Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.DownLoader.4837

Added to the Dr.Web virus database: 2020-02-16

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.DownLoader.611.origin
  • Android.DownLoader.906.origin
  • Android.Triada.4567
  • Android.Triada.470.origin
Downloads the following detected threats from the Internet:
  • Android.DownLoader.611.origin
Network activity:
Connects to:
  • UDP(DNS) 2####.5.5.5:53
  • UDP(DNS) 8####.8.4.4:53
  • UDP(DNS) 1####.29.29.29:53
  • UDP(DNS) 2####.6.6.6:53
  • UDP(DNS) 1####.114.114.114:53
  • TCP(HTTP/1.1) gd.a.s####.com:80
  • TCP(HTTP/1.1) ti####.c####.l####.####.com:80
  • TCP(HTTP/1.1) p####.api.adoc####.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) s####.e.qq.com:80
  • TCP(HTTP/1.1) s####.al####.com:80
  • TCP(HTTP/1.1) 1####.62.44.93:80
  • TCP(HTTP/1.1) l####.tbs.qq.com:80
  • TCP(HTTP/1.1) np.bul####.cn:6087
  • TCP(HTTP/1.1) task####.yuta####.com:80
  • TCP(HTTP/1.1) c-h####.g####.com:80
  • TCP(HTTP/1.1) yq####.jn####.ltd:80
  • TCP(HTTP/1.1) ngc.aliy####.com:80
  • TCP(HTTP/1.1) v3.bule####.cn:7001
  • TCP(HTTP/1.1) pg####.d2####.com:10273
  • TCP(HTTP/1.1) 1####.37.132.16:80
  • TCP(HTTP/1.1) q####.c####.l####.####.com:80
  • TCP(HTTP/1.1) awk.aoxun####.com:8199
  • TCP(HTTP/1.1) api.lubang####.com:80
  • TCP(HTTP/1.1) np.bul####.cn:81
  • TCP(HTTP/1.1) www.d####.xyz:80
  • TCP(HTTP/1.1) sdk.o####.p####.####.com:80
  • TCP(HTTP/1.1) w####.pcon####.com.cn:80
  • TCP(HTTP/1.1) iop.tlfj####.com:80
  • TCP(HTTP/1.1) ny.bul####.cn:666
  • TCP(HTTP/1.1) sh.wagbr####.aliyun####.com:80
  • TCP(HTTP/1.1) d####.buywe####.com:80
  • TCP(HTTP/1.1) luna-im####.qq.com.####.com:80
  • TCP(HTTP/1.1) sdk.w####.com:80
  • TCP(HTTP/1.1) co####.ssp.adoc####.com:80
  • TCP(HTTP/1.1) cdn-sdk####.g####.com.####.com:80
  • TCP(HTTP/1.1) vvv.focusd####.cn:80
  • TCP(HTTP/1.1) 1####.27.70.235:80
  • TCP(HTTP/1.1) ip.ta####.com:80
  • TCP(HTTP/1.1) tt####.vni####.com:20147
  • TCP(HTTP/1.1) hom####.yuta####.com:80
  • TCP(HTTP/1.1) api.gug####.com:8935
  • TCP(HTTP/1.1) zgx.powerle####.com:80
  • TCP(HTTP/1.1) sdk-ope####.g####.com:80
  • TCP(HTTP/1.1) np.bul####.cn:666
  • TCP(HTTP/1.1) e4####.0r####.com:10293
  • TCP(HTTP/1.1) t####.c####.q####.####.net:80
  • TCP(HTTP/1.1) c.isds####.qq.com:80
  • TCP(TLS/1.0) wild####.go-mp####.net.####.net:443
  • TCP(TLS/1.0) sb.scoreca####.com.####.net:443
  • TCP(TLS/1.0) s####.e.qq.com:443
  • TCP(TLS/1.0) h-adash####.ut.ta####.com:443
  • TCP(TLS/1.0) se####.v####.i####.com:443
  • TCP(TLS/1.0) a####.d####.com:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) wildca####.go-mp####.net.####.net:443
  • TCP(TLS/1.0) nl####.i####.com:443
  • TCP(TLS/1.0) log.mm####.com:443
  • TCP(TLS/1.0) ad####.cp####.cn:443
  • TCP(TLS/1.0) et2.wagbr####.adverti####.####.com:443
  • TCP(TLS/1.0) i####.com.edg####.net:443
  • TCP(TLS/1.0) mobjump####.oss-cn-####.aliy####.com:443
  • TCP(TLS/1.0) safebro####.google####.com:443
  • TCP(TLS/1.0) analy####.ray####.com:443
  • TCP(TLS/1.0) c####.i####.com:443
  • TCP(TLS/1.0) 1####.217.168.202:443
  • TCP(TLS/1.0) playato####.google####.com:443
  • TCP(TLS/1.0) dualsta####.wagbr####.ali####.####.com:443
  • TCP(TLS/1.0) is.sn####.com:443
  • TCP(TLS/1.0) i####.uc.cn:443
  • TCP(TLS/1.0) l####.58.com:443
  • TCP(TLS/1.0) analy####.map.qq.com:443
  • TCP(TLS/1.0) pcw####.i####.com:443
  • TCP(TLS/1.0) 1####.217.17.42:443
  • TCP(TLS/1.0) 1####.217.168.238:443
  • TCP(TLS/1.0) s####.d####.com:443
  • TCP(TLS/1.0) ims-####.sm.cn:443
  • TCP(TLS/1.0) na61-####.wagbr####.ali####.####.com:443
  • TCP(TLS/1.0) mi.g####.qq.com:443
  • TCP(TLS/1.0) android####.go####.com:443
  • TCP(TLS/1.0) hm.b####.com:443
  • TCP(TLS/1.0) contr####.i####.com:443
