Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.Locker.16710

Added to the Dr.Web virus database: 2023-05-22

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Locker.14669
Threat detection based on machine learning.
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(TLS/1.0) gmscomp####.google####.com:443
  • TCP(TLS/1.0) i.bimbo####.com:443
  • TCP(TLS/1.0) www.por####.com:443
  • TCP(TLS/1.0) hw-####.a####.com:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) connect####.gst####.com:443
  • TCP(TLS/1.0) p####.google####.com:443
  • TCP(TLS/1.0) www.go####.ru:443
  • TCP(TLS/1.0) ads.traffic####.net:443
  • TCP(TLS/1.0) rr13---####.g####.com:443
  • TCP(TLS/1.0) and####.a####.go####.com:443
  • TCP(TLS/1.0) and####.google####.com:443
  • TCP(TLS/1.0) st####.traffic####.com:443
  • TCP(TLS/1.0) i.dy####.com:443
  • TCP(TLS/1.0) ei.ph####.com:443
  • TCP(TLS/1.0) 1####.250.150.102:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) cdn1-sm####.ph####.com:443
  • TCP(TLS/1.0) di.ph####.com:443
  • TCP(TLS/1.0) m####.traffic####.net:443
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.0) s####.g.doublec####.net:443
  • TCP(TLS/1.0) sto####.google####.com:443
  • TCP(TLS/1.0) h####.por####.com:443
  • TCP(TLS/1.0) dy####.com:443
DNS requests:
  • ads.traffic####.net
  • and####.a####.go####.com
  • and####.google####.com
  • cdn1-sm####.ph####.com
  • connect####.gst####.com
  • di.ph####.com
  • dy####.com
  • ei.ph####.com
  • gmscomp####.google####.com
  • h####.por####.com
  • ht-####.a####.com
  • hw-####.a####.com
  • i.bimbo####.com
  • i.dy####.com
  • m####.traffic####.net
  • p####.google####.com
  • rr13---####.g####.com
  • s####.g.doublec####.net
  • st####.traffic####.com
  • sto####.google####.com
  • v.dy####.com
  • www.go####.com
  • www.go####.ru
  • www.google####.com
  • www.google-####.com
  • www.googlet####.com
  • www.por####.com
File system changes:
Creates the following files:
  • /data/data/####/01e4dbd76aa58e5d_0
  • /data/data/####/01e4dbd76aa58e5d_s
  • /data/data/####/02e3c39ae5f24289_0
  • /data/data/####/03a82da4b6cf4e18_0
  • /data/data/####/03a9ac49388381ee_0
  • /data/data/####/045be1a25e7625f3_0
  • /data/data/####/050eac9f99725501_0 (deleted)
  • /data/data/####/064e5073fc92e16d_0
  • /data/data/####/06e2cee4a3a05915_0
  • /data/data/####/07079e138cba78a0_0
  • /data/data/####/070e1c75cc2bf6ca_0
  • /data/data/####/070e1c75cc2bf6ca_1
  • /data/data/####/09456025483146c3_0
  • /data/data/####/09456025483146c3_1
  • /data/data/####/097379ea6acd5296_0
  • /data/data/####/0a20b79c3042d675_0
  • /data/data/####/0a364fb28e1eff70_0
  • /data/data/####/0a364fb28e1eff70_1
  • /data/data/####/0abf6ae53b496651_0
  • /data/data/####/0b5f7c6ce09780a8_0
  • /data/data/####/0b6b2cf9001cc531_0 (deleted)
  • /data/data/####/0ba25789d2ed8c11_0
  • /data/data/####/0c2b8db3e975b42a_0
  • /data/data/####/0ccd23d6380ac5c4_0
  • /data/data/####/0d6c5e827867991d_0
  • /data/data/####/0da032ae64e6b9aa_0 (deleted)
  • /data/data/####/0db9c5701de112d5_0
