Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.RemoteCode.7267

Added to the Dr.Web virus database: 2021-02-01

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.RemoteCode.314.origin
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) p####.api.adoc####.com:80
  • TCP(HTTP/1.1) ip####.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) amdc####.m.ta####.com:80
  • TCP(HTTP/1.1) sh.wagbr####.aliyun####.com:80
  • TCP(HTTP/1.1) 14.17.1####.182:80
  • TCP(HTTP/1.1) f####.st####.z####.com:80
  • TCP(HTTP/1.1) api.a####.ads####.cn:80
  • TCP(HTTP/1.1) wa.bu####.vip:80
  • TCP(HTTP/1.1) pro.wildpet####.com:201
  • TCP(HTTP/1.1) cl.ads####.cn:80
  • TCP(HTTP/1.1) lo.bu####.vip:80
  • TCP(HTTP/1.1) 52.2####.173.174:80
  • TCP(HTTP/1.1) 2####.73.129.195:28018
  • TCP(HTTP/1.1) api.z####.com:80
  • TCP(HTTP/1.1) res####.a####.com:80
  • TCP(HTTP/1.1) 1####.76.103.4:28018
  • TCP(HTTP/1.1) p####.ugd####.com.####.com:80
  • TCP(HTTP/1.1) 1####.77.67.185:28018
  • TCP(HTTP/1.1) r####.bu####.vip:80
  • TCP(HTTP/1.1) l####.tbs.qq.com:80
  • TCP(HTTP/1.1) co####.ssp.adoc####.com:80
  • TCP(HTTP/1.1) s####.e.qq.com:80
  • TCP(HTTP/1.1) sd.bu####.vip:80
  • TCP(HTTP/1.1) api.adoc####.com:80
  • TCP(HTTP/1.1) alldo####.sweetco####.com.####.com:80
  • TCP(HTTP/1.1) newap####.math####.cn:80
  • TCP(HTTP/1.1) dy.cn.wildpet####.xyz:80
  • TCP(TLS/1.0) dxp.b####.com:443
  • TCP(TLS/1.0) di####.b####.net:443
  • TCP(TLS/1.0) 1####.74.90.25:31828
  • TCP(TLS/1.0) mi.g####.qq.com:443
  • TCP(TLS/1.0) api16-a####.pa####.io.####.net:443
  • TCP(TLS/1.0) alldo####.linx####.com.####.com:443
  • TCP(TLS/1.0) ap1.qi####.com:443
  • TCP(TLS/1.0) to####.ctobsn####.com:443
  • TCP(TLS/1.0) qy-swa####.qi####.com:443
  • TCP(TLS/1.0) fir####.h####.org:5665
  • TCP(TLS/1.0) dm.ps####.com:443
  • TCP(TLS/1.0) otherbd####.x2s####.t####.####.com:443
  • TCP(TLS/1.0) pang####.sn####.com:443
  • TCP(TLS/1.0) dualsta####.wagbr####.ali####.####.com:443
  • TCP(TLS/1.0) lbs.net####.im:443
  • TCP(TLS/1.0) sy.cl####.com:443
  • TCP(TLS/1.0) 2####.107.1.100:443
  • TCP(TLS/1.0) msg.umengc####.com:443
  • TCP(TLS/1.0) s####.e.qq.com:443
  • TCP(TLS/1.0) analy####.map.qq.com:443
  • TCP(TLS/1.0) dfzxi####.dftou####.com.####.com:443
  • TCP(TLS/1.0) al####.u####.com:443
  • TCP(TLS/1.0) hm.b####.com:443
  • TCP(TLS/1.0) 2####.58.211.106:443
  • TCP(TLS/1.0) res####.a####.com:443
  • TCP(TLS/1.0) securit####.sp####.mig.####.net:443
  • TCP(TLS/1.2) 2####.58.214.10:443
  • TCP(TLS/1.2) 1####.217.168.227:443
  • TCP(TLS/1.2) 1####.217.19.206:443
  • TCP l####.net####.im:8080
  • TCP zb-cent####.m.ta####.com:443
DNS requests:
  • a####.man.aliy####.com
  • amdc####.m.ta####.com
  • analy####.map.qq.com
  • and####.b####.qq.com
  • ap1.qi####.com
  • api.a####.ads####.cn
  • api.adoc####.com
  • api.z####.com
