Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.Triada.5132

Added to the Dr.Web virus database: 2021-11-02

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Click.311.origin
  • Android.Click.395.origin
  • Android.DownLoader.1007.origin
  • Android.DownLoader.1051.origin
  • Android.DownLoader.981.origin
  • Android.Mobifun.30.origin
  • Android.Packed.55438
  • Android.RemoteCode.231.origin
  • Android.RemoteCode.319.origin
  • Android.Triada.4567
  • Android.Triada.5071
  • Android.Triada.510.origin
  • Android.Triada.537.origin
  • Android.Triada.573.origin
Threat detection based on machine learning.
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) 2kp####.quants####.com:80
  • TCP(HTTP/1.1) t####.c8####.com:13002
  • TCP(HTTP/1.1) c####.jq####.com:80
  • TCP(HTTP/1.1) u.y####.com:80
  • TCP(HTTP/1.1) sdk.appclic####.com:80
  • TCP(HTTP/1.1) cdn.adpu####.com:80
  • TCP(HTTP/1.1) d####.dd7####.com:80
  • TCP(HTTP/1.1) nu####.js####.com:12029
  • TCP(HTTP/1.1) y####.k8####.com:80
  • TCP(HTTP/1.1) fung####.ly####.com:80
  • TCP(HTTP/1.1) api.bi####.com:80
  • TCP(HTTP/1.1) s####.appclic####.com:80
  • TCP(HTTP/1.1) www-bin####.dual-a-####.a-ms####.net:80
  • TCP(HTTP/1.1) at.al####.com:80
  • TCP(HTTP/1.1) d.moce####.com:80
  • TCP(HTTP/1.1) www.d####.xyz:80
  • TCP(HTTP/1.1) h####.app####.com:80
  • TCP(HTTP/1.1) d.moce####.com:9091
  • TCP(HTTP/1.1) z.c####.com:80
  • TCP(HTTP/1.1) public-####.geo.adpu####.com:80
  • TCP(HTTP/1.1) en.hasm####.com:80
  • TCP(HTTP/1.1) geo.appclic####.com:80
  • TCP(HTTP/1.1) www.z####.com:80
  • TCP(HTTP/1.1) c####.y####.xyz:80
  • TCP(HTTP/1.1) www.h5s####.com:80
  • TCP(HTTP/1.1) web-eve####.ap-sout####.log.####.com:80
  • TCP(HTTP/1.1) 1####.128.85.140:80
  • TCP(HTTP/1.1) www.variety####.com:80
  • TCP(HTTP/1.1) p####.pay####.com:80
  • TCP(HTTP/1.1) z4####.ep####.com:14002
  • TCP(HTTP/1.1) securep####.g.doublec####.net:80
  • TCP(HTTP/1.1) cdn.pop####.net:80
  • TCP(HTTP/1.1) ro####.infol####.com:80
  • TCP(HTTP/1.1) pag####.googles####.com:80
  • TCP(HTTP/1.1) a####.r####.com:13002
  • TCP(HTTP/1.1) cdn.vig####.com:80
  • TCP(HTTP/1.1) api.applove####.com:80
  • TCP(HTTP/1.1) gc4####.9####.com:80
  • TCP(HTTP/1.1) hw9####.new####.com:80
  • TCP(HTTP/1.1) sdk####.appclic####.com:80
  • TCP(HTTP/1.1) s####.b####.com:80
  • TCP(TLS/1.0) securep####.g.doublec####.net:443
  • TCP(TLS/1.0) s####.1rx.io:443
  • TCP(TLS/1.0) b1####.zem####.com:443
  • TCP(TLS/1.0) 1####.177.14.95:443
  • TCP(TLS/1.0) pag####.googles####.com:443
  • TCP(TLS/1.0) adser####.go####.nl:443
  • TCP(TLS/1.0) m####.b####.com:443
  • TCP(TLS/1.0) www.gst####.com:443
  • TCP(TLS/1.0) s####.g.doublec####.net:443
  • TCP(TLS/1.0) c.c####.com:443
  • TCP(TLS/1.0) f####.google####.com:443
  • TCP(TLS/1.0) m.z####.cc:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) a.rf####.com.####.net:443
  • TCP(TLS/1.0) onetag####.com:443
  • TCP(TLS/1.0) ssc####.33ac####.com:443
  • TCP(TLS/1.0) s.c####.to:443
  • TCP(TLS/1.0) tpc.googles####.com:443
  • TCP(TLS/1.0) ssum####.casalem####.com.####.net:443
  • TCP(TLS/1.0) c####.pay####.com:443
  • TCP(TLS/1.0) cdn.jsde####.net:443
  • TCP(TLS/1.0) s####.appclic####.com:443
  • TCP(TLS/1.0) 1####.194.220.95:443
  • TCP(TLS/1.0) topm####.vip:443
  • TCP(TLS/1.0) wcf.seven####.com:443
  • TCP(TLS/1.0) p####.ups####.aolp-ds####.####.cloud:443
  • TCP(TLS/1.0) packag####.oss-ap-####.aliy####.com:443
  • TCP(TLS/1.0) gd.a.s####.com:443
  • TCP(TLS/1.0) a####.cloudf####.com:443
  • TCP(TLS/1.0) cdn.adpu####.com:443
  • TCP(TLS/1.0) dsp.adke####.com:443
  • TCP(TLS/1.0) i.vime####.com:443
  • TCP(TLS/1.0) z.c####.com:443
  • TCP(TLS/1.0) d####.pop####.net:443