  • /data/data/####/0dd38d398ed87208_0
  • /data/data/####/0eafde0a79fe0c3e_0
  • /data/data/####/119252b61ee504f1_0
  • /data/data/####/123343380b18c9aa_0
  • /data/data/####/123343380b18c9aa_1
  • /data/data/####/12a6ab2820351259_0
  • /data/data/####/1301815d416eae78_0 (deleted)
  • /data/data/####/1327588364a3b019_0
  • /data/data/####/138c36b82cbf34a1_0
  • /data/data/####/13907509ad4254bf_0
  • /data/data/####/13d2472b524bec67_0
  • /data/data/####/13e77088e80af0e8_0
  • /data/data/####/13e77088e80af0e8_1
  • /data/data/####/16774205fc992627_0
  • /data/data/####/170d300e1002ff31_0
  • /data/data/####/173ca1218bbfa8e6_0
  • /data/data/####/1756e6fdc0b163e8_0
  • /data/data/####/18348b91cf1f3977_0 (deleted)
  • /data/data/####/18b0a05f7a77ae3d_0 (deleted)
  • /data/data/####/1ce5ffb85b32a3e3_0
  • /data/data/####/1d8548926f2f7dff_0
  • /data/data/####/1d8548926f2f7dff_1
  • /data/data/####/1f449e77ab3d7f81_0
  • /data/data/####/20838a1c1d14743d_0
  • /data/data/####/21e87adf9aeda162_0
  • /data/data/####/22bd7212a88e28b2_0
  • /data/data/####/232711db5e55c005_0
  • /data/data/####/235c0d1fd83b8acb_0
  • /data/data/####/2576a4c18abbebc1_0
  • /data/data/####/2626055c46f21cb2_0
  • /data/data/####/267ef86bd6d9ee04_0
  • /data/data/####/2719f71f98afc17f_0
  • /data/data/####/272bebb1f82fbdc7_0
  • /data/data/####/28180da96b381650_0
  • /data/data/####/2940195bd9870d6e_0
  • /data/data/####/2940195bd9870d6e_1
  • /data/data/####/2a92103ff2ab1ab9_0
  • /data/data/####/2a9abdd2760760f6_0
  • /data/data/####/2ae4afb33f985cc5_0
  • /data/data/####/2b6c0fdbb3971b46_0
  • /data/data/####/2b92c470956cd8c0_0
  • /data/data/####/2b92c470956cd8c0_1
  • /data/data/####/2cc80dabc69f58b6_0
  • /data/data/####/2d4023ead7cf1844_0
  • /data/data/####/2dcb295b6a2c1989_0
  • /data/data/####/2dcb295b6a2c1989_1
  • /data/data/####/2f141d67b1f84758_0
  • /data/data/####/2f34dafc6f85c09d_0
  • /data/data/####/2f5e0652b54f9892_0
  • /data/data/####/3145b55246c2d428_0
  • /data/data/####/32e2ae6847c4d6ce_0
  • /data/data/####/3330feba67415e58_0
  • /data/data/####/33474d826c1f993c_0
  • /data/data/####/33b9b7992bd48699_0 (deleted)
  • /data/data/####/341b5b8df6d99622_0
  • /data/data/####/343974af900c0a46_0
  • /data/data/####/347bfb137425d2cc_0
  • /data/data/####/35a221f52a05a1cf_0 (deleted)
  • /data/data/####/35e4224f77da7e6f_0
  • /data/data/####/3617d7bdcb9ad60e_0
  • /data/data/####/36f75327e89a18e1_0
  • /data/data/####/373ee0918b0e1063_0
  • /data/data/####/373ee0918b0e1063_1
  • /data/data/####/399052d3228822a7_0
  • /data/data/####/3a066e736666897f_0
  • /data/data/####/3a0c6e5a158da91a_0
  • /data/data/####/3ccabe5398a1174a_0
  • /data/data/####/3cd650809bc1bf3a_0
  • /data/data/####/3d46bead0e0c7073_0 (deleted)
  • /data/data/####/3e786e013d43d2e7_0
  • /data/data/####/3ea4d78ea985ea67_0
  • /data/data/####/3ee1f1ee0f4c7c19_0
  • /data/data/####/3f272aca370f27d2_0
  • /data/data/####/3f7d683a44726fb5_0
  • /data/data/####/3fbfcd3a01762f61_0
  • /data/data/####/411c5e0570a123d0_0