  • TCP(TLS/1.0) cryptau####.google####.com:443
  • TCP(TLS/1.0) a####.i####.com.####.net:443
  • TCP(TLS/1.0) m####.qy.net:443
  • TCP(TLS/1.0) ada####.m.ta####.com:443
  • TCP(TLS/1.0) jump####.58.com:443
  • TCP(TLS/1.0) t####.m.qq.com:443
  • TCP(TLS/1.0) api.adoc####.com:443
  • TCP(TLS/1.0) i####.d####.com:443
  • TCP(TLS/1.0) fk-old-####.ray####.com:443
  • TCP(TLS/1.0) trac####.58.com:443
  • TCP(TLS/1.0) st3.wagbr####.adverti####.####.com:443
  • TCP(TLS/1.0) iqiy####.com.edg####.net:443
  • TCP(TLS/1.0) nl-no####.i####.com:443
  • TCP(TLS/1.0) j1.5####.com.####.com:443
  • TCP(TLS/1.0) 1####.217.19.202:443
  • TCP(TLS/1.0) ad1.azh####.com:9190
  • TCP(TLS/1.0) g.al####.com:443
  • TCP(TLS/1.0) st####.i####.com.####.net:443
  • TCP(TLS/1.0) voledev####.google####.com:443
  • TCP(TLS/1.2) 1####.217.168.195:443
  • TCP(TLS/1.2) 1####.217.168.194:443
  • TCP(TLS/1.2) 1####.217.168.238:443
  • TCP(TLS/1.2) 1####.217.168.202:443
  • TCP(TLS/1.2) 1####.217.168.234:443
  • TCP(TLS/1.2) 1####.217.17.42:443
  • TCP(TLS/1.2) 1####.217.20.110:443
  • TCP(TLS/1.2) 1####.217.19.202:443
  • TCP cm-1####.ig####.com:5224
  • TCP sdk.o####.t####.####.com:5224
DNS requests:
  • 4s####.8c####.com
  • 7j####.c####.z0.####.com
  • a####.al####.com
  • a####.d####.com
  • a####.m.sm.cn
  • a####.man.aliy####.com
  • ad####.cp####.cn
  • ad1.azh####.com
  • ad3.azh####.com
  • ada####.ut.ta####.com
  • adas####.ut.ta####.com
  • analy####.map.qq.com
  • analy####.ray####.com
  • and####.b####.qq.com
  • android####.go####.com
  • api.adoc####.com
  • api.gug####.com
  • api.lubang####.com
  • awk.aoxun####.com
  • c####.i####.com
  • c####.m.i####.com
  • c####.v####.i####.com
  • c-h####.g####.com
  • c.5####.com.cn
  • c.go-mp####.net
  • c.isds####.qq.com
  • cdn-sdk####.g####.com
  • cm-1####.ig####.com
  • co####.ssp.adoc####.com
  • contr####.i####.com
  • cryptau####.google####.com
  • d####.b####.com
  • d####.buywe####.com
  • e4####.0r####.com
  • f####.api.aliyun####.com
  • f####.ftnorma####.com
  • fou####.ta####.com
  • g.al####.com
  • hm.b####.com
  • hom####.yuta####.com
  • i####.d####.com
  • i####.iqiy####.com
  • i####.m####.cn
  • i####.uc.cn
  • imgc####.qq.com
  • ims-####.sm.cn
  • iop.tlfj####.com
  • ip.ta####.com
  • is.sn####.com
  • j1.5####.com.cn
  • jump####.58.com
  • l####.58.com
  • l####.m.sm.cn
  • l####.tbs.qq.com
  • log.mm####.com
  • m####.go####.com
  • m####.qy.net
  • mi.g####.qq.com
  • mobjump####.oss-cn-####.aliy####.com
  • ngc.aliy####.com
  • nl####.i####.com
  • nl-no####.i####.com
  • np.bul####.cn
  • ny.bul####.cn
  • p####.api.adoc####.com
  • p####.google####.com
  • p####.yuta####.com
  • pco####.sm.cn
  • pcw####.i####.com
  • pg####.d2####.com
  • playato####.google####.com
  • plb####.u####.com
  • pub.m.i####.com
  • pv.s####.com
  • s####.al####.com
  • s####.d####.com
  • s####.d####.com
  • s####.e.qq.com
  • s####.m.sm.cn
  • s.go-mp####.net
  • safebro####.google####.com
  • sb.scoreca####.com
  • sdk-ope####.g####.com
  • sdk.c####.ig####.com
  • sdk.o####.p####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.com
  • sdk.o####.t####.####.net
  • sdk.w####.com
  • se####.v####.i####.com
  • secu####.i####.com
  • set####.ray####.com
  • st####.i####.com
  • st####.q####.com
  • stc.iqiy####.com
  • t####.m.qq.com
  • t7z.c####.i####.com
  • task####.yuta####.com
  • trac####.58.com
  • tt####.vni####.com
  • u####.u####.com
  • v3.bule####.cn
  • voledev####.google####.com
  • vvv.focusd####.cn
  • w####.pcon####.com.cn
  • www.d####.xyz
  • www.google-####.com
  • www.i####.com
  • www.iqiy####.com
  • y####.m.sm.cn
  • yq####.jn####.ltd
  • zgx.powerle####.com
HTTP GET requests:
  • c.isds####.qq.com/code.cgi?rate=####&domain=####&cgi=####&time=####&type...
