Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.Packed.46650

Added to the Dr.Web virus database: 2019-08-18

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.DownLoader.861.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) i####.b####.3g.cn:80
  • TCP(HTTP/1.1) ggboo####.3g.cn:80
  • TCP(HTTP/1.1) fre####.b####.3g.cn:80
  • TCP(HTTP/1.1) cgi.con####.qq.com:80
  • TCP(HTTP/1.1) u####.3g.cn:80
  • TCP(TLS/1.0) ot####.x2.tc.####.com:443
DNS requests:
  • a####.u####.com
  • and####.b####.qq.com
  • cgi.con####.qq.com
  • fre####.b####.3g.cn
  • fre####.gg####.cn
  • ggboo####.3g.cn
  • i####.b####.3g.cn
  • s.b####.g####.com
  • u####.3g.cn
HTTP GET requests:
  • cgi.con####.qq.com/qqconnectopen/openapi/policy_conf?sdkv=####&appid=###...
  • fre####.b####.3g.cn/index.php?c=####&m=####&a=####
  • fre####.b####.3g.cn/index.php?c=####&m=####&a=####&vps=####&pass=####&ty...
  • fre####.b####.3g.cn/index.php?c=####&m=####&a=####&vps=####&unionid=####...
  • fre####.b####.3g.cn/xuan/webApp/freeRead/classify.html?typeid=####&typen...
  • fre####.b####.3g.cn/xuan/webApp/freeRead/css/introduce.min.css?v=####
  • fre####.b####.3g.cn/xuan/webApp/freeRead/css/reset_new.min.css?v=####
  • fre####.b####.3g.cn/xuan/webApp/freeRead/images/210_280.png
  • fre####.b####.3g.cn/xuan/webApp/freeRead/images/gotop_03.png
  • fre####.b####.3g.cn/xuan/webApp/freeRead/images/icon-author.png
  • fre####.b####.3g.cn/xuan/webApp/freeRead/images/icon_gotop_sdk-min.png
  • fre####.b####.3g.cn/xuan/webApp/freeRead/js/classify.js?v=####
  • fre####.b####.3g.cn/xuan/webApp/freeRead/js/common.js?v=####
  • fre####.b####.3g.cn/xuan/webApp/freeRead/js/lazyload.min.js
  • fre####.b####.3g.cn/xuan/webApp/freeRead/js/md5.js
  • fre####.b####.3g.cn/xuan/webApp/freeRead/js/zepto.min.js
  • ggboo####.3g.cn/Home/Indexapp/content?versionname=####&qudao=####&versio...
  • ggboo####.3g.cn/Home/Indexapp/quit?versionname=####&qudao=####&versionco...
  • ggboo####.3g.cn/front/webApp/freeRead/css/home.min.css?v=####
  • ggboo####.3g.cn/front/webApp/freeRead/css/reset_new.min.css?v=####
  • ggboo####.3g.cn/front/webApp/freeRead/css/swiper.min.css
  • ggboo####.3g.cn/front/webApp/freeRead/images/90_120.jpg
  • ggboo####.3g.cn/front/webApp/freeRead/images/gotop_03.png
  • ggboo####.3g.cn/front/webApp/freeRead/images/icon-author.png
  • ggboo####.3g.cn/front/webApp/freeRead/images/icon_ads_word.png
  • ggboo####.3g.cn/front/webApp/freeRead/images/icon_change.png
  • ggboo####.3g.cn/front/webApp/freeRead/images/nav_img1.png
  • ggboo####.3g.cn/front/webApp/freeRead/images/nav_img2.png
  • ggboo####.3g.cn/front/webApp/freeRead/images/nav_img3.png
  • ggboo####.3g.cn/front/webApp/freeRead/images/nav_img6.png
  • ggboo####.3g.cn/front/webApp/freeRead/index.html?versionName=####&versio...
  • ggboo####.3g.cn/front/webApp/freeRead/js/common.js?v=####
  • ggboo####.3g.cn/front/webApp/freeRead/js/home.js?v=####
  • ggboo####.3g.cn/front/webApp/freeRead/js/lazyload.min.js
  • ggboo####.3g.cn/front/webApp/freeRead/js/md5.js
  • ggboo####.3g.cn/front/webApp/freeRead/js/swiper-4.3.3.min.js
  • ggboo####.3g.cn/front/webApp/freeRead/js/zepto.min.js
  • ggboo####.3g.cn/index.php?c=####&m=####&a=####&pass=####&pn=####&vps=###...