  • /data/data/####/42104658c729135e_0
  • /data/data/####/42104658c729135e_1
  • /data/data/####/42ae9024636dd0d3_0
  • /data/data/####/43bb056573be5e2e_0
  • /data/data/####/442634d118055523_0
  • /data/data/####/451cf9d4c58471c3_0 (deleted)
  • /data/data/####/45440df98dd6e1a5_0
  • /data/data/####/4696b5a0b72bd258_0
  • /data/data/####/48c3feee84388013_0
  • /data/data/####/49a5cceda2c36363_0
  • /data/data/####/4a27610c77f66293_0
  • /data/data/####/4ac6e9671e899d1b_0
  • /data/data/####/4baf6bfb8b0b86fc_0
  • /data/data/####/4bbd16f76cc3a677_0
  • /data/data/####/4bbd16f76cc3a677_s
  • /data/data/####/4c5a264caa4b1d25_0
  • /data/data/####/4cb013792b196a35_0
  • /data/data/####/4cb013792b196a35_1
  • /data/data/####/4eb35da5861c5160_0
  • /data/data/####/4ed92342b9895a0f_0
  • /data/data/####/4ed92342b9895a0f_1
  • /data/data/####/5003909ad2bd4ed6_0
  • /data/data/####/515fa18f5edf7a71_0
  • /data/data/####/5419832ac7f601a4_0
  • /data/data/####/5538f8b8de97a28c_0 (deleted)
  • /data/data/####/556b00d49d2f0647_0
  • /data/data/####/56dff86e002ed067_0
  • /data/data/####/574cb475e71779c9_0
  • /data/data/####/57b41eae62d0b53b_0
  • /data/data/####/59982710c160333f_0
  • /data/data/####/5bafd5dc46764e98_0
  • /data/data/####/5bafd5dc46764e98_1
  • /data/data/####/5c80fff7ea99cf20_0
  • /data/data/####/5ca24638459ec86c_0
  • /data/data/####/5dbd6e08966ad78d_0
  • /data/data/####/5dc6b03222a24bef_0
  • /data/data/####/5eafc2a0220fb51c_0
  • /data/data/####/5eafc2a0220fb51c_1
  • /data/data/####/5edeeecea831989a_0
  • /data/data/####/6089a435b6d034e1_0
  • /data/data/####/618c35c26cb1951f_0
  • /data/data/####/627f8408e064f136_0
  • /data/data/####/62c7a4b13f61aac3_0
  • /data/data/####/637f5d641865b37a_0
  • /data/data/####/64508fa1cd46b0ab_0
  • /data/data/####/64508fa1cd46b0ab_1
  • /data/data/####/64fc3eb2431ff7e7_0
  • /data/data/####/66e7834481663201_0
  • /data/data/####/66e7834481663201_1
  • /data/data/####/67d79cdd4bb85ac7_0
  • /data/data/####/6802d32000f7a29d_0
  • /data/data/####/68307d5784b05214_0
  • /data/data/####/6a9d203bdc7779f4_0
  • /data/data/####/6cf8a266766c39c6_0
  • /data/data/####/6fd1b9f6777c8284_0
  • /data/data/####/701d95dce24c67ff_0
  • /data/data/####/701d95dce24c67ff_1
  • /data/data/####/7066d884af61cd67_0
  • /data/data/####/71536c05d797db2a_0 (deleted)
  • /data/data/####/71d007cbe7cec7bd_0
  • /data/data/####/72206be8c3273e0a_0 (deleted)
  • /data/data/####/72acfe0ca4762d12_0
  • /data/data/####/7403236690f91b38_0
  • /data/data/####/7636c68b20dfb857_0
  • /data/data/####/78c7c798979a4ae7_0
  • /data/data/####/79b84fed6e8090af_0
  • /data/data/####/7ab78ddbdb117579_0
  • /data/data/####/7c36fcfeed892bef_0
  • /data/data/####/7c36fcfeed892bef_1
  • /data/data/####/7d59656b674ff3b5_0
  • /data/data/####/7daf53d96b278a9a_0
  • /data/data/####/7daf53d96b278a9a_s
  • /data/data/####/7e4a3dff3bd08183_0
  • /data/data/####/7e7502214ad2755b_0
  • /data/data/####/7f5e07f8d684a87b_0 (deleted)
  • /data/data/####/7f9acb48d981e999_0 (deleted)