  • cdn-sdk####.g####.com.####.com/tdata_EDB102
  • cdn-sdk####.g####.com.####.com/tdata_WMP296
  • cdn-sdk####.g####.com.####.com/tdata_qCN694
  • co####.ssp.adoc####.com/api/v2/SDKCommonConfig?channelCode=####&version=...
  • co####.ssp.adoc####.com/api/v2/mgmConfig?channelCode=####&version=####
  • co####.ssp.adoc####.com/api/v2/mgmWebviewRatioConfig?channelCode=####&ve...
  • d####.buywe####.com/Dock/getDYToken
  • hom####.yuta####.com/video_classes/
  • hom####.yuta####.com/video_modules/?class_id=####&page=####&page_size=##...
  • iop.tlfj####.com/eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ4NjQiOmZhbHNlLC...
  • ip.ta####.com/service/getIpInfo.php?ip=####
  • luna-im####.qq.com.####.com/qzone/biz/gdt/mod/android/AndroidAllInOne/pr...
  • p####.api.adoc####.com/ip
  • q####.c####.l####.####.com/config/hz-hzv6.conf
  • q####.c####.l####.####.com/tdata_TOj019
  • s####.al####.com/static/oss/aliyun-hz-sm-o2o01/launching_platform/9723f9...
  • s####.al####.com/static/oss/aliyun-hz-sm-o2o01/launching_platform/db87df...
  • sdk.o####.p####.####.com/api/addr.htm
  • t####.c####.q####.####.net/CMS/News/2019/06/25/151039.68297792_620X620.jpg
  • task####.yuta####.com/static/ad.json
  • task####.yuta####.com/static/x5.json
  • task####.yuta####.com/video_classes/
  • task####.yuta####.com/video_modules/?class_id=####&page=####&page_size=#...
  • ti####.c####.l####.####.com/20200211/从地球.jpg
  • ti####.c####.l####.####.com/20200211/医妃难囚2.jpg
  • ti####.c####.l####.####.com/20200211/快本.jpg
  • ti####.c####.l####.####.com/20200211/想见你.jpg
  • ti####.c####.l####.####.com/20200211/新世界.jpg
  • ti####.c####.l####.####.com/20200211/欢乐喜剧人.jpg
  • vvv.focusd####.cn/ad/v1/log.action?action=####&package=####&channel=####...
  • yq####.jn####.ltd/sy/hjwuzj
  • yq####.jn####.ltd/zz/445gjrjrtwyf.zip
  • zgx.powerle####.com/dnfile/cmm/PWrap20210P.jar
  • zgx.powerle####.com/dnfile/video/KernalApiTT20190903_119.jar
HTTP POST requests:
  • and####.b####.qq.com/rqd/async?aid=####
  • api.gug####.com:8935/
  • api.lubang####.com/domain.php
  • api.lubang####.com/srp.php
  • awk.aoxun####.com:8199/awk
  • c-h####.g####.com/api.php?format=####&t=####
  • e4####.0r####.com:10293/widlth/
  • gd.a.s####.com/cityjson
  • l####.tbs.qq.com/ajax?c=####&k=####
  • ngc.aliy####.com/data/r?a=####&m=####&o=####&k=####&p=####&u=####&t=####...
  • np.bul####.cn:6087/Sdk/patchPlayReport
  • np.bul####.cn:6087/Sdk/reportTask
  • np.bul####.cn:6087/Sdk/task
  • np.bul####.cn:6087/Sdk/tsReport
  • np.bul####.cn:666/slsdk/api_report.aspx
  • np.bul####.cn:81/Dock/getRsaAdverData
  • ny.bul####.cn:666/slsdk/getdata.aspx
  • pg####.d2####.com:10273/dvjnzt/
  • pg####.d2####.com:10273/rnggno/
  • pg####.d2####.com:10273/tzvntp/
  • s####.e.qq.com/activate
  • s####.e.qq.com/launch
  • sdk-ope####.g####.com/api.php?format=####&t=####
  • sdk.o####.p####.####.com/api.php?format=####&t=####
  • sdk.o####.p####.####.com/api.php?format=####&t=####&d=####&k=####
  • sdk.w####.com/rest/pt
  • sh.wagbr####.aliyun####.com/man/api?ak=####&s=####
  • tt####.vni####.com:20147/dijc1v/
  • v3.bule####.cn:7001/v3/api_request.aspx
  • v3.bule####.cn:7001/v3/api_settings.aspx
  • w####.pcon####.com.cn/ip.jsp
  • www.d####.xyz/Orders/getlive?channel=####&Slevi=####&anmac=####&anosv=##...