  • TCP(TLS/1.0) s####.go.so####.com:443
  • TCP(TLS/1.0) imagesy####.pubm####.com:443
  • TCP(TLS/1.0) api.vig####.com:443
  • TCP(TLS/1.0) gm.mm####.com:443
  • TCP(TLS/1.0) g.geo####.com:443
  • TCP(TLS/1.0) e####.vap.l####.com:443
  • TCP(TLS/1.0) rgk.zu####.cn:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) funding####.go####.com:443
  • TCP(TLS/1.0) im####.google####.com:443
  • TCP(TLS/1.0) m####.ad####.org:443
  • TCP(TLS/1.0) u.o####.net:443
  • TCP(TLS/1.0) android####.go####.com:443
  • TCP(TLS/1.0) p####.ups-a####.aolp-ds####.####.cloud:443
  • TCP(TLS/1.0) newas####.hcap####.com:443
  • TCP(TLS/1.0) jsc.adske####.com:443
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.0) de.t####.com:443
  • TCP(TLS/1.0) ro####.infol####.com:443
  • TCP(TLS/1.0) fo####.site:443
  • TCP(TLS/1.0) 5.ah####.com:443
  • TCP(TLS/1.2) 1####.194.220.95:443
  • TCP(TLS/1.2) 64.2####.164.138:443
  • TCP(TLS/1.2) 74.1####.131.94:443
  • UDP 74.1####.173.167:443
  • TCP 1####.194.220.95:443
  • UDP 1####.194.220.95:443
  • TCP 1####.177.14.95:443
DNS requests:
  • 5.ah####.com
  • a####.cloudf####.com
  • a####.r####.com
  • adser####.go####.com
  • adser####.go####.nl
  • android####.go####.com
  • ap.l####.com
  • api.applove####.com
  • api.bi####.com
  • api.vig####.com
  • at.al####.com
  • b1####.zem####.com
  • c####.jq####.com
  • c####.mm####.com
  • c####.pay####.com
  • c####.y####.xyz
  • c.c####.com
  • cdn.adpu####.com
  • cdn.jsde####.net
  • cdn.pop####.net
  • cdn.vig####.com
  • d####.dd7####.com
  • d####.pop####.net
  • d.moce####.com
  • de.t####.com
  • dsp.adke####.com
  • dwq.fs####.com
  • e####.quants####.com
  • e3.adpu####.com
  • en.hasm####.com
  • f####.google####.com
  • f####.gst####.com
  • fo####.site
  • funding####.go####.com
  • fung####.ly####.com
  • ga_####.appclic####.com
  • gc4####.9####.com
  • geo.appclic####.com
  • googl####.g.doublec####.net
  • h####.app####.com
  • h5s####.com
  • hcap####.com
  • hw9####.new####.com
  • i.vime####.com
  • ib.a####.com
  • im####.google####.com
  • im####.pubm####.com
  • jsc.adske####.com
  • jz####.mc####.com
  • m####.ad####.org
  • m####.b####.com
  • m.z####.cc
  • newas####.hcap####.com
  • nu####.js####.com
  • onetag####.com
  • p####.adverti####.com
  • p####.pay####.com
  • p.cli####.net
  • p.rf####.com
  • packag####.oss-ap-####.aliy####.com
  • pag####.googles####.com
  • par####.googlea####.com
  • pv.s####.com
  • resou####.infol####.com
  • rgk.zu####.cn
  • ro####.infol####.com
  • s####.1rx.io
  • s####.appclic####.com
  • s####.b####.com
  • s####.g.doublec####.net
  • s####.go.so####.com
  • s.c####.to
  • s19.c####.com
  • sdk####.appclic####.com
  • sdk-eve####.ap-sout####.log.####.com
  • sdk.appclic####.com
  • securep####.g.doublec####.net
  • ssc####.33ac####.com
  • ssum####.casalem####.com
  • t####.c8####.com
  • topm####.vip
  • tpc.googles####.com
  • u.o####.net
  • u.y####.com
  • ups.analy####.y####.com
  • wcf.seven####.com
  • web-eve####.ap-sout####.log.####.com
  • www.b####.com
  • www.d####.xyz
  • www.duol####.com
  • www.go####.com
  • www.google-####.com
  • www.googlet####.com
  • www.googlet####.com
  • www.gst####.com
  • www.h5s####.com
  • www.variety####.com
  • www.z####.com
  • y####.k8####.com
  • z4####.ep####.com
  • z8.c####.com
  • z9.c####.com
HTTP GET requests:
  • 2kp####.quants####.com/quant.js
  • 5.ah####.com:443/thirdsdk/flowcashpack/123/TK-209a-202106251800d
  • 5.ah####.com:443/thirdsdk/flowcashpack/160/num-29072a-202110251610d
  • 5.ah####.com:443/thirdsdk/flowcashpack/82/MF-1.19a-202104301548d
  • a####.cloudf####.com:443/cdn-cgi/scripts/04b3eb47/cloudflare-static/mira...