  • /data/data/####/8027f09ec562a42c_0 (deleted)
  • /data/data/####/80f468ecf75b6b3f_0
  • /data/data/####/81c70b9581b34a53_0
  • /data/data/####/82c40b393676aa41_0
  • /data/data/####/84068c9499a2cf8c_0
  • /data/data/####/8514bb6ccbe87983_0
  • /data/data/####/8601294cfc66d3f3_0
  • /data/data/####/883925fa7b872158_0
  • /data/data/####/8888bac454c36fa6_0
  • /data/data/####/8888bac454c36fa6_1
  • /data/data/####/891807cd26ba8414_0
  • /data/data/####/8a763521a9dacbb1_0
  • /data/data/####/8d370449385ed857_0
  • /data/data/####/8e271bb7dc871e14_0
  • /data/data/####/8ebe8f3fbd2b919a_0
  • /data/data/####/922c749ad5672bd7_0
  • /data/data/####/92defcfcec8ff33e_0
  • /data/data/####/936cb1a9b87b87bb_0
  • /data/data/####/9402ef73a016ffbb_0
  • /data/data/####/9593cfbc28ec4cb8_0
  • /data/data/####/95cae56d052c205b_0
  • /data/data/####/99368256906f1ac6_0
  • /data/data/####/9ac35cd54d432e91_0
  • /data/data/####/9c2e51860fdbc06d_0
  • /data/data/####/9d0ec0b1c17328a2_0
  • /data/data/####/9dbd22f8dab4b211_0
  • /data/data/####/9ed5fa90eef33434_0
  • /data/data/####/9ef6af65c92b4e10_0
  • /data/data/####/9f1de426e63372ab_0
  • /data/data/####/CURRENT
  • /data/data/####/Cookies-journal
  • /data/data/####/CrokYbDPh.dex
  • /data/data/####/CrokYbDPh.dex.flock (deleted)
  • /data/data/####/Databases.db-journal
  • /data/data/####/MANIFEST-000001
  • /data/data/####/QuotaManager-journal
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a19385f7808f8ab6_0
  • /data/data/####/a1a0eb390b604316_0
  • /data/data/####/a1a0eb390b604316_1
  • /data/data/####/a4db31a5b9d95ede_0
  • /data/data/####/a5cdc8ccd50cf749_0
  • /data/data/####/a681c5c7206bfb57_0
  • /data/data/####/a681c5c7206bfb57_1
  • /data/data/####/a9d56e07f351f496_0
  • /data/data/####/ab1bea372c211567_0
  • /data/data/####/ab5ced6f83c91eb1_0
  • /data/data/####/ab97b97001c6a355_0
  • /data/data/####/abb734c02a26bb51_0
  • /data/data/####/acc87fa3c449dbf6_0
  • /data/data/####/add9b674b59dc9b7_0
  • /data/data/####/aeba38124b1b5d46_0
  • /data/data/####/b088c912433d5779_0
  • /data/data/####/b133b88ee171509b_0
  • /data/data/####/b236916fc3821b36_0
  • /data/data/####/b2575f6ecf380ef9_0
  • /data/data/####/b3128d903b922a4b_0
  • /data/data/####/b3128d903b922a4b_1
  • /data/data/####/b356e5a0ef0a381e_0
  • /data/data/####/b3fe2b8489778804_0
  • /data/data/####/b5964c8ffe7c3d12_0 (deleted)
  • /data/data/####/b82fbbf4f01b2416_0
  • /data/data/####/b84d47cfa3fd736d_0
  • /data/data/####/ba3145df04d10ced_0
  • /data/data/####/bd49ffa69488246a_0
  • /data/data/####/bd9392b2b514a115_0
  • /data/data/####/bdbc1c11fcc1ed1c_0
  • /data/data/####/bdbc1c11fcc1ed1c_1
  • /data/data/####/bfaea5dbf29a07e9_0
  • /data/data/####/c08f10363fecd3e5_0
  • /data/data/####/c14ca00c05ad58f4_0
  • /data/data/####/c18c7ed5326fbd20_0
  • /data/data/####/c19ae617aa2ab5eb_0
  • /data/data/####/c30256ed37b5b2b8_0
  • /data/data/####/c3b7f75ab229848e_0
  • /data/data/####/c5184263db28bf0a_0
  • /data/data/####/c6bb490016567b06_0