  • ggboo####.3g.cn/xuan//webApp/freeRead/css/reset_new.min.css?v=####
  • ggboo####.3g.cn/xuan//webApp/freeRead/introduce.html?bookid=####&version...
  • i####.b####.3g.cn/bookimage/bookpic/04/160504/160504_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/07/567207/567207_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/12/160712/160712_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/14/235614/235614_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/15/117215/117215_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/15/160015/160015_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/29/121829/121829_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/34/148234/148234_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/37/205237/205237_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/38/267538/267538_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/39/170339/170339_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/44/421044/421044_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/46/505246/505246_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/48/178948/178948_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/54/143454/143454_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/65/127065/127065_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/65/159965/159965_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/70/360970/360970_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/76/315576/315576_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/81/106281/106281_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/81/159981/159981_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/82/127682/127682_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/88/222888/222888_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/90/128490/128490_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/92/216892/216892_210_280.jpg
  • i####.b####.3g.cn/bookimage/bookpic/93/566793/566793_210_280.jpg
  • u####.3g.cn/Home/Indexapp/bookshelfcon?versionname=####&qudao=####&versi...
  • u####.3g.cn/Home/Indexapp/screen?versionname=####&qudao=####&versioncode...
HTTP POST requests:
  • a####.u####.com/app_logs
  • and####.b####.qq.com/rqd/async?aid=####
File system changes:
Creates the following files:
  • /data/data/####/.imprint
  • /data/data/####/05067399bb426ad9fd337984ea782ff9.0
  • /data/data/####/05067399bb426ad9fd337984ea782ff9.1
  • /data/data/####/05067399bb426ad9fd337984ea782ff9.2
  • /data/data/####/066189022eff5a6eb218939b5ddf5fe4.0
  • /data/data/####/066189022eff5a6eb218939b5ddf5fe4.1
  • /data/data/####/066189022eff5a6eb218939b5ddf5fe4.2
  • /data/data/####/0764d71a344601e407960acf44617ef7.0.tmp (deleted)
  • /data/data/####/0764d71a344601e407960acf44617ef7.1.tmp (deleted)
  • /data/data/####/0764d71a344601e407960acf44617ef7.2.tmp (deleted)
  • /data/data/####/1002
  • /data/data/####/1004
  • /data/data/####/1fc0dc1cf13aefc8822e0d4316c8bbda.0
  • /data/data/####/1fc0dc1cf13aefc8822e0d4316c8bbda.1
  • /data/data/####/1fc0dc1cf13aefc8822e0d4316c8bbda.2
  • /data/data/####/204b98032d3b86ec4796b645faf0900c.0
  • /data/data/####/204b98032d3b86ec4796b645faf0900c.1
  • /data/data/####/204b98032d3b86ec4796b645faf0900c.2
  • /data/data/####/2590bc8ee4562be5bbb8ac1f92f97c55.0
  • /data/data/####/2590bc8ee4562be5bbb8ac1f92f97c55.1