  • adser####.go####.nl:443/pagead/html/r20211029/r20190131/zrt_lookup.html
  • api.applove####.com/api/v3/cache/get?osv=####&srnc=####&token=####&ds=##...
  • api.applove####.com/api/v3/search/get?osv=####&token=####&pm=####&os=###...
  • api.applove####.com/api/v3/template/get?slot_id=####&update_time=####&us...
  • at.al####.com/t/font_633469_vsn760jskh.css
  • c####.jq####.com/jquery-2.2.2.min.js
  • c####.y####.xyz/cdn-cgi/scripts/7d0fa10a/cloudflare-static/rocket-loader...
  • c####.y####.xyz/detail?id=####
  • c####.y####.xyz/favicon.ico
  • c####.y####.xyz/images/2019010502311799183.png
  • c####.y####.xyz/images/2019030514003912405.png
  • c####.y####.xyz/images/2019030713060410729.png
  • c####.y####.xyz/images/2019102506200537719.png
  • c####.y####.xyz/static/dist/css/basis.min.css
  • c####.y####.xyz/static/dist/css/detail.min.css
  • c####.y####.xyz/static/dist/js/quick.min.js
  • c####.y####.xyz/static/dist/js/router.min.js
  • cdn.adpu####.com/40494/adpushup.js
  • cdn.adpu####.com:443/pbuseridscripts/quantcast.js
  • cdn.jsde####.net:443/npm/lib-flexible@0.3.2/flexible.min.js
  • cdn.jsde####.net:443/npm/mobile-detect@1.4.3/mobile-detect.min.js
  • cdn.jsde####.net:443/npm/vanilla-lazyload@10.15.0/dist/lazyload.min.js
  • cdn.pop####.net/show.js
  • cdn.vig####.com/api/vglnk.js
  • d####.dd7####.com/upload/hw/batdex20191010.jar
  • d####.dd7####.com/upload/hw/c1005dex20190527.jar
  • d####.dd7####.com/upload/hw/h5rq20191022.jar
  • d####.dd7####.com/upload/hw/kklz02dex20200414.jar
  • d####.dd7####.com/upload/hw/lsdk20200506.jar
  • d####.dd7####.com/upload/hw/mf20200508.jar
  • d####.dd7####.com/upload/hw/qcdex20200316.jar
  • d####.dd7####.com/upload/plog/cy1028.jar
  • d####.dd7####.com/upload/plog/djso1101.jar
  • d####.dd7####.com/upload/plog/hx0409.jar
  • d####.dd7####.com/upload/plog/jar20190515.jar
  • d####.dd7####.com/upload/plog/jrw20210630.jar
  • d####.dd7####.com/upload/plog/kk20201106.jar
  • d####.dd7####.com/upload/plog/ps20210219.jar
  • d####.dd7####.com/upload/plog/sdk0625.jar
  • d####.dd7####.com/upload/plog/sh290_20210810.jar
  • d####.dd7####.com/upload/plog/skk20210416.jar
  • d####.dd7####.com/upload/plog/xianmm0512.jar
  • d####.dd7####.com/upload/plog/yeah0510.jar
  • en.hasm####.com/uploads/image/20190425/5cc176167a237dbg1k25cc176167a328....
  • fo####.site:443/ewewew/s20211101220628.1
  • funding####.go####.com:443/f/AGSKWxWGtL7zuZ1y1IcNdDu97XV3A1nSFYlAxzUsMF1...
  • fung####.ly####.com/cdn-cgi/challenge-platform/h/b/orchestrate/managed/v...