  • api16-a####.pa####.io
  • cde.sweetco####.com
  • cl.ads####.cn
  • co####.ssp.adoc####.com
  • dfzxi####.dftou####.com
  • dig.b####.net
  • dm.byted####.com
  • dm.ps####.com
  • dm.tou####.com
  • dwf.linx####.com
  • dxp.b####.com
  • dy.cn.wildpet####.xyz
  • f####.st####.z####.com
  • fir####.h####.org
  • h####.b####.com
  • hm.b####.com
  • ip####.com
  • l####.net####.im
  • l####.tbs.qq.com
  • lbs.net####.im
  • lo.bu####.vip
  • mi.g####.qq.com
  • msg.umengc####.com
  • newap####.math####.cn
  • p####.api.adoc####.com
  • p####.ugd####.com
  • pang####.sn####.com
  • plb####.u####.com
  • pro.wildpet####.com
  • q####.qq.com
  • qy-swa####.qi####.com
  • r####.bu####.vip
  • r####.bu####.vip
  • res####.a####.com
  • s####.e.qq.com
  • s9.c####.com
  • sd.bu####.vip
  • sf3-fe####.pglstat####.com
  • sf3-ttc####.ps####.com
  • sy.cl####.com
  • t####.m.qq.com
  • to####.ctobsn####.com
  • u####.u####.com
  • umen####.m.ta####.com
  • umengj####.m.ta####.com
  • wa.bu####.vip
HTTP GET requests:
  • alldo####.sweetco####.com.####.com/rhsdk/js/w20c.html
  • api.z####.com/v1/advert/config?platform=####&versionCode=####&timestamp=...
  • co####.ssp.adoc####.com/api/v2/SDKActiveConfig?version=####&channelCode=...
  • co####.ssp.adoc####.com/api/v2/SDKCommonConfig?channelCode=####&version=...
  • co####.ssp.adoc####.com/api/v2/mgmConfig?channelCode=####&version=####
  • co####.ssp.adoc####.com/api/v2/mgmWebviewRatioConfig?channelCode=####&ve...
  • f####.st####.z####.com/php12123/074163237731eb8feae0e1f1a1fb80a6.jpg
  • f####.st####.z####.com/php12123/20190319/1d0ad428ee3db572f8d7dc9caf5318a...
  • f####.st####.z####.com/php12123/508443a2aa7dc9235b6fed1dfdfcc594.jpg
  • f####.st####.z####.com/php12123/641c178a68f953dec8b9eb39d6a4c4d5.png
  • f####.st####.z####.com/php12123/81c1bc4e1321b330e3a14a20556d1d05.png
  • f####.st####.z####.com/php12123/8efe4c5c314baf02d77c1929e4056797.png
  • f####.st####.z####.com/php12123/c490c3279a36cdbeaa45fbd3475e8c14.png
  • f####.st####.z####.com/php12123/cc8be51abbbd6e129b1bbd6f316948d9.png
  • f####.st####.z####.com/php12123/cdb30a907b09862d617fe702bbf2c39d.png
  • f####.st####.z####.com/php12123/e66e55fe9d6fa063474494889f22de85.png
  • ip####.com/json/?lang=####
  • lo.bu####.vip/v1/log/track?key=####&mtype=####&device_####&pkg=####&subi...
  • newap####.math####.cn/ssp/mgm/task?taskId=####&ip=####
  • p####.api.adoc####.com/ip
  • p####.ugd####.com.####.com/gdt/0/EABCILvAQ4AeAAAAa4qBfj8IRBy0EFVmz.jpg/0...
  • r####.bu####.vip/assets/bdtj/it8.html?hmsr=####&hmpl=####
  • r####.bu####.vip/assets/bdtj/ppt.html?hmsr=####&hmpl=####&hmcu=####
  • r####.bu####.vip/favicon.ico
  • wa.bu####.vip/v1/log/track?key=####&mtype=####&device_####&pkg=####&subi...
HTTP POST requests:
  • amdc####.m.ta####.com/amdc/mobileDispatch?appkey=####&deviceId=####&plat...