  • /data/data/####/2590bc8ee4562be5bbb8ac1f92f97c55.2
  • /data/data/####/276cac060c11936368d0ef690a510a78.0.tmp (deleted)
  • /data/data/####/276cac060c11936368d0ef690a510a78.1.tmp (deleted)
  • /data/data/####/276cac060c11936368d0ef690a510a78.2.tmp (deleted)
  • /data/data/####/28f1e3f25a6e5ecd6be004bbc7bc72ef.0.tmp (deleted)
  • /data/data/####/28f1e3f25a6e5ecd6be004bbc7bc72ef.1.tmp (deleted)
  • /data/data/####/28f1e3f25a6e5ecd6be004bbc7bc72ef.2.tmp (deleted)
  • /data/data/####/2d50aef70d4844f7b15393a9a42dc150.0
  • /data/data/####/2d50aef70d4844f7b15393a9a42dc150.1
  • /data/data/####/2d50aef70d4844f7b15393a9a42dc150.2
  • /data/data/####/2eec3243aa42af928d60494a86a20673.0
  • /data/data/####/2eec3243aa42af928d60494a86a20673.1
  • /data/data/####/2eec3243aa42af928d60494a86a20673.2
  • /data/data/####/3224adb5e20ee126b7f2e4683a1b7190.0.tmp (deleted)
  • /data/data/####/3224adb5e20ee126b7f2e4683a1b7190.1.tmp (deleted)
  • /data/data/####/3224adb5e20ee126b7f2e4683a1b7190.2.tmp (deleted)
  • /data/data/####/3a00946a616cff25493c696e9ee9e9a1.0.tmp (deleted)
  • /data/data/####/3a00946a616cff25493c696e9ee9e9a1.1.tmp (deleted)
  • /data/data/####/3a00946a616cff25493c696e9ee9e9a1.2.tmp (deleted)
  • /data/data/####/3a35937f-c880-45f1-a6f0-8971959a3c91.zip
  • /data/data/####/3a4279afa12ea7d72b2e5c9e84d32739.0.tmp (deleted)
  • /data/data/####/3a4279afa12ea7d72b2e5c9e84d32739.1.tmp (deleted)
  • /data/data/####/3a4279afa12ea7d72b2e5c9e84d32739.2.tmp (deleted)
  • /data/data/####/3fe73b796637075cabf9cdf6f25dcefc.0
  • /data/data/####/3fe73b796637075cabf9cdf6f25dcefc.1
  • /data/data/####/3fe73b796637075cabf9cdf6f25dcefc.2
  • /data/data/####/41e64ddf6bce116e96f9c5073af05799.0
  • /data/data/####/41e64ddf6bce116e96f9c5073af05799.1
  • /data/data/####/41e64ddf6bce116e96f9c5073af05799.2
  • /data/data/####/50217e064bce3bf4c79e523674afd7f0.0
  • /data/data/####/50217e064bce3bf4c79e523674afd7f0.1
  • /data/data/####/50217e064bce3bf4c79e523674afd7f0.2
  • /data/data/####/59dcde97cdb7d84af7895b600af0c61a.0.tmp (deleted)
  • /data/data/####/59dcde97cdb7d84af7895b600af0c61a.1.tmp (deleted)
  • /data/data/####/59dcde97cdb7d84af7895b600af0c61a.2.tmp (deleted)
  • /data/data/####/5d09c3c3bc057189c66f699747c0e2c9.0
  • /data/data/####/5d09c3c3bc057189c66f699747c0e2c9.1
  • /data/data/####/5d09c3c3bc057189c66f699747c0e2c9.2
  • /data/data/####/5f60f13b70dea21b1a584898708ded64.0
  • /data/data/####/5f60f13b70dea21b1a584898708ded64.1
  • /data/data/####/5f60f13b70dea21b1a584898708ded64.2
  • /data/data/####/638ce349653cf3d0ce2c4e811f530738.0.tmp (deleted)
  • /data/data/####/638ce349653cf3d0ce2c4e811f530738.1.tmp (deleted)
  • /data/data/####/638ce349653cf3d0ce2c4e811f530738.2.tmp (deleted)
  • /data/data/####/65daaac409252d9accba675c056076d8.0
  • /data/data/####/65daaac409252d9accba675c056076d8.1
  • /data/data/####/65daaac409252d9accba675c056076d8.2
  • /data/data/####/668fe310ee7563265997204ea37450d6.0
  • /data/data/####/668fe310ee7563265997204ea37450d6.1
  • /data/data/####/668fe310ee7563265997204ea37450d6.2
  • /data/data/####/6868df402742df35fa56f5f8cc42827d.0
  • /data/data/####/6868df402742df35fa56f5f8cc42827d.1
  • /data/data/####/6868df402742df35fa56f5f8cc42827d.2
  • /data/data/####/693adb8ed960abd0cbe35d773a8a3b8b.0.tmp (deleted)
  • /data/data/####/693adb8ed960abd0cbe35d773a8a3b8b.1.tmp (deleted)