  • fung####.ly####.com/cdn-cgi/images/browser-bar.png?137675####
  • fung####.ly####.com/cdn-cgi/images/cf-no-screenshot-warn.png
  • fung####.ly####.com/cdn-cgi/images/trace/captcha/nojs/h/transparent.gif?...
  • fung####.ly####.com/cdn-cgi/images/trace/managed/js/transparent.gif?ray=...
  • fung####.ly####.com/cdn-cgi/styles/cf.errors.css
  • fung####.ly####.com/favicon.ico
  • fung####.ly####.com/lym07ly07/game/greedy-rat-eating-peas/
  • gc4####.9####.com/zsyunsxda
  • gc4####.9####.com/zsyunsxda/
  • gd.a.s####.com:443/cityjson
  • geo.appclic####.com/
  • h####.app####.com/allgame/ICON/wjzz/icon160.jpg
  • h####.app####.com/allgame/ICON/zhengfuyinhe/icon160.jpg
  • im####.google####.com:443/js/sdkloader/ima3.js
  • jsc.adske####.com:443/c/o/cool.ymqd.xyz.1000384.js
  • p####.pay####.com/s-r/332/60063a81055a8
  • packag####.oss-ap-####.aliy####.com:443/Ipv2_20211009/Ipv2_20211009_2
  • packag####.oss-ap-####.aliy####.com:443/browser_lada_20210507/browser_la...
  • packag####.oss-ap-####.aliy####.com:443/device_info/device_info_20210722
  • packag####.oss-ap-####.aliy####.com:443/js_browser_0312/js_browser_0312_...
  • packag####.oss-ap-####.aliy####.com:443/js_htp_20210604/js_htp_20210604_2
  • packag####.oss-ap-####.aliy####.com:443/js_soa_2/js_soa_2_20210926
  • packag####.oss-ap-####.aliy####.com:443/js_testpoca/js_testpoca_20210205
  • packag####.oss-ap-####.aliy####.com:443/js_wpn/js_wpn_20210412
  • packag####.oss-ap-####.aliy####.com:443/js_yy/js_yy_20210830
  • packag####.oss-ap-####.aliy####.com:443/js_yynews_2_20211026/js_yynews_2...
  • packag####.oss-ap-####.aliy####.com:443/stg/stg_201119
  • packag####.oss-ap-####.aliy####.com:443/test_inner/inner_20210804
  • pag####.googles####.com/pagead/show_ads.js
  • pag####.googles####.com:443/pagead/js/adsbygoogle.js
  • ro####.infol####.com/gsd?evt=afterGSD&pid=3288809&wsid=0&pdom=www.h5sgam...
  • ro####.infol####.com/js/1762.009-2.035/icemobile.js
  • ro####.infol####.com/js/infolinks_main.js
  • s####.appclic####.com/stg?channel=####&sdk=####
  • s####.appclic####.com:443/stg?channel=####&sdk=####
  • s####.b####.com/redirect?s=####&at=####&rt=####&s1=####
  • sdk####.appclic####.com/input?uuid=####&app=####&channel=####&vcode=####
  • sdk.appclic####.com/check?channel=####&geo=####
  • securep####.g.doublec####.net:443/tag/js/gpt.js
  • web-eve####.ap-sout####.log.####.com/logstores/web-ads/track?APIVersion=...
  • www-bin####.dual-a-####.a-ms####.net/
  • www.h5s####.com/ad/user_model.js?time=####
  • www.h5s####.com/favicon.ico
  • www.h5s####.com/list.html?list=####&user=####&uuid=####&app=####&channel...
  • www.h5s####.com/style/css/list.css
  • www.h5s####.com/style/css/public.min.css
  • www.h5s####.com/style/js/jquery-3.1.1.min.js
  • www.h5s####.com/style/js/jquery.mmenu.all.js
  • www.h5s####.com/style/js/main.js
  • www.h5s####.com/style/js/swiper.min.css
  • www.h5s####.com/style/js/swiper.min.js
  • www.variety####.com/f7220841d4f3911b2e5cf8e8ae6fe5e2/invoke.js
  • www.z####.com/12115.htm
  • www.z####.com/?ac=####&do=####&cid=####&channel=####&pagesize=####&callb...