  • and####.b####.qq.com/rqd/async?aid=####
  • api.a####.ads####.cn/thirdparty/sapi/chn
  • api.adoc####.com/titan/monitor/device_info
  • api.z####.com/app/version/android-upgrade
  • api.z####.com/push-tag/list
  • api.z####.com/tab-conf/app-column-conf
  • api.z####.com/tab-conf/app-sys-conf
  • api.z####.com/tab-conf/uuid
  • api.z####.com/tips/index
  • api.z####.com/v1/advert/list
  • api.z####.com/v1/news/list
  • api.z####.com/v1/news/type
  • cl.ads####.cn/cqapi/control/postrest
  • dy.cn.wildpet####.xyz/dycn/update
  • l####.tbs.qq.com/ajax?c=####&k=####
  • pro.wildpet####.com:201/proxy/get?e=####&r=####
  • res####.a####.com/v3/weather/weatherInfo
  • s####.e.qq.com/activate
  • sd.bu####.vip/v1/project/sdk
  • sh.wagbr####.aliyun####.com/man/api?ak=####&s=####
  • wa.bu####.vip/v1/wake/list
File system changes:
Creates the following files:
  • /data/data/####/.imprint
  • /data/data/####/.turing.dat
  • /data/data/####/1002
  • /data/data/####/1004
  • /data/data/####/105498_auMini_1
  • /data/data/####/1416f4da233ec65233b16f4a6f686f16.temp
  • /data/data/####/1cd5bdde56912f32_0
  • /data/data/####/1d2b904cbeadfb72ed9546111a231c85.0
  • /data/data/####/241d1deebf94583cf936e05310b8e392.temp
  • /data/data/####/24c110e1f76093b35c3c2df1927aab79.0
  • /data/data/####/27212187916668.0
  • /data/data/####/29857e5b185b6c8f_0
  • /data/data/####/29857e5b185b6c8f_1
  • /data/data/####/35214814470321.0
  • /data/data/####/3YeNzfHZubiLNhPTi_d23YlvD2Q.618268430.tmp
  • /data/data/####/4iV1UNQPWyrFSglhgK2_wdsoJiM.113358526.tmp
  • /data/data/####/54214028002768.0
  • /data/data/####/7c6fadb33e914b15bfc7019e4b5908d0
  • /data/data/####/7cb36f2b1e5a41bf_0
  • /data/data/####/8a5b201b1f5d4350bad0a6b3b6b1a7a4
  • /data/data/####/ACCS_BINDumeng;58107fdec8957663fb003c19.xml
  • /data/data/####/ACCS_SDK.xml
  • /data/data/####/ACCS_SDK_CHANNEL.xml
  • /data/data/####/ACCS_SDK_CHANNEL.xml.bak
  • /data/data/####/AGOO_BIND.xml
  • /data/data/####/Agoo_AppStore.xml
  • /data/data/####/Alvin2.xml
  • /data/data/####/BUGLY_COMMON_VALUES.xml
  • /data/data/####/BUGLY_COMMON_VALUES.xml.bak
  • /data/data/####/BuglySdkInfos.xml
  • /data/data/####/ContextData.xml
  • /data/data/####/Cookies-journal
  • /data/data/####/D7yiowOa4gRZeVnp5MokNkdgBaY.365474643.tmp
  • /data/data/####/EPLgwve4222gGRZB92xNiiLt6h0.1070963782.tmp
  • /data/data/####/ESTeupzo0a40wTVVCmChcXz_sXc.215986507.tmp
  • /data/data/####/GDTSDK.db
  • /data/data/####/GDTSDK.db-journal
  • /data/data/####/GPhNMysg_LbOHcXK5E6FwN1HnEo.cnt
  • /data/data/####/MessageStore.db-journal
  • /data/data/####/MsgLogStore.db-journal
  • /data/data/####/N-36LOhbgwidzYz1PCNWaz4U4jk.1702699562.tmp
  • /data/data/####/NIMSDK_Config_f7274dbc6d1b56317a1437bb9d42f596.xml
  • /data/data/####/NIMSDK_Config_f7274dbc6d1b56317a1437bb9d42f596_...02.xml
  • /data/data/####/UM_PROBE_DATA.xml
  • /data/data/####/Unicorn.f7274dbc6d1b56317a1437bb9d42f596.xml
  • /data/data/####/Unicorn.f7274dbc6d1b56317a1437bb9d42f596.xml.bak
  • /data/data/####/Unicorn.f7274dbc6d1b56317a1437bb9d42f596.xml.bak (deleted)
  • /data/data/####/V7Rha1I7ZGCW0X0lwEw6hATLkrI.cnt
  • /data/data/####/VNrBGRc5zPXj_9-3W2pFD7Y0ydU.cnt
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/ZH503.dex
  • /data/data/####/ZH503.dex.flock (deleted)
  • /data/data/####/ZH503.jar
  • /data/data/####/__Baidu_Stat_SDK_SendRem.xml