  • www.d####.xyz/Orders/getliveshua?channel=####&Slevi=####&anid=####&anmac...
  • www.d####.xyz/Orders/pigchannel?channel=####&nochannel=####
  • www.d####.xyz/Orders/setpnum?pnum=####&channel=####
File system changes:
Creates the following files:
  • /data/anr/traces.txt
  • /data/data/####/.__id_
  • /data/data/####/.__mob_ad_data.xml
  • /data/data/####/.imprint
  • /data/data/####/.jg.ic
  • /data/data/####/.turing.dat
  • /data/data/####/.zeg.xml
  • /data/data/####/.zeg.xml.bak
  • /data/data/####/00b93eba85ba5807_0
  • /data/data/####/0271f28e19d81dd6_0
  • /data/data/####/0271f28e19d81dd6_1
  • /data/data/####/02f27a2767be0f99_0
  • /data/data/####/0325798c3add3389_0
  • /data/data/####/0325798c3add3389_1
  • /data/data/####/03328aa96a49b36c_0
  • /data/data/####/0404a49d5efdf009_0
  • /data/data/####/06f723a54a89a4a7_0
  • /data/data/####/09f101986ddfd8c6_0
  • /data/data/####/0bfc91fe2bca9630_0
  • /data/data/####/0bff43be09dc3ac0_0
  • /data/data/####/0da42c3166426948_0
  • /data/data/####/0da42c3166426948_1
  • /data/data/####/0e350b766d596aff_0
  • /data/data/####/0edcc6716795d065_0 (deleted)
  • /data/data/####/1002
  • /data/data/####/1004
  • /data/data/####/1230ba3f28326e0b_0
  • /data/data/####/1295130a5bf8762b_0
  • /data/data/####/13b23ca5b481cedb_0
  • /data/data/####/1b15a8aec6124c17_0
  • /data/data/####/2020_02_16readzibao.xml
  • /data/data/####/2020_02_16shuareadszibao.xml
  • /data/data/####/2020_02_16zibao.xml
  • /data/data/####/25201b605bbf1b48_0
  • /data/data/####/25201b605bbf1b48_1
  • /data/data/####/269855efb55f0314_0
  • /data/data/####/269855efb55f0314_1
  • /data/data/####/280449a6c9ea1e96_0
  • /data/data/####/2881a2e43dfb704c0df1e1f3829713c1.0.tmp
  • /data/data/####/2881a2e43dfb704c0df1e1f3829713c1.1.tmp
  • /data/data/####/2889906ff7729a7b_0
  • /data/data/####/2889906ff7729a7b_1
  • /data/data/####/28cc8d6ab0e750e2_0
  • /data/data/####/2940195bd9870d6e_0
  • /data/data/####/2940195bd9870d6e_1
  • /data/data/####/29d774d9a517
  • /data/data/####/2dc7f6c5cb93851e_0
  • /data/data/####/2e0dd1b88e948719_0
  • /data/data/####/2e1e520bc235bdae_0
  • /data/data/####/2edcd5f6f14ada92_0
  • /data/data/####/3368a7f076e1a3a7_0
  • /data/data/####/3557.yaqcookie
  • /data/data/####/3740.yaqcookie
  • /data/data/####/37e6daadf3d6661e_0
  • /data/data/####/3b5e0c8dc54ae055_0
  • /data/data/####/3ba6bfe1b6979c0f_0
  • /data/data/####/3ec0cc838a8e5b7e_0
  • /data/data/####/40deb5c7e66c9ac0_0
  • /data/data/####/412d5f1a0654348f_0
  • /data/data/####/4158.yaqcookie
  • /data/data/####/41d469a6557bc896_0
  • /data/data/####/41d469a6557bc896_1
  • /data/data/####/4423.yaqcookie
  • /data/data/####/44367F39739CCD6BBF960E91E7DB78B2.xml
  • /data/data/####/453b6a5777b939fa_0
  • /data/data/####/453b6a5777b939fa_1
  • /data/data/####/4B8DB6B83129A65A2EF4DCFC1393C3B0.xml
  • /data/data/####/4a2cb75fa4554e5b_0
  • /data/data/####/4a2cb75fa4554e5b_1
  • /data/data/####/4b148bfbc5531137_0
  • /data/data/####/4baf45cd7e2e427e_0
  • /data/data/####/4baf45cd7e2e427e_1
  • /data/data/####/4f9ce0006c2cb16a_0
  • /data/data/####/50c122406c1ba4f0_0
  • /data/data/####/54500874f61556d7_0
  • /data/data/####/54500874f61556d7_1
  • /data/data/####/55f41614dab41f65_0
  • /data/data/####/58d07aa188497352_0
  • /data/data/####/58d07aa188497352_1
  • /data/data/####/59d103a390634512_0
  • /data/data/####/59d103a390634512_1
  • /data/data/####/5a69b321fb263283_0
  • /data/data/####/5aee4004d5c59561_0
  • /data/data/####/5d41bdd1a4a586bb_0
  • /data/data/####/6014a504a843fb60_0
  • /data/data/####/61861ba3a6a581d2_0
  • /data/data/####/672866b40937e598_0 (deleted)
  • /data/data/####/69520e093494a8f0_0
  • /data/data/####/69520e093494a8f0_1
  • /data/data/####/69d717170d156de8_0
  • /data/data/####/69d717170d156de8_1
  • /data/data/####/6a97283703a165e8_0
  • /data/data/####/6c5194f42d8e5d71_0