  • www.z####.com/favicon.ico
  • www.z####.com/static/dh/default/css/ex.css
  • www.z####.com/static/dh/default/css/main.min.css?160708####
  • www.z####.com/static/js/dh_main.js?160708####
  • y####.k8####.com/cocoDY/app-5329125.zip
  • y####.k8####.com/dtbx/liangzong/hwlz06.zip
  • y####.k8####.com/dtbx/xingchuang/D10233_20210726.zip
  • y####.k8####.com/dtbx/yunshi/awli-release.zip
  • y####.k8####.com/hwyw/akertuns.zip
  • y####.k8####.com/hwyw/erfdoc9e54utr9gf7e455968y.zip
  • y####.k8####.com/hwyw/staunkert.zip
  • y####.k8####.com/plugins/applh0723.zip
  • y####.k8####.com/plugins/dp2.zip
  • y####.k8####.com/plugins/yz058Uc30i0913.zip
  • y####.k8####.com/zhuti/7y21yueermobi.zip
  • y####.k8####.com/zhuti/7y27jsdededkk.zip
  • y####.k8####.com/zhuti/8y17xinghao.zip
  • z.c####.com/stat.htm?id=####&cnzz_eid=####
HTTP POST requests:
  • a####.r####.com:13002/84gcjmo/
  • a####.r####.com:13002/ck0k66o/
  • a####.r####.com:13002/v1jyved/
  • api.bi####.com/un
  • c####.pay####.com:443/1/j?a=####
  • d.moce####.com/wap/gateway
  • d.moce####.com:9091/wap/gateway
  • fung####.ly####.com/cdn-cgi/challenge-platform/h/b/flow/ov1/0.2984151362...
  • hw9####.new####.com/api/activite
  • hw9####.new####.com/api/back
  • hw9####.new####.com/api/offer
  • hw9####.new####.com/api/tbdynamic
  • hw9####.new####.com/apidata/showeb
  • nu####.js####.com:12029/hfdlls/
  • nu####.js####.com:12029/i3v8nb/
  • nu####.js####.com:12029/lfkdnr/
  • public-####.geo.adpu####.com/AdPushupFeedbackWebService/user/sync
  • rgk.zu####.cn:443/v1/init?id=####
  • rgk.zu####.cn:443/v1/mr?id=####
  • t####.c8####.com:13002/4ad8fq/
  • t####.c8####.com:13002/a7atzr/
  • t####.c8####.com:13002/lgu4ds/
  • u.y####.com/api.php
  • u.y####.com/gst.php
  • u.y####.com/sal.php
  • u.y####.com/v4.php
  • u.y####.com/vereport.php
  • wcf.seven####.com:443/FBService.svc/GetPGCSetting
  • web-eve####.ap-sout####.log.####.com/logstores/dev-log/track
  • www.d####.xyz/Orders/getlive?channel=####&Slevi=####&anmac=####&anosv=##...
  • www.h5s####.com/api.php?req=####
  • z4####.ep####.com:14002/a2jyco/
  • z4####.ep####.com:14002/ajnhz5/
  • z4####.ep####.com:14002/uv2tay/
File system changes:
Creates the following files:
  • /data/data/####/.atmp9.dex
  • /data/data/####/.atmp9.dex.flock (deleted)
  • /data/data/####/.atmp9.jar
  • /data/data/####/.atmp_8.log
  • /data/data/####/.ki
  • /data/data/####/.m
  • /data/data/####/.t
  • /data/data/####/.wmgs
  • /data/data/####/011134986548f3458aa3e7e2a7fceb8d
  • /data/data/####/1.dex
  • /data/data/####/1.dex.flock (deleted)
  • /data/data/####/1.jar
  • /data/data/####/109099jvy
  • /data/data/####/109099jvy.dex
  • /data/data/####/109099jvy.dex.flock (deleted)
  • /data/data/####/17d4c14507657bb0_0
  • /data/data/####/2021_11_02readzibaoliangwuke.xml
  • /data/data/####/2037c3a34640dc5b_0
  • /data/data/####/2118BF62061AA81849864E1FA899D952
  • /data/data/####/2118BF62061AA81849864E1FA899D952.dex
  • /data/data/####/2118BF62061AA81849864E1FA899D952.dex.flock (deleted)
  • /data/data/####/2118BF62061AA81849864E1FA899D952.temp