  • /data/data/####/693adb8ed960abd0cbe35d773a8a3b8b.2.tmp (deleted)
  • /data/data/####/79f70b5cf92e33765069ceaa75dfc85d.0
  • /data/data/####/79f70b5cf92e33765069ceaa75dfc85d.1
  • /data/data/####/79f70b5cf92e33765069ceaa75dfc85d.2
  • /data/data/####/7a85f69323c2a68feb56ea9cc9b5f99a.0
  • /data/data/####/7a85f69323c2a68feb56ea9cc9b5f99a.1
  • /data/data/####/7a85f69323c2a68feb56ea9cc9b5f99a.2
  • /data/data/####/7d910dfe134f1783b08f108e23c93438.0
  • /data/data/####/7d910dfe134f1783b08f108e23c93438.1
  • /data/data/####/7d910dfe134f1783b08f108e23c93438.2
  • /data/data/####/89b8cd5b84868f0a421d8939152574f2.0
  • /data/data/####/89b8cd5b84868f0a421d8939152574f2.1
  • /data/data/####/89b8cd5b84868f0a421d8939152574f2.2
  • /data/data/####/8af1a465716d884477dc3d062d0d96d2.0
  • /data/data/####/8af1a465716d884477dc3d062d0d96d2.1
  • /data/data/####/8af1a465716d884477dc3d062d0d96d2.2
  • /data/data/####/8b307bc8fd75390cbe71cc5bc77f7f79.0.tmp (deleted)
  • /data/data/####/8b307bc8fd75390cbe71cc5bc77f7f79.1.tmp (deleted)
  • /data/data/####/8b307bc8fd75390cbe71cc5bc77f7f79.2.tmp (deleted)
  • /data/data/####/8d55d4a0ffdaaed96065e996d163cc2c.0.tmp (deleted)
  • /data/data/####/8d55d4a0ffdaaed96065e996d163cc2c.1.tmp (deleted)
  • /data/data/####/8d55d4a0ffdaaed96065e996d163cc2c.2.tmp (deleted)
  • /data/data/####/95acb5e885707387374e339fefc2350e.0
  • /data/data/####/95acb5e885707387374e339fefc2350e.1
  • /data/data/####/95acb5e885707387374e339fefc2350e.2
  • /data/data/####/95ec4c1edb246c88534200494001dbf8.0
  • /data/data/####/95ec4c1edb246c88534200494001dbf8.1
  • /data/data/####/95ec4c1edb246c88534200494001dbf8.2
  • /data/data/####/9900a53245862e7b01510253aa5afe07.0
  • /data/data/####/9900a53245862e7b01510253aa5afe07.1
  • /data/data/####/9900a53245862e7b01510253aa5afe07.2
  • /data/data/####/9b26d2d170998dce338591737565c9db.0.tmp (deleted)
  • /data/data/####/9b26d2d170998dce338591737565c9db.1.tmp (deleted)
  • /data/data/####/9b26d2d170998dce338591737565c9db.2.tmp (deleted)
  • /data/data/####/9ba8c01535b73b66c3e3b9987efe334f.0
  • /data/data/####/9ba8c01535b73b66c3e3b9987efe334f.1
  • /data/data/####/9ba8c01535b73b66c3e3b9987efe334f.2
  • /data/data/####/BUGLY_COMMON_VALUES.xml
  • /data/data/####/KA.xml
  • /data/data/####/LocalSetting.xml
  • /data/data/####/LocalSetting.xml.bak
  • /data/data/####/a2d0bce179384dc0c9e7bc18073522f3.0.tmp (deleted)
  • /data/data/####/a2d0bce179384dc0c9e7bc18073522f3.1.tmp (deleted)
  • /data/data/####/a2d0bce179384dc0c9e7bc18073522f3.2.tmp (deleted)
  • /data/data/####/ab7227890c14f614d90902dca8c77f1f.0
  • /data/data/####/ab7227890c14f614d90902dca8c77f1f.1
  • /data/data/####/ab7227890c14f614d90902dca8c77f1f.2
  • /data/data/####/abe765acb6d8849f3680699b3bc57d78.0.tmp (deleted)
  • /data/data/####/abe765acb6d8849f3680699b3bc57d78.1.tmp (deleted)
  • /data/data/####/abe765acb6d8849f3680699b3bc57d78.2.tmp (deleted)
  • /data/data/####/b1f2ade9286a5c1a7053625801a3dd42.0
  • /data/data/####/b1f2ade9286a5c1a7053625801a3dd42.1
  • /data/data/####/b1f2ade9286a5c1a7053625801a3dd42.2
  • /data/data/####/b37bf595fdb02486913fbfda5caf7bbd.0
  • /data/data/####/b37bf595fdb02486913fbfda5caf7bbd.1
  • /data/data/####/b37bf595fdb02486913fbfda5caf7bbd.2
  • /data/data/####/b8dbe498563df4f6e458cfc61e825d6a.0.tmp (deleted)
  • /data/data/####/b8dbe498563df4f6e458cfc61e825d6a.1.tmp (deleted)