  • /data/data/####/c6bb490016567b06_s
  • /data/data/####/c83e75d9202d2bd2_0
  • /data/data/####/c8d57cd2964a8a22_0 (deleted)
  • /data/data/####/ca656a6680c4aea1_0
  • /data/data/####/cd589e3d857b5e56_0
  • /data/data/####/cd6df9bdd189bffb_0
  • /data/data/####/cf4af6e703a8ea6f_0
  • /data/data/####/cf642a5d367ab353_0
  • /data/data/####/cf85bf49bd92311a_0 (deleted)
  • /data/data/####/com.yrg_preferences.xml
  • /data/data/####/d08a77f411bfbce3_0
  • /data/data/####/d14624f00742cf44_0
  • /data/data/####/d2125ea008c8f548_0
  • /data/data/####/d26e7ea5458a253b_0
  • /data/data/####/d3bc5fc6d2861a5d_0
  • /data/data/####/d49281a647c57da6_0
  • /data/data/####/d4e63e6902feb759_0
  • /data/data/####/d53a3157fdc7b7fe_0
  • /data/data/####/d560fbb1c1ec7e0e_0
  • /data/data/####/d560fbb1c1ec7e0e_s
  • /data/data/####/d59ea3c8026be953_0
  • /data/data/####/d62c24efb3754268_0
  • /data/data/####/d7d0b29dec0c04ce_0
  • /data/data/####/d88ad28af52b1ee1_0
  • /data/data/####/d8e73036ad7c9e18_0
  • /data/data/####/d93e992ab540be2a_0
  • /data/data/####/d94884ddf0674398_0
  • /data/data/####/d97ac7dfd2b9e438_0
  • /data/data/####/d98025b30d7c3051_0
  • /data/data/####/d994cd69353c3aba_0
  • /data/data/####/dTQCMuu.dex
  • /data/data/####/dTQCMuu.dex.flock (deleted)
  • /data/data/####/db7aed9237363e91_0
  • /data/data/####/dc144477264c4f2c_0
  • /data/data/####/de32f54c37853f54_0
  • /data/data/####/dfb6d0898b03fa12_0
  • /data/data/####/e06fa67ef6faa210_0
  • /data/data/####/e376e57ab16c1ab4_0
  • /data/data/####/e3da7782931ec491_0
  • /data/data/####/e3da7782931ec491_1
  • /data/data/####/e6b55e6d55a0ebe0_0
  • /data/data/####/e83bffaa4639e53e_0
  • /data/data/####/e8eb80236ce3b384_0
  • /data/data/####/e8ff0abbbf3f304c_0
  • /data/data/####/e9b61f3df4fed675_0
  • /data/data/####/ebb535b041108ed0_0 (deleted)
  • /data/data/####/ebd1bdfb66e8fe4b_0
  • /data/data/####/ebd1bdfb66e8fe4b_1
  • /data/data/####/ee2cfa7c190cc7cf_0
  • /data/data/####/ee2cfa7c190cc7cf_1
  • /data/data/####/eea6d2be0fda024f_0
  • /data/data/####/ef6f52a1e0f2c3bd_0 (deleted)
  • /data/data/####/efd687c859782d02_0
  • /data/data/####/effd37cf07a9b470_0 (deleted)
  • /data/data/####/f4e9e6d00d0f099e_0
  • /data/data/####/f541183115c4e88d_0
  • /data/data/####/f5c650dda24dbecf_0
  • /data/data/####/f6acb2c424fcf957_0
  • /data/data/####/f818e96864db9d92_0
  • /data/data/####/f8d36614af171c8b_0
  • /data/data/####/f92a7fc5ff43cef3_0
  • /data/data/####/fa3ae88a1377781f_0
  • /data/data/####/fb33c0b0ec7683ce_0
  • /data/data/####/fb6b3684ddfb2b99_0
  • /data/data/####/fd0ae33a87d21481_0 (deleted)
  • /data/data/####/fe1168dc43b26411_0
  • /data/data/####/fe1168dc43b26411_s
  • /data/data/####/fee6ef73fdd6723e_0
  • /data/data/####/hrrolQe.dex
  • /data/data/####/hrrolQe.dex.flock (deleted)
  • /data/data/####/index
  • /data/data/####/metrics_guid
  • /data/data/####/ptsfif.dex
  • /data/data/####/the-real-index
  • /data/misc/####/primary.prof
Miscellaneous:
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android