  • /data/data/####/2118BF62061AA81849864E1FA899D952.zip
  • /data/data/####/22a8a032bffbd3c4_0
  • /data/data/####/37D20B1E2F07E4F3F21755062BA40547
  • /data/data/####/3e2wssr.xml
  • /data/data/####/3e2wssr.xml.bak
  • /data/data/####/47AB7209AD7ACF4EB1EA636A3039D803
  • /data/data/####/4A20E7AD78924312CD8BC7F756DE340F
  • /data/data/####/4A20E7AD78924312CD8BC7F756DE340F.dex
  • /data/data/####/4A20E7AD78924312CD8BC7F756DE340F.dex.flock (deleted)
  • /data/data/####/4A20E7AD78924312CD8BC7F756DE340F.temp
  • /data/data/####/4A20E7AD78924312CD8BC7F756DE340F.zip
  • /data/data/####/4d244479b54f7803_0
  • /data/data/####/5A064F2364D48401E82059BE1BFB3FC6
  • /data/data/####/5A064F2364D48401E82059BE1BFB3FC6.dex
  • /data/data/####/5A064F2364D48401E82059BE1BFB3FC6.dex.flock (deleted)
  • /data/data/####/5A064F2364D48401E82059BE1BFB3FC6.jar
  • /data/data/####/5A064F2364D48401E82059BE1BFB3FC6.temp
  • /data/data/####/636CD3B3EDFDE2D4D1D32F10D7347670
  • /data/data/####/636CD3B3EDFDE2D4D1D32F10D7347670.dex
  • /data/data/####/636CD3B3EDFDE2D4D1D32F10D7347670.dex.flock (deleted)
  • /data/data/####/636CD3B3EDFDE2D4D1D32F10D7347670.temp
  • /data/data/####/636CD3B3EDFDE2D4D1D32F10D7347670.zip
  • /data/data/####/6fb69037213d6bb4_0 (deleted)
  • /data/data/####/8FFE8235E5662DE0A07F13AC7491AB54
  • /data/data/####/90FCBC4E72D8C499954E2A48BD6A2C19
  • /data/data/####/90FCBC4E72D8C499954E2A48BD6A2C19.dex
  • /data/data/####/90FCBC4E72D8C499954E2A48BD6A2C19.dex.flock (deleted)
  • /data/data/####/90FCBC4E72D8C499954E2A48BD6A2C19.jar
  • /data/data/####/90FCBC4E72D8C499954E2A48BD6A2C19.temp
  • /data/data/####/92803EBB7D87B2E67FB0CEF6704D2D24
  • /data/data/####/95D59285D710EC3D31C7DC4E023745A4
  • /data/data/####/95D59285D710EC3D31C7DC4E023745A4.dex
  • /data/data/####/95D59285D710EC3D31C7DC4E023745A4.dex.flock (deleted)
  • /data/data/####/95D59285D710EC3D31C7DC4E023745A4.temp
  • /data/data/####/95D59285D710EC3D31C7DC4E023745A4.zip
  • /data/data/####/9B6F0F554183A3CD8361BE73C403E28B
  • /data/data/####/9B6F0F554183A3CD8361BE73C403E28B.dex
  • /data/data/####/9B6F0F554183A3CD8361BE73C403E28B.dex.flock (deleted)
  • /data/data/####/9B6F0F554183A3CD8361BE73C403E28B.temp
  • /data/data/####/9B6F0F554183A3CD8361BE73C403E28B.zip
  • /data/data/####/BFDB36197AD62250D717DC665B6B32FF
  • /data/data/####/C3B2481BF31F7E7DF213B1679D8AFC65
  • /data/data/####/C926D733D4E308956A8587F7AD9FED7C
  • /data/data/####/C926D733D4E308956A8587F7AD9FED7C.dex
  • /data/data/####/C926D733D4E308956A8587F7AD9FED7C.dex.flock (deleted)
  • /data/data/####/C926D733D4E308956A8587F7AD9FED7C.jar
  • /data/data/####/C926D733D4E308956A8587F7AD9FED7C.temp
  • /data/data/####/Cookies-journal
  • /data/data/####/D1E212CE2246CA824FF329FE82DA5812
  • /data/data/####/D1E212CE2246CA824FF329FE82DA5812.dex
  • /data/data/####/D1E212CE2246CA824FF329FE82DA5812.dex.flock (deleted)
  • /data/data/####/D1E212CE2246CA824FF329FE82DA5812.jar
  • /data/data/####/D1E212CE2246CA824FF329FE82DA5812.temp
  • /data/data/####/E1A26EB104BC37CA228217F2AA6136CB
  • /data/data/####/E1A26EB104BC37CA228217F2AA6136CB.dex