  • /data/data/####/b8dbe498563df4f6e458cfc61e825d6a.2.tmp (deleted)
  • /data/data/####/books.db-journal
  • /data/data/####/bugly_db_-journal
  • /data/data/####/c45f3de1074983debcb00c2796b47975.0.tmp (deleted)
  • /data/data/####/c45f3de1074983debcb00c2796b47975.1.tmp (deleted)
  • /data/data/####/c45f3de1074983debcb00c2796b47975.2.tmp (deleted)
  • /data/data/####/c5bf2889cfb8c58de94b454d7ab87342.0.tmp (deleted)
  • /data/data/####/c5bf2889cfb8c58de94b454d7ab87342.1.tmp (deleted)
  • /data/data/####/c5bf2889cfb8c58de94b454d7ab87342.2.tmp (deleted)
  • /data/data/####/c870a926fef1eb83e7da5bc2db0f939a.0
  • /data/data/####/c870a926fef1eb83e7da5bc2db0f939a.1
  • /data/data/####/c870a926fef1eb83e7da5bc2db0f939a.2
  • /data/data/####/c9109eda3f9685c3c52522bdc6735fa7.0
  • /data/data/####/c9109eda3f9685c3c52522bdc6735fa7.1
  • /data/data/####/c9109eda3f9685c3c52522bdc6735fa7.2
  • /data/data/####/caa62327543b3344b3c816a9f2ba9a03.0.tmp (deleted)
  • /data/data/####/caa62327543b3344b3c816a9f2ba9a03.1.tmp (deleted)
  • /data/data/####/caa62327543b3344b3c816a9f2ba9a03.2.tmp (deleted)
  • /data/data/####/cc.db
  • /data/data/####/cc.db-journal
  • /data/data/####/chapter.db-journal
  • /data/data/####/classes.dex.dex
  • /data/data/####/classes.dex.jar
  • /data/data/####/com.tencent.open.config.json.1105530559
  • /data/data/####/com.weteent.freebook.BETA_VALUES.xml
  • /data/data/####/core_info
  • /data/data/####/crashrecord.xml
  • /data/data/####/d3e8fd5a26b0835be8cdf79817e72e8f.0.tmp (deleted)
  • /data/data/####/d3e8fd5a26b0835be8cdf79817e72e8f.1.tmp (deleted)
  • /data/data/####/d3e8fd5a26b0835be8cdf79817e72e8f.2.tmp (deleted)
  • /data/data/####/d7865dc39e7b20dc86acbe0959115a24.0
  • /data/data/####/d7865dc39e7b20dc86acbe0959115a24.1
  • /data/data/####/d7865dc39e7b20dc86acbe0959115a24.2
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/dde64304bc921336976ccac229f30db5.0.tmp (deleted)
  • /data/data/####/dde64304bc921336976ccac229f30db5.1.tmp (deleted)
  • /data/data/####/dde64304bc921336976ccac229f30db5.2.tmp (deleted)
  • /data/data/####/e1b26fbe9d4076026ad1b2571b0a8be0.0
  • /data/data/####/e1b26fbe9d4076026ad1b2571b0a8be0.1
  • /data/data/####/e1b26fbe9d4076026ad1b2571b0a8be0.2
  • /data/data/####/e41d5f3fe3ba1efdb8ef33e2e3f46dd2.0
  • /data/data/####/e41d5f3fe3ba1efdb8ef33e2e3f46dd2.1
  • /data/data/####/e41d5f3fe3ba1efdb8ef33e2e3f46dd2.2
  • /data/data/####/e551f308e6c0207bb93db0a418559109.0
  • /data/data/####/e551f308e6c0207bb93db0a418559109.1
  • /data/data/####/e551f308e6c0207bb93db0a418559109.2
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f06a846d3b6a177041b4ae18d891263f.0
  • /data/data/####/f06a846d3b6a177041b4ae18d891263f.1
  • /data/data/####/f06a846d3b6a177041b4ae18d891263f.2
  • /data/data/####/f552d3c247c75406fc05b3c0c46598f3.0.tmp (deleted)
  • /data/data/####/f552d3c247c75406fc05b3c0c46598f3.1.tmp (deleted)
  • /data/data/####/f552d3c247c75406fc05b3c0c46598f3.2.tmp (deleted)
  • /data/data/####/f5d20d9343ed886e5860d89d2dfe7205.0.tmp (deleted)
  • /data/data/####/f5d20d9343ed886e5860d89d2dfe7205.1.tmp (deleted)
  • /data/data/####/f5d20d9343ed886e5860d89d2dfe7205.2.tmp (deleted)
  • /data/data/####/f9e0e889e96c2e45d3c601225efde137.0
  • /data/data/####/f9e0e889e96c2e45d3c601225efde137.0.tmp (deleted)
  • /data/data/####/f9e0e889e96c2e45d3c601225efde137.1
  • /data/data/####/f9e0e889e96c2e45d3c601225efde137.1.tmp (deleted)