  • /data/data/####/__Baidu_Stat_SDK_SendRem.xml.bak
  • /data/data/####/___rb.p12___
  • /data/data/####/__cid__v1__.dat
  • /data/data/####/__local_ap_info_cache.json
  • /data/data/####/__local_last_session.json
  • /data/data/####/__local_stat_cache.json
  • /data/data/####/__local_stat_full_cache.json
  • /data/data/####/__rbpr_up18__
  • /data/data/####/__send_data_1612203435074
  • /data/data/####/a19677a629e00ac3_0
  • /data/data/####/a6d6e4a7cafe62e342c8d78e76f8571b.temp
  • /data/data/####/accs.db-journal
  • /data/data/####/adinitdex.xml
  • /data/data/####/agoo.pid
  • /data/data/####/aocd0402458.apk
  • /data/data/####/aocd0402458_o
  • /data/data/####/aocd0402458_o.flock (deleted)
  • /data/data/####/appuserid.xml
  • /data/data/####/b84a01b82563935f_0
  • /data/data/####/bac583bc0497fb9d_0
  • /data/data/####/bac583bc0497fb9d_1
  • /data/data/####/baed1190b959dbc2_0
  • /data/data/####/baed1190b959dbc2_0 (deleted)
  • /data/data/####/baidu_mtj_sdk_record.xml
  • /data/data/####/baidu_mtj_sdk_record.xml.bak
  • /data/data/####/bd_embed_tea_agent.db-journal
  • /data/data/####/be18eddcba8c4e79e761c913fbe81d34
  • /data/data/####/bugly_db_-journal
  • /data/data/####/cdu_st_-1897404729
  • /data/data/####/cdu_st_-1963733048
  • /data/data/####/cdu_st_-724289219
  • /data/data/####/cdu_st_-752754616
  • /data/data/####/cdu_st_1495260626
  • /data/data/####/cdu_st_1606883332
  • /data/data/####/cdu_st_465275389
  • /data/data/####/cdu_st_759790841
  • /data/data/####/channel_umeng_common_config.xml
  • /data/data/####/chuanglan_report_2.2.1.db
  • /data/data/####/chuanglan_report_2.2.1.db-journal
  • /data/data/####/com.qiyukf.analytics.xml
  • /data/data/####/com.qiyukf.analytics.xml.bak
  • /data/data/####/com.wswy.wzcx.BETA_VALUES.xml
  • /data/data/####/com.wswy.wzcx.BETA_VALUES.xml.bak
  • /data/data/####/com.wswy.wzcx_preferences.xml
  • /data/data/####/comxcxid.xml
  • /data/data/####/config
  • /data/data/####/core_info
  • /data/data/####/core_umeng_common_config.xml
  • /data/data/####/crashrecord.xml
  • /data/data/####/d2aa1683ac051e8d_0
  • /data/data/####/d5ab650655ea1d06_0
  • /data/data/####/dH-2X_6c8M5jbuJcHgNouIeVBEM.1931426136.tmp
  • /data/data/####/dW1weF9pbnRlcm5hbF8xNjEyMjAzNDI5NTQ1;
  • /data/data/####/dW1weF9wdXNoX2xhdW5jaF8xNjEyMjAzNDcyOTU4;
  • /data/data/####/dW1weF9wdXNoX3JlZ2lzdGVyXzE2MTIyMDM0NjI4OTg=;
  • /data/data/####/data.m
  • /data/data/####/de6fc6e6d00bdf773ac85456213ada55.temp
  • /data/data/####/devCloudSetting.cfg
  • /data/data/####/devCloudSetting.sig
  • /data/data/####/download_upload
  • /data/data/####/downloader.db-journal
  • /data/data/####/dso_deps
  • /data/data/####/dso_lock
  • /data/data/####/dso_manifest
  • /data/data/####/dso_state
  • /data/data/####/e5afbaf052dd347d_0
  • /data/data/####/e5eae7927a3c2e75_0
  • /data/data/####/eAfLZGqOEOCbjWqwjzwN8mtjv2A.cnt
  • /data/data/####/embed_applog_stats.xml
  • /data/data/####/embed_header_custom.xml
  • /data/data/####/embed_last_sp_session.xml
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/gdt_config.cfg
  • /data/data/####/gdt_download.db
  • /data/data/####/gdt_download.db-journal
  • /data/data/####/gdt_stat.db
  • /data/data/####/gdt_stat.db-journal
  • /data/data/####/gdt_suid
  • /data/data/####/hmdb
  • /data/data/####/hmdb-journal
  • /data/data/####/httpdns_config_cache.xml
