705bbc2ae79....0.tmp
  • /data/data/####/45c0ea65cdd5007b3904ac70e5fd211fd4d536b7058a89d....0.tmp
  • /data/data/####/45f9eef9c6a0560d6ec3ca3e785b8e6d2db2e8ed72ba43d....0.tmp
  • /data/data/####/4ba107de3535890f6bfceb8b9c44ce807aa081d907f74d1....0.tmp
  • /data/data/####/4e2611f1f283acc0e92d5f24637ae797a5d239badaf08d6....0.tmp
  • /data/data/####/4e73333e8cf5ff9305c69ffd194674b08b8e0180597de9d....0.tmp
  • /data/data/####/4f45d202cc52038cb52c9725f0a2f68a3df7a12ec7f2712....0.tmp
  • /data/data/####/5464bfd6c15de00cb823ef8cedb09834.0.tmp
  • /data/data/####/5464bfd6c15de00cb823ef8cedb09834.1.tmp
  • /data/data/####/56a408ac31cc63070d3758951935bda2af0b1d0e3b44019....0.tmp
  • /data/data/####/58f4595c960590f6ef7403e070ebb890.0.tmp
  • /data/data/####/58f4595c960590f6ef7403e070ebb890.1.tmp
  • /data/data/####/59a6b8e94da93c2826c679388afb4307.0.tmp
  • /data/data/####/59a6b8e94da93c2826c679388afb4307.1.tmp
  • /data/data/####/5f19ec349328efd517c7468ae4a57cb88d29fd62af5161b....0.tmp
  • /data/data/####/604f8de853a91c4fab579c1a78e69bb6.0.tmp
  • /data/data/####/604f8de853a91c4fab579c1a78e69bb6.1.tmp
  • /data/data/####/61e90e18cc1df4ba869548b60a4cc3547f8513e353041e9....0.tmp
  • /data/data/####/63cfed14c2feef9c99c093ed765674733e0685389e9ae16....0.tmp
  • /data/data/####/662e17173a8899382256ea2a6a0857749a559b4bf0cd045....0.tmp
  • /data/data/####/6788b0adc0841dbecc3ac681456832c6b758a24e01b4e9d....0.tmp
  • /data/data/####/6baf7c4649a15c4eb77c57524f87242f10120282014d604....0.tmp
  • /data/data/####/6cad589bb7214b41dc1621e926e9ee14831628abddb4048....0.tmp
  • /data/data/####/6e5b881fbb210a19090158b32b2d031c57e3484c8d13dc9....0.tmp
  • /data/data/####/724956620743daaa2bd575f18a23aaa15421688e94539b7....0.tmp
  • /data/data/####/72d95b13a990daf60af723f9868fc6ce9bbd413d5c95ce3....0.tmp
  • /data/data/####/7b145f8bbc19f2eea0a9b1118ccb0a8a.0.tmp
  • /data/data/####/7b145f8bbc19f2eea0a9b1118ccb0a8a.1.tmp
  • /data/data/####/7f5ec0e3076e93e3951f5bb5327af555f465585ea2faafa....0.tmp
  • /data/data/####/856909.jar
  • /data/data/####/859f08b275d0292ef3dd191e7cdfaefb.0.tmp
  • /data/data/####/859f08b275d0292ef3dd191e7cdfaefb.1.tmp
  • /data/data/####/875c74441d400c4db8bb3f766deaeae815b914a39076b88....0.tmp
  • /data/data/####/8973870ac4036f8c1a856e2bf300def901068c4c9bb8afa....0.tmp
  • /data/data/####/8c60fcd972fc705ac26f7189ccd1a53cb906038d45288bb....0.tmp
  • /data/data/####/90ac5cca2b458c1321d2b4d97638d5da6fd3587c71510f4....0.tmp
  • /data/data/####/92a624a918049f6c12b3ab188ec5aca129510700ab7a03d....0.tmp
  • /data/data/####/9949ba98e3de6febe5d6764d21ebff240310630830ae41e....0.tmp
  • /data/data/####/9b2a70c7ac9835e38299d39c4bf601de0b6f2e92c8f4057....0.tmp
  • /data/data/####/9e3118ab38542b55630c41e97f8b4eaf.0.tmp
  • /data/data/####/9e3118ab38542b55630c41e97f8b4eaf.1.tmp
  • /data/data/####/9e640d2e0d441443375f21e7e3258e5329e5031a1050bc1....0.tmp
  • /data/data/####/9e70435b76d83725d1fc77b4beb44d66674d7120bd72ccc....0.tmp
  • /data/data/####/Hawk2.xml
  • /data/data/####/MultiDex.lock
  • /data/data/####/TD_app_pefercen_profile.xml
  • /data/data/####/TDpref_longtime.xml
  • /data/data/####/TDpref_longtime0.xml
  • /data/data/####/TDpref_shorttime.xml
  • /data/data/####/TDpref_shorttime0.xml
  • /data/data/####/YMMsg.db-journal
  • /data/data/####/a00417c71464f8fc49767c4f77567310fb6cd8b02475b7c....0.tmp
  • /data/data/####/a74f23d31227574f8bc8242e2ed815a18f46649d3a99260....0.tmp
  • /data/data/####/a75fe4e6e6802d3a1fc64577c019d71c7ff1fee3643d665....0.tmp
  • /data/data/####/af30ec51ff6a1b7e42812d34ea491b85c310b933c4075a9....0.tmp
  • /data/data/####/awaken.xml
  • /data/data/####/b1e574db281678f6f7a4807b20d93a79f2c332c544df1d7....0.tmp
  • /data/data/####/b4b2317c768265f9af07c3374b177909.0.tmp
  • /data/data/####/b4b2317c768265f9af07c3374b177909.1.tmp
  • /data/data/####/b68f02707a31537cf2b2474677a6784532db42d7b91eee6....0.tmp