  • /data/data/####/70772331cf89b0de_0
  • /data/data/####/717e144651393dda_0
  • /data/data/####/7345f8162bd38137_0
  • /data/data/####/735e0911ab158d7f_0
  • /data/data/####/735e0911ab158d7f_1
  • /data/data/####/73fbe694fec8749f_0
  • /data/data/####/78f8ccbb32dbf8eba3a7023280c29674d14576436b115af....0.tmp
  • /data/data/####/7958388b2794a276_0
  • /data/data/####/7e146d4c9145b65e_0
  • /data/data/####/7fb6b828696f1ffc_0
  • /data/data/####/7fe617f8dc674e01_0
  • /data/data/####/808ae25b8aeba0a0_0
  • /data/data/####/8285687079f726e81979764e271ed349
  • /data/data/####/854741e046fd7d46_0
  • /data/data/####/8EAD111D030291821E19A80E344C340A.xml
  • /data/data/####/8b1cbb2e3c093a41_0
  • /data/data/####/8d999de25cda553b_0
  • /data/data/####/8d999de25cda553b_1
  • /data/data/####/8e75ff5ab24c0925_0
  • /data/data/####/90ae8cd34b7e4b539a15647e550016916f02a6aeba6ad56....0.tmp
  • /data/data/####/945145051a642c1880e0897f33a83ff1.0.tmp
  • /data/data/####/945145051a642c1880e0897f33a83ff1.1.tmp
  • /data/data/####/9663b8a8d67107c9_0
  • /data/data/####/97601de48c54f14d_0
  • /data/data/####/98c9b94fa94c92fe_0
  • /data/data/####/9ba2bc7be9720987_0
  • /data/data/####/9c45071a4b54ea6c_0
  • /data/data/####/9c8e9d32933819eb_0
  • /data/data/####/9cdf8e397c1dc061_0
  • /data/data/####/9cdf8e397c1dc061_1
  • /data/data/####/9e201b89844cb3d0_0
  • /data/data/####/9f123cc57eea71fe_0
  • /data/data/####/9f7fef82df814a0ebc2d9fc14d0bb11d.0.tmp
  • /data/data/####/9f7fef82df814a0ebc2d9fc14d0bb11d.1
  • /data/data/####/9f7fef82df814a0ebc2d9fc14d0bb11d.1.tmp
  • /data/data/####/Alvin2.xml
  • /data/data/####/BUGLY_COMMON_VALUES.xml
  • /data/data/####/BuglySdkInfos.xml
  • /data/data/####/ContextData.xml
  • /data/data/####/Cookies-journal
  • /data/data/####/DBE6A9C2BD7AE80EDFEF46878DB0B843.dex
  • /data/data/####/DBE6A9C2BD7AE80EDFEF46878DB0B843.dex.flock (deleted)
  • /data/data/####/GDTSDK.db
  • /data/data/####/GDTSDK.db-journal
  • /data/data/####/SDK_config
  • /data/data/####/SDK_config1
  • /data/data/####/SP_AROUTER_CACHE.xml
  • /data/data/####/UM_PROBE_DATA.xml
  • /data/data/####/UTCommon.xml
  • /data/data/####/VideoRes.apk
  • /data/data/####/WebViewBasePrefs.xml
  • /data/data/####/WebViewBasePrefs.xml.bak
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/_p.xml
  • /data/data/####/_sh.xml
  • /data/data/####/_umeng_common_config.xml
  • /data/data/####/a0086c5d8823c8b1_0
  • /data/data/####/a02acb6bf0aab84f_0
  • /data/data/####/a0dd39811f753b38_0
  • /data/data/####/a1ba1c9a11de5aac_0
  • /data/data/####/a2c3f7a8dcf8b410_0
  • /data/data/####/a2c3f7a8dcf8b410_1
  • /data/data/####/a400477b4a240046_0
  • /data/data/####/a400477b4a240046_1
  • /data/data/####/a5018c15c32265f0_0 (deleted)
  • /data/data/####/a607bc0033142622_0
  • /data/data/####/a607bc0033142622_1
  • /data/data/####/a93b07c2165363e2e72ccf0eb9c9e6bf5b4e1bab96dddfb....0.tmp
  • /data/data/####/a==8.0.0&&1.7.2.0_1581859505745_envelope.log
  • /data/data/####/ab9f03d66e586bf5_0
  • /data/data/####/ab9f03d66e586bf5_1
  • /data/data/####/abe11f2a9066fe2f_0
  • /data/data/####/abe11f2a9066fe2f_1
  • /data/data/####/af718ea2158bb085_0
  • /data/data/####/ap.Lock
  • /data/data/####/apkseparate.DoubleBackUpDB.db
  • /data/data/####/apkseparate.DoubleBackUpDB.db-journal
  • /data/data/####/b00677ac19172264_0
  • /data/data/####/b0ee3b2e4c7a4e0c_0
  • /data/data/####/b4c7b48d2fbdae34_0
  • /data/data/####/b704bc6006131134_0
  • /data/data/####/b7c50b8ef6837078_0
  • /data/data/####/bbe826c1889316fa156d1159ecde763c94d256099b5e132....0.tmp
  • /data/data/####/bc078a07d6abef3e_0
  • /data/data/####/bffc0b6286fb1e28_0
  • /data/data/####/bugly_db_-journal
  • /data/data/####/c1d1a43976088a7d_0
  • /data/data/####/c764a1872e07576d_0
  • /data/data/####/c853015aa11d5f67_0
  • /data/data/####/c853015aa11d5f67_1