  • /data/data/####/httpdns_config_cache.xml.bak
  • /data/data/####/i==1.2.0&&3.8.4_1612203429513_envelope.log
  • /data/data/####/index
  • /data/data/####/info.xml
  • /data/data/####/iqWC7GFZ34ULpE0yp-GaiN_zW30.cnt
  • /data/data/####/journal
  • /data/data/####/journal.tmp
  • /data/data/####/k.store
  • /data/data/####/km01
  • /data/data/####/km09_4598.so
  • /data/data/####/km09_4598.so_tmp
  • /data/data/####/km13
  • /data/data/####/kms_02ext
  • /data/data/####/kw_130191
  • /data/data/####/kw_130191_tmp
  • /data/data/####/libCtaApiLib.so
  • /data/data/####/libMMANDKSignature.so
  • /data/data/####/libShanYCore.so
  • /data/data/####/libcocklogic-1.1.3.so
  • /data/data/####/libcuid.so
  • /data/data/####/libeq
  • /data/data/####/libgifimage.so
  • /data/data/####/libimagepipeline.so
  • /data/data/####/libkm05.so
  • /data/data/####/libkm05_64.so
  • /data/data/####/libnative-filters.so
  • /data/data/####/libnative-imagetranscoder.so
  • /data/data/####/libnms.so
  • /data/data/####/libtnet-3.1.14.so
  • /data/data/####/libtobEmbedEncrypt.so
  • /data/data/####/libturingau.so
  • /data/data/####/libyaqcore_gdtadv.so
  • /data/data/####/libyaqstub_gdtadv.so
  • /data/data/####/local_crash_lock
  • /data/data/####/logdb.db
  • /data/data/####/logdb.db-journal
  • /data/data/####/message_accs_db
  • /data/data/####/message_accs_db-journal
  • /data/data/####/metrics_guid
  • /data/data/####/mpdc_105498_1
  • /data/data/####/msg.db-journal
  • /data/data/####/mtj_auto.config
  • /data/data/####/mtj_autoTracker.js
  • /data/data/####/native_record_lock (deleted)
  • /data/data/####/npth.xml
  • /data/data/####/npth_log.db-journal
  • /data/data/####/pp-Pl0vwwRC9G47uAHMHH2DheUg.89404806.tmp
  • /data/data/####/preload
  • /data/data/####/proc_auxv
  • /data/data/####/push_app_3.xml
  • /data/data/####/qiyu_save_f7274dbc6d1b56317a1437bb9d42f596.xml
  • /data/data/####/sdkCloudSetting.cfg
  • /data/data/####/sdkCloudSetting.sig
  • /data/data/####/sdkinit.xml
  • /data/data/####/sdkinit.xml.bak
  • /data/data/####/security_info
  • /data/data/####/shanyan_share_data.xml
  • /data/data/####/shanyan_share_data.xml.bak
  • /data/data/####/simple-main-req.dat
  • /data/data/####/snssdk_openudid.xml
  • /data/data/####/spUtils.xml
  • /data/data/####/sp_push_time.xml
  • /data/data/####/ssoconfigs.xml
  • /data/data/####/svvQ9rV78kR6K-G8uk78VC-xLfw.438728309.tmp
  • /data/data/####/t==8.1.2&&3.8.4_1612203430424_envelope.log
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbs_download_config.xml.bak
  • /data/data/####/tbs_download_stat.xml
  • /data/data/####/tbs_pv_config
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/the-real-index
  • /data/data/####/trace_circle.data
  • /data/data/####/tt_ad_sdk_sp.xml
  • /data/data/####/tt_dns_settings.xml
  • /data/data/####/tt_sdk_settings.xml
  • /data/data/####/tt_sdk_settings.xml.bak
  • /data/data/####/tt_sp_app_list.xml
  • /data/data/####/tt_sp_app_list.xml.bak
  • /data/data/####/ttopenadsdk.xml
  • /data/data/####/ttopenadsdk.xml.bak
  • /data/data/####/ttopensdk.db-journal
  • /data/data/####/turingfd_conf_105498_auMini.xml
  • /data/data/####/turingfd_conf_105498_auMini.xml.bak
  • /data/data/####/turingfd_protect_105498_47_auMini.xml
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/um_pri.xml
  • /data/data/####/umdat.xml
  • /data/data/####/umeng_common_config.xml