  • /data/data/####/b818812ce117aa2ef6857d0c62adc9ab.0.tmp
  • /data/data/####/b818812ce117aa2ef6857d0c62adc9ab.1.tmp
  • /data/data/####/b8995f88de9d34b075271672d0ad0891d40c095e6e250bd....0.tmp
  • /data/data/####/babysong-database.db-journal
  • /data/data/####/bugly_db_-journal
  • /data/data/####/c9fbdd3514b185c2f23b8cfe8c98cf39158078483d9dbb8....0.tmp
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/cc20832dd1459e1897a64cc8d75415a6517482071c63fe8....0.tmp
  • /data/data/####/cea8d4c09760879083c10113f7441692.0.tmp
  • /data/data/####/cea8d4c09760879083c10113f7441692.1.tmp
  • /data/data/####/com.isrsx.bbvideos_preferences.xml
  • /data/data/####/crashrecord.xml
  • /data/data/####/d0c4346ba291618c86d21ddfd4ea02b462a4460f040433f....0.tmp
  • /data/data/####/d2e4fc65d8a6538d3dbcad3ef265ab81049e1d3fdc3cae6....0.tmp
  • /data/data/####/d47a0303882806e6e8a53792bb1e96824dd0754620d1dd5....0.tmp
  • /data/data/####/d4d1ac3f47f46cea0f6423500ff9559918c69895ec66119....0.tmp
  • /data/data/####/d755ee998bb8f05c3cddd9e83ff9443489b93f41cbb7a2e....0.tmp
  • /data/data/####/d79c9ba233b34e5295a43a3f51a07b2d8ba99381f92ae5d....0.tmp
  • /data/data/####/da0154b4a69fded5b37a544cf50e77f9f689c3e2511b931....0.tmp
  • /data/data/####/db49747946f783e821f8fcf7202074dfad12abcf166a603....0.tmp
  • /data/data/####/dbf5603cce63a30fe610ba3fedbd1223.0.tmp
  • /data/data/####/dbf5603cce63a30fe610ba3fedbd1223.1.tmp
  • /data/data/####/dd6b274be990186e6d67af8fbad8d7ed0d6a627009ee1f6....0.tmp
  • /data/data/####/e1e16707df6e2e9069b1cecdbe1af2e7ecb7f750de9e303....0.tmp
  • /data/data/####/e8c799dbabe68e733da2f645a51fbcea5980fd889f755b1....0.tmp
  • /data/data/####/ecedf07a775578bb143430c4f4776ba7f1ab583f1e27a48....0.tmp
  • /data/data/####/f3bf8380cba4cd1aee6e2e7657b41374c71c85c6a44b35d....0.tmp
  • /data/data/####/f6ba600271e18b05f5b0ce9671d55e503ca8eed8b256842....0.tmp
  • /data/data/####/f7d4e841f32b9ec45740bd5cefed877cbf09739b85dfd01....0.tmp
  • /data/data/####/fb3c9d4a9b3ec16e2b01b4e59637719c.0.tmp
  • /data/data/####/fb3c9d4a9b3ec16e2b01b4e59637719c.1.tmp
  • /data/data/####/fdc5032161e162ed192393886c03568a.0.tmp
  • /data/data/####/fdc5032161e162ed192393886c03568a.1.tmp
  • /data/data/####/feb012c5557b146c1502a3a237939153f015d4acd990574....0.tmp
  • /data/data/####/geofencing.db
  • /data/data/####/geofencing.db-journal
  • /data/data/####/hbs0911-971d82b2eb5b5e50477bd77f262aa767.jar
  • /data/data/####/idremao.app.xml
  • /data/data/####/idremao.user.xml
  • /data/data/####/journal.tmp
  • /data/data/####/local_crash_lock
  • /data/data/####/mipush.xml
  • /data/data/####/mipush_extra.xml
  • /data/data/####/mipush_region
  • /data/data/####/mipush_region.lock
  • /data/data/####/mobclick_agent_cached_com.isrsx.bbvideos20504
  • /data/data/####/multidex.version.xml
  • /data/data/####/native_record_lock
  • /data/data/####/security_info
  • /data/data/####/tdid.xml
  • /data/data/####/tiny_data.data
  • /data/data/####/tiny_data.lock
  • /data/data/####/tmp-com.isrsx.bbvideos-1.apk.classes-729793463.zip
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/y08.jar
  • /data/media/####/.nomedia
  • /data/media/####/.tcookieid
  • /data/media/####/MP_QD_001_real.jar
Miscellaneous:
Executes next shell scripts:
  • /system/bin/sh -c getprop
  • /system/bin/sh -c type su
  • getprop
Loads the following dynamic libraries:
  • 0oijhy7nvcderty
  • Bugly
  • ijkffmpeg
  • ijkplayer
  • ijksdl
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-GCM-NoPadding
  • DES-CBC-PKCS5Padding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
  • AES-GCM-NoPadding
  • DES-CBC-PKCS5Padding
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about APN settings.
Gains access to information about installed applications.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android