  • /data/data/####/c890005d26666b07_0
  • /data/data/####/cb31534aa0abe708_0
  • /data/data/####/cc54d9acb3b964b0_0 (deleted)
  • /data/data/####/cc6d999de52aa16f_0
  • /data/data/####/cc75f77054923b17e70867dc8fc3ac3bd7b7980c7e75210....0.tmp
  • /data/data/####/cca.xml
  • /data/data/####/cd76a202682142db_0
  • /data/data/####/ce2dbd918a206259_0
  • /data/data/####/classes.dex
  • /data/data/####/classes.dex;classes2.dex
  • /data/data/####/classes.dex;classes3.dex
  • /data/data/####/clyjkk.png
  • /data/data/####/com.qq.e.sdkconfig.xml
  • /data/data/####/com.qq.e.sdkconfig.xml.bak
  • /data/data/####/com.ztzj.jhsp.BETA_VALUES.xml
  • /data/data/####/com.ztzj.jhsp.xml
  • /data/data/####/com.ztzj.jhsp.xml.bak
  • /data/data/####/com.ztzj.jhsp_preferences.xml
  • /data/data/####/config
  • /data/data/####/config.xml
  • /data/data/####/config.xml.bak
  • /data/data/####/core_info
  • /data/data/####/crashrecord.xml
  • /data/data/####/cv.xml
  • /data/data/####/d33461741a383042_0
  • /data/data/####/d855220268c2032c_0
  • /data/data/####/d855220268c2032c_1
  • /data/data/####/d870c33211690f82_0
  • /data/data/####/d97ee404b71b5154_0 (deleted)
  • /data/data/####/dW1weF9pbnRlcm5hbF8xNTgxODU5NTA1NTI0;
  • /data/data/####/dW1weF9pbnRlcm5hbF8xNTgxODU5NTE5NzI4;
  • /data/data/####/da16f7c07344520b_0
  • /data/data/####/da16f7c07344520b_1
  • /data/data/####/deeb263f45008a8c_0
  • /data/data/####/deeb263f45008a8c_1
  • /data/data/####/devCloudSetting.cfg
  • /data/data/####/devCloudSetting.sig
  • /data/data/####/device_id.xml.xml
  • /data/data/####/dexMethod.11475203.dat
  • /data/data/####/dn_config.db
  • /data/data/####/dn_config.db-journal
  • /data/data/####/downloader.db-journal
  • /data/data/####/e03d5746a0970fcd_0
  • /data/data/####/e03d5746a0970fcd_1
  • /data/data/####/e14184c2ee4989e2_0
  • /data/data/####/e2dffabf1471dc66_0
  • /data/data/####/e3edb0039a698f9d_0
  • /data/data/####/e3edb0039a698f9d_1
  • /data/data/####/e41653f03c521a54_0
  • /data/data/####/e41653f03c521a54_1
  • /data/data/####/e560d9f5b41ce3ce2ed074bcf11147a8.0.tmp
  • /data/data/####/e560d9f5b41ce3ce2ed074bcf11147a8.1.tmp
  • /data/data/####/eae86bc1a7121e79_0
  • /data/data/####/ed22206d2f99f7bd72583ce30470f0f1d7a0d83c0fc042c....0.tmp
  • /data/data/####/ed5bfe4bdbec3416c956d017ae73c00a
  • /data/data/####/ee6802e5fa51650a_0
  • /data/data/####/ef0ae86720d22f38_0
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f1f4a16e2b6aee8c_0
  • /data/data/####/f2e62622a46c9435_0
  • /data/data/####/f3687b3651fb2c75_0
  • /data/data/####/f7cb1127d3afb38e_0
  • /data/data/####/f8756f4f3ac5d9e5_0
  • /data/data/####/fa8e8d1c1ec4cb31_0
  • /data/data/####/fb7138146f4281e9_0
  • /data/data/####/fc.xml
  • /data/data/####/fc.xml.bak
  • /data/data/####/fe17a3067d3ace52_0
  • /data/data/####/fe17a3067d3ace52_1
  • /data/data/####/ffa32140e4ad68dd_0
  • /data/data/####/ffa32140e4ad68dd_1
  • /data/data/####/gameid
  • /data/data/####/gameid.zip
  • /data/data/####/gdt_config.cfg
  • /data/data/####/gdt_plugin.dex
  • /data/data/####/gdt_plugin.dex.flock (deleted)
  • /data/data/####/gdt_plugin.jar
  • /data/data/####/gdt_plugin.jar.sig
  • /data/data/####/gdt_plugin.tmp
  • /data/data/####/gdt_plugin.tmp.sig
  • /data/data/####/gdt_stat.db
  • /data/data/####/gdt_stat.db-journal
  • /data/data/####/gdt_suid
  • /data/data/####/getui_sp.xml
  • /data/data/####/gx_sp.xml
  • /data/data/####/https_www.iqiyi.com_0.localstorage-journal
  • /data/data/####/https_yz.m.sm.cn_0.localstorage-journal
  • /data/data/####/i==1.2.0&&1.7.2.0_1581859505918_envelope.log
  • /data/data/####/i==1.2.0&&1.7.2.0_1581859519731_envelope.log
  • /data/data/####/id87e15e87-6be2-4c4a-9048-7a630291be6c.tmp
  • /data/data/####/idaad0f211-f1c6-472f-b04a-8a69fb8040bb.tmp
  • /data/data/####/index
  • /data/data/####/info.xml
  • /data/data/####/init.pid