  • /data/data/####/umeng_common_config.xml.bak
  • /data/data/####/umeng_common_location.xml
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_general_config.xml.bak
  • /data/data/####/umeng_it.cache
  • /data/data/####/umeng_message_state.xml
  • /data/data/####/umengc.db
  • /data/data/####/unicorn#cheese#
  • /data/data/####/update_lc
  • /data/data/####/upz_5
  • /data/data/####/wBrand.xml
  • /data/data/####/weizhangapp.xml
  • /data/data/####/xdtversion.xml
  • /data/data/####/xoGyCbYSjGXH_qHfb3Dh2Mh_Zsc.cnt
  • /data/media/####/.a.dat
  • /data/media/####/.adfwe.dat
  • /data/media/####/.cca.dat
  • /data/media/####/.confd
  • /data/media/####/.confd-journal
  • /data/media/####/.nid
  • /data/media/####/.timestamp
  • /data/media/####/.turing.dat
  • /data/media/####/.umm.dat
  • /data/media/####/1612203436981.db
  • /data/media/####/1d8a29c01f0165feb179b17431d2e08f.tmp
  • /data/media/####/Alvin2.xml
  • /data/media/####/ContextData.xml
  • /data/media/####/alsn20170807.db
  • /data/media/####/alsn20170807.db-journal
  • /data/media/####/deviceToken
  • /data/media/####/e231c83c89094e16c0b3a255da8a2891.tmp
  • /data/media/####/meta.dat
  • /data/media/####/tbslog.txt
  • /data/media/####/temp_pkg_info.json
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • /proc/4598/exe
  • /system/bin/cat /proc/cpuinfo
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/aocd0402458.apk --oat-fd=92 --oat-location=/data/user/0/<Package>/files/aocd0402458_o --compiler-filter=speed
  • /system/bin/dex2oat --runtime-arg -classpath --runtime-arg & --instruction-set=x86 --instruction-set-features=smp,ssse3,sse4.1,sse4.2,-avx,-avx2,-lock_add,popcnt --runtime-arg -Xrelocate --boot-image=/system/framework/boot.art --runtime-arg -Xms64m --runtime-arg -Xmx512m --instruction-set-variant=x86 --instruction-set-features=default --dex-file=/data/user/0/<Package>/files/tda/ZH503.jar --oat-fd=122 --oat-location=/data/user/0/<Package>/files/tda/ZH503.dex --compiler-filter=speed
  • /system/bin/df
  • /system/bin/getprop
  • /system/lib/arm/houdini /data/user/0/<Package>/files/kms_02ext /data/user/0/<Package>/files/kms_02ext --ru89 0 /data/user/0/<Package>/files/debuggerd_real
  • /system/lib/arm/houdini <Package Folder>/files/kw_130191 <Package Folder>/files/kw_130191 3 267534
  • chmod 777 /data/user/0/<Package>/cache/Download
  • getprop
  • getprop ro.build.display.id
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.letv.release.version
  • getprop ro.miui.ui.version.name
  • getprop ro.product.cpu.abi
  • getprop ro.smartisan.version
  • getprop ro.vivo.os.build.display.id
  • getprop ro.vivo.os.version
  • logcat -d -v threadtime
  • ls /
  • ls /sys/class/thermal
  • mount
  • sh -c <Package Folder>/files/kw_130191 3 267534 &
  • sh -c cat /proc/4623/maps
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-NoPadding
  • AES-ECB-PKCS5Padding
  • AES-ECB-PKCS7Padding
  • AES-GCM-NoPadding
  • DES
  • RSA-ECB-NoPadding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS7Padding
  • AES-ECB-NoPadding
  • AES-ECB-PKCS5Padding
  • AES-ECB-PKCS7Padding
  • AES-GCM-NoPadding
  • DES
  • RSA-ECB-PKCS1Padding
Accesses the ITelephony private interface.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about APN settings.
Gets information about installed apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android