  • /data/data/####/E1A26EB104BC37CA228217F2AA6136CB.dex.flock (deleted)
  • /data/data/####/E1A26EB104BC37CA228217F2AA6136CB.jar
  • /data/data/####/E1A26EB104BC37CA228217F2AA6136CB.temp
  • /data/data/####/E7C8A3F6E0E20F381FF38DF485FCE16E
  • /data/data/####/E7C8A3F6E0E20F381FF38DF485FCE16E.dex
  • /data/data/####/E7C8A3F6E0E20F381FF38DF485FCE16E.dex.flock (deleted)
  • /data/data/####/E7C8A3F6E0E20F381FF38DF485FCE16E.temp
  • /data/data/####/E7C8A3F6E0E20F381FF38DF485FCE16E.zip
  • /data/data/####/EC0DA9876DC2A33B72C2A6BBEE1FE801.dex (deleted)
  • /data/data/####/EC0DA9876DC2A33B72C2A6BBEE1FE801.dex.flock (deleted)
  • /data/data/####/EC0DA9876DC2A33B72C2A6BBEE1FE801.jar
  • /data/data/####/F4B17ACF5290B91BC7F8C0FE52D16691
  • /data/data/####/F4B17ACF5290B91BC7F8C0FE52D16691.dex
  • /data/data/####/F4B17ACF5290B91BC7F8C0FE52D16691.dex.flock (deleted)
  • /data/data/####/F4B17ACF5290B91BC7F8C0FE52D16691.temp
  • /data/data/####/F4B17ACF5290B91BC7F8C0FE52D16691.zip
  • /data/data/####/F73811C2013B84778D431A6EE070420A
  • /data/data/####/F73811C2013B84778D431A6EE070420A.dex
  • /data/data/####/F73811C2013B84778D431A6EE070420A.dex.flock (deleted)
  • /data/data/####/F73811C2013B84778D431A6EE070420A.jar
  • /data/data/####/F73811C2013B84778D431A6EE070420A.temp
  • /data/data/####/MobikokCommonConfig.xml
  • /data/data/####/PreferenceDeviceConfig.xml
  • /data/data/####/RDEwMjMz_iuy_data.xml
  • /data/data/####/RDEwMjMz_uuid_data.xml
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/YnJvd3Nlcl9sYWRh%0A.abc
  • /data/data/####/ZS50bXAuZGVjLmphcg%3D%3D%0A.jar
  • /data/data/####/ZS50bXAuamFy%0A
  • /data/data/####/ZS5kZWMuamFy%0A.dex
  • /data/data/####/ZS5kZWMuamFy%0A.dex.flock (deleted)
  • /data/data/####/ZS5kZWMuamFy%0A.jar
  • /data/data/####/a0.d
  • /data/data/####/aG9zdF9zdGdfYmVzdF9zZGs%3D%0A.abc
  • /data/data/####/aXB2Mg%3D%3D%0A
  • /data/data/####/aXB2Mg%3D%3D%0A.abc
  • /data/data/####/aa1dc02f14bd694ad17d1f188edfa210
  • /data/data/####/ai
  • /data/data/####/anNfYnJvd3Nlcl8wMzEy%0A.abc
  • /data/data/####/anNfYnJvd3Nlcl8wMzEy%0A.dex
  • /data/data/####/anNfYnJvd3Nlcl8wMzEy%0A.dex.flock (deleted)
  • /data/data/####/anNfYnJvd3Nlcl8wMzEy%0A.jar
  • /data/data/####/anNfZGV2aWNlX2luZm8%3D%0A
  • /data/data/####/anNfZGV2aWNlX2luZm8%3D%0A.abc
  • /data/data/####/anNfaHRw%0A
  • /data/data/####/anNfaHRw%0A.abc
  • /data/data/####/anNfaHRw%0A.dex
  • /data/data/####/anNfaHRw%0A.dex.flock (deleted)
  • /data/data/####/anNfaHRw%0A.jar
  • /data/data/####/anNfc29hXzI%3D%0A.abc
  • /data/data/####/anNfd3Bu%0A
  • /data/data/####/anNfd3Bu%0A.abc
  • /data/data/####/anNfd3Bu%0A.dex
  • /data/data/####/anNfd3Bu%0A.dex.flock (deleted)
  • /data/data/####/anNfd3Bu%0A.jar
  • /data/data/####/anNfdGVzdHBvY2E%3D%0A.abc
  • /data/data/####/anNfdGVzdHBvY2E%3D%0A.dex
  • /data/data/####/anNfdGVzdHBvY2E%3D%0A.dex.flock (deleted)
  • /data/data/####/anNfdGVzdHBvY2E%3D%0A.jar
  • /data/data/####/anNfeXk%3D%0A.abc
  • /data/data/####/anNfeXluZXdzXzI%3D%0A
  • /data/data/####/anNfeXluZXdzXzI%3D%0A.abc
  • /data/data/####/androidxcorebac5z.