  • /data/data/####/init_c1.pid
  • /data/data/####/jhsp.db-journal
  • /data/data/####/journal.tmp
  • /data/data/####/jxnatrmn.dex (deleted)
  • /data/data/####/jxnatrmn.dex.flock (deleted)
  • /data/data/####/jxnatrmn.jar
  • /data/data/####/libMMANDKSignature.ce9085b0.so
  • /data/data/####/libdjtv
  • /data/data/####/libjiagu.so
  • /data/data/####/libsvdigk.so
  • /data/data/####/libsvdigk.so-32
  • /data/data/####/libsvdigk.so-64
  • /data/data/####/libturingau.ce9085b0.so
  • /data/data/####/libyaqbasic.11475203.so
  • /data/data/####/libyaqbasic.ce9085b0.so
  • /data/data/####/libyaqpro.11475203.so
  • /data/data/####/libyaqpro.ce9085b0.so
  • /data/data/####/local_crash_lock
  • /data/data/####/local_crash_lock (deleted)
  • /data/data/####/metrics_guid
  • /data/data/####/mintegral.msdk.db-journal
  • /data/data/####/mintegral.xml
  • /data/data/####/mpdc_105498_1
  • /data/data/####/native_record_lock
  • /data/data/####/native_record_lock (deleted)
  • /data/data/####/prdopt.xml
  • /data/data/####/proc_auxv
  • /data/data/####/push.pid
  • /data/data/####/pushext.db-journal
  • /data/data/####/pushg.db-journal
  • /data/data/####/pushsdk.db-journal
  • /data/data/####/pushservice_umeng_common_config.xml
  • /data/data/####/readzibao.xml
  • /data/data/####/run.pid
  • /data/data/####/sdkCloudSetting.cfg
  • /data/data/####/sdkCloudSetting.sig
  • /data/data/####/security_info
  • /data/data/####/share_date.xml
  • /data/data/####/share_date.xml.bak
  • /data/data/####/sp_global_info.xml
  • /data/data/####/t==8.0.0&&1.7.2.0_1581859505525_envelope.log
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbs_download_config.xml.bak
  • /data/data/####/tbs_download_stat.xml
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/tdargs.xml
  • /data/data/####/tdata_WMP296
  • /data/data/####/tdata_WMP296.dex
  • /data/data/####/tdata_WMP296.dex.flock (deleted)
  • /data/data/####/tdata_WMP296.jar
  • /data/data/####/tdata_qCN694
  • /data/data/####/tdata_qCN694.dex
  • /data/data/####/tdata_qCN694.dex.flock (deleted)
  • /data/data/####/tdata_qCN694.jar
  • /data/data/####/the-real-index
  • /data/data/####/tmp7.xml
  • /data/data/####/tmpbl.dex (deleted)
  • /data/data/####/tmpbl.dex.flock (deleted)
  • /data/data/####/tools8977.xml
  • /data/data/####/tools8977New2.xml
  • /data/data/####/tt_sdk_settings.xml
  • /data/data/####/ttff.xml
  • /data/data/####/ttff.xml.bak
  • /data/data/####/ttopenadsdk.xml
  • /data/data/####/ttopensdk.db-journal
  • /data/data/####/turingfd_conf_105498_auMini.xml
  • /data/data/####/turingfd_conf_105498_auMini.xml.bak
  • /data/data/####/turingfd_protect_105498_41_auMini.xml
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/um_pri.xml
  • /data/data/####/umdat.xml
  • /data/data/####/umeng_common_config.xml
  • /data/data/####/umeng_common_location.xml
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_general_config.xml.bak
  • /data/data/####/umeng_it.cache
  • /data/data/####/update_lc
  • /data/data/####/ut.db
  • /data/data/####/ut.db-journal
  • /data/data/####/videokernel.apk
  • /data/data/####/videokernel.dex
  • /data/data/####/videokernel.dex.flock (deleted)
  • /data/data/####/videonewyd_db-journal
  • /data/data/####/webview_umeng_common_config.xml
  • /data/data/####/yaq.ce9085b0.sec
  • /data/data/####/yaq2.ce9085b0.sec
  • /data/data/####/yaq3_0.ce9085b0.sec
  • /data/data/####/yaqsdkcookie
  • /data/data/####/yd_config_c.xml
  • /data/data/####/yunceng.conf
  • /data/media/####/.YiAds.log
  • /data/media/####/.YiAds_Net.log
  • /data/media/####/.a.dat
  • /data/media/####/.adfwe.dat
  • /data/media/####/.cca.dat
  • /data/media/####/.nid
  • /data/media/####/.nomedia
  • /data/media/####/.turing.dat
  • /data/media/####/.umm.dat
  • /data/media/####/.usdis
  • /data/media/####/.zjl