  • /data/data/####/f9e0e889e96c2e45d3c601225efde137.2
  • /data/data/####/f9e0e889e96c2e45d3c601225efde137.2.tmp (deleted)
  • /data/data/####/f_000001
  • /data/data/####/ggbook.db-journal
  • /data/data/####/icon.png
  • /data/data/####/icon_close.png
  • /data/data/####/index
  • /data/data/####/info.lock
  • /data/data/####/journal.tmp
  • /data/data/####/libpl_droidsonroids_gif.so
  • /data/data/####/local_crash_lock
  • /data/data/####/multidex.version.xml
  • /data/data/####/mute.png
  • /data/data/####/native_record_lock
  • /data/data/####/patch-330931cd.apk
  • /data/data/####/patch.apk
  • /data/data/####/patch.info
  • /data/data/####/patch.retry
  • /data/data/####/resources.apk
  • /data/data/####/resources.arsc
  • /data/data/####/security_info
  • /data/data/####/setting.xml
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/temp.apk
  • /data/data/####/test.dex.dex
  • /data/data/####/test.dex.jar
  • /data/data/####/tmpPatch.apk
  • /data/data/####/tt_ad_logo_small.png
  • /data/data/####/tt_ad_normal_screen_loading.png
  • /data/data/####/tt_back_video.png
  • /data/data/####/tt_close_move_details_normal.png
  • /data/data/####/tt_close_move_details_pressed.png
  • /data/data/####/tt_dislike_icon.png
  • /data/data/####/tt_download_active.png
  • /data/data/####/tt_download_pause.png
  • /data/data/####/tt_enlarge_video.png
  • /data/data/####/tt_forward_video.png
  • /data/data/####/tt_lefterbackicon_titlebar.png
  • /data/data/####/tt_lefterbackicon_titlebar_for_dark.png
  • /data/data/####/tt_lefterbackicon_titlebar_press.png
  • /data/data/####/tt_lefterbackicon_titlebar_press_for_dark.png
  • /data/data/####/tt_loading_fullscreen.png
  • /data/data/####/tt_new_pause_video.png
  • /data/data/####/tt_new_pause_video_press.png
  • /data/data/####/tt_new_play_video.png
  • /data/data/####/tt_normalscreen_loading.png
  • /data/data/####/tt_refreshing_video_textpage_normal.png
  • /data/data/####/tt_refreshing_video_textpage_pressed.png
  • /data/data/####/tt_shadow_fullscreen_top.9.png
  • /data/data/####/tt_shadow_lefterback_titlebar.png
  • /data/data/####/tt_shadow_lefterback_titlebar_press.png
  • /data/data/####/tt_shadow_lefterback_titlebar_press_withoutnight.png
  • /data/data/####/tt_shadow_lefterback_titlebar_withoutnight.png
  • /data/data/####/tt_shrink_fullscreen.png
  • /data/data/####/tt_shrink_video.png
  • /data/data/####/tt_titlebar_close.png
  • /data/data/####/tt_titlebar_close_for_dark.png
  • /data/data/####/tt_titlebar_close_press.png
  • /data/data/####/tt_titlebar_close_press_for_dark.png
  • /data/data/####/tt_white_lefterbackicon_titlebar.png
  • /data/data/####/tt_white_lefterbackicon_titlebar_press.png
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/unmute.png
  • /data/data/####/video_close.png
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal (deleted)
  • /data/media/####/tbslog.txt
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/sh -c getprop
  • getprop
  • getprop ro.product.cpu.abi
Loads the following dynamic libraries:
  • Bugly
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS7Padding
  • AES-GCM-NoPadding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS7Padding
  • AES-GCM-NoPadding
Contains functionality for automatic SMS sending.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android