  • /data/data/####/androidxcorebac5z.dex
  • /data/data/####/androidxcorebac5z.dex.flock (deleted)
  • /data/data/####/base.apk
  • /data/data/####/base.dex
  • /data/data/####/base.dex.flock (deleted)
  • /data/data/####/c34a4c3h54e6_TYUYRTTYT
  • /data/data/####/ccddef.dex
  • /data/data/####/ccddef.dex.flock (deleted)
  • /data/data/####/ccddef.jar
  • /data/data/####/coeeem.sdf.dsf.dsfefe_ct_default.xml
  • /data/data/####/coeeem.sdf.dsf.dsfefe_preferences.xml
  • /data/data/####/coeeem.sdf.dsf.dsfefeye_after_install_pkg.xml
  • /data/data/####/curtain_sp.xml
  • /data/data/####/curtain_sp.xml.bak
  • /data/data/####/curtain_sp.xml.bak (deleted)
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e00c219ae8-4d8b-4...1f89b4
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e00c219ae8-4d8b-4...b4.dex
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e00c219ae8-4d8b-4...leted)
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e038e17b0e57b6ecc...0e1356
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e038e17b0e57b6ecc...6cache
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e07d8ad6e7195b848...949da4
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e07d8ad6e7195b848...leted)
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0b6cb96745f47e9c...65f071
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0b6cb96745f47e9c...leted)
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0bc8bc798-b8ed-4...5ba696
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0bc8bc798-b8ed-4...96.dex
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0bc8bc798-b8ed-4...leted)
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0fb872ce1-6120-4...4335e6
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0fb872ce1-6120-4...e6.dex
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0fb872ce1-6120-4...leted)
  • /data/data/####/d5d86b66b33e867b_0 (deleted)
  • /data/data/####/data.dex
  • /data/data/####/data.dex.flock (deleted)
  • /data/data/####/data.jar
  • /data/data/####/df4essr.xml
  • /data/data/####/df4essr.xml.bak
  • /data/data/####/du
  • /data/data/####/e3f4r3ed.data-journal
  • /data/data/####/e3wg5rd.data-journal
  • /data/data/####/fb9dd01690a0d1ddbce9e527fb32207f.xml
  • /data/data/####/fb9dd01690a0d1ddbce9e527fb32207f.xml.bak
  • /data/data/####/gameid
  • /data/data/####/gameid.zip
  • /data/data/####/gczt.png
  • /data/data/####/gjbq.png
  • /data/data/####/http_cool.ymqd.xyz_0.localstorage-journal
  • /data/data/####/index
  • /data/data/####/jctr
  • /data/data/####/kdid
  • /data/data/####/ktwp
  • /data/data/####/libkezc.so
  • /data/data/####/libkezc.so-32 (deleted)
  • /data/data/####/libkezc.so-64 (deleted)
  • /data/data/####/libmytz.so
  • /data/data/####/libmytz.so-32
  • /data/data/####/libmytz.so-64
  • /data/data/####/libsszf.so
  • /data/data/####/libsszf.so-32
  • /data/data/####/libsszf.so-64
  • /data/data/####/life_record_config.xml
  • /data/data/####/link.db
  • /data/data/####/link.db-journal
  • /data/data/####/metrics_guid
  • /data/data/####/mq.xml
  • /data/data/####/ofew.png
  • /data/data/####/ofew.png (deleted)
  • /data/data/####/pakge_caches.xml
  • /data/data/####/readzibaoliang.xml
  • /data/data/####/s1s1k1_c2o3n23f2i3g2.xml
  • /data/data/####/s3p43_OIUTIUYT.xml
  • /data/data/####/settingsLog.xml
  • /data/data/####/settingsLog.xml.bak
  • /data/data/####/settingsLog.xml.bak (deleted)
  • /data/data/####/sp_dojz.xml
  • /data/data/####/sp_dqzanr.xml
  • /data/data/####/sp_tgee.xml
  • /data/data/####/sp_tgee.xml.bak
  • /data/data/####/sp_uenzy.xml
  • /data/data/####/sp_uenzy.xml.bak
  • /data/data/####/sytk.xml
  • /data/data/####/the-real-index
  • /data/data/####/uhen.xml
  • /data/data/####/ulanda.xml
  • /data/data/####/uma.xml
  • /data/data/####/v71.xml
  • /data/data/####/v71.xml.bak
  • /data/data/####/xfksgku
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • app_process /system/bin com.android.commands.pm.Pm list package -3
  • cat /proc/version
  • cat /sys/class/net/wlan0/address
  • getprop ro.yunos.build.version
  • sh
Loads the following dynamic libraries:
  • xfksgku
Uses the following algorithms to encrypt data:
  • AES
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-ECB-PKCS5Padding
  • DES-CBC-PKCS5Padding
  • RSA-None-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-ECB-PKCS5Padding
  • DES-CBC-PKCS5Padding
  • RSA-None-PKCS1Padding
  • desede-CBC-PKCS5Padding
Accesses the ITelephony private interface.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Adds tasks to the system scheduler.
Requests the system alert window permission.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android