  • /data/media/####/1AF278535C486DC18070D7F86A7F22DB.temp
  • /data/media/####/2020_02_16zibao
  • /data/media/####/Alvin2.xml
  • /data/media/####/ContextData.xml
  • /data/media/####/DBE6A9C2BD7AE80EDFEF46878DB0B843
  • /data/media/####/DBE6A9C2BD7AE80EDFEF46878DB0B843.jar
  • /data/media/####/DBE6A9C2BD7AE80EDFEF46878DB0B843.temp
  • /data/media/####/E7ACE756EA704D1F1FB4769319831648
  • /data/media/####/Videoshell.log
  • /data/media/####/_pn
  • /data/media/####/_shn
  • /data/media/####/app.db
  • /data/media/####/ca024a78a304747077e7808f6313f66e.xml
  • /data/media/####/com.getui.sdk.deviceId.db
  • /data/media/####/com.igexin.sdk.deviceId.db
  • /data/media/####/com.ztzj.jhsp.bin
  • /data/media/####/com.ztzj.jhsp.db
  • /data/media/####/com.ztzj.jhsp1.7.2.0apkseparate.DoubleBackUpDB.db
  • /data/media/####/com.ztzj.jhsp1.7.2.0apkseparate.DoubleBackUpDB.db-journal
  • /data/media/####/dn_config.db
  • /data/media/####/dn_config.db-journal
  • /data/media/####/engc.jar
  • /data/media/####/isreadzibao
  • /data/media/####/kernel.dat
  • /data/media/####/plug.status
  • /data/media/####/session.dat
  • /data/media/####/sysid.dat
  • /data/media/####/tag4.dat
  • /data/media/####/tag4.date63ef890-4a3a-4ab5-bb7a-f0fd4d77080e.tmp
  • /data/media/####/tbslog.txt
  • /data/media/####/tdata_WMP296
  • /data/media/####/tdata_qCN694
  • /data/media/####/test.log
  • /data/media/####/tmpbl.jar
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/cat /proc/cpuinfo
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/.nvugk/jxnatrmn.jar --oat-fd=221 --oat-location=/data/user/0/<Package>/.nvugk/jxnatrmn.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/app_e_qq_com_plugin/gdt_plugin.jar --oat-fd=44 --oat-location=/data/user/0/<Package>/app_e_qq_com_dex/gdt_plugin.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/app_kernel/videokernel.apk --oat-fd=35 --oat-location=/data/user/0/<Package>/app_kernel/videokernel.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/app_kernel/videokernel.apk --oat-fd=71 --oat-location=/data/user/0/<Package>/app_kernel/videokernel.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/tdata_WMP296.jar --oat-fd=60 --oat-location=/data/user/0/<Package>/files/tdata_WMP296.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/tdata_qCN694.jar --oat-fd=61 --oat-location=/data/user/0/<Package>/files/tdata_qCN694.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/storage/emulated/0/.uct/tmp/dat/tmpbl.jar --oat-fd=95 --oat-location=/data/user/0/<Package>/app_tcdx/tmpbl.dex --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/storage/emulated/0/rxyd/<Package>/yui/DBE6A9C2BD7AE80EDFEF46878DB0B843.jar --oat-fd=161 --oat-location=/data/user/0/<Package>/files/DBE6A9C2BD7AE80EDFEF46878DB0B843.dex --compiler-filter=speed
  • /system/bin/df
  • cat /proc/cpuinfo
  • cat /sys/class/net/wlan0/address
  • getprop
  • getprop ro.build.version.emui
  • getprop ro.letv.release.version
  • getprop ro.product.cpu.abi
  • getprop ro.vivo.os.build.display.id
  • ls /
  • ls /proc/3557
  • ls /proc/3740
  • ls /sys/class/thermal
  • mount
  • ps
  • sh
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-CFB-NoPadding
  • AES-ECB-PKCS5Padding
  • AES-ECB-PKCS7Padding
  • AES-GCM-NoPadding
  • DES
  • DES-CBC-PKCS5Padding
  • Des-ECB-NoPadding
  • RSA-ECB-NoPadding
  • RSA-ECB-PKCS1Padding
  • RSA-NONE-OAEPWithSHA1AndMGF1Padding
  • RSA-None-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS5Padding
  • AES-ECB-PKCS7Padding
  • AES-GCM-NoPadding
  • DES
  • DES-CBC-PKCS5Padding
  • Des-ECB-NoPadding
  • RSA-ECB-PKCS1Padding
  • RSA-None-PKCS1Padding
Accesses the ITelephony private interface.
Uses special library to hide executable bytecode.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Gets information about running apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android