Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.BankBot.TgToxic.55

Added to the Dr.Web virus database: 2023-11-23

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.BankBot.TgToxic.1
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) connect####.gst####.com:80
  • TCP(TLS/1.0) rr18---####.g####.com:443
  • TCP(TLS/1.0) 74.1####.131.138:443
  • TCP(TLS/1.0) rr2---s####.g####.com:443
  • TCP(TLS/1.0) connect####.gst####.com:443
  • TCP(TLS/1.0) and####.a####.go####.com:443
  • TCP(TLS/1.0) and####.google####.com:443
  • TCP(TLS/1.0) sqs.ap-nort####.amazo####.com:443
  • TCP(TLS/1.0) p####.google####.com:443
  • TCP(TLS/1.2) 64.2####.165.99:443
  • UDP p####.google####.com:443
DNS requests:
  • and####.a####.go####.com
  • and####.google####.com
  • connect####.gst####.com
  • gmscomp####.google####.com
  • p####.google####.com
  • rr18---####.g####.com
  • rr2---s####.g####.com
  • sqs.ap-nort####.amazo####.com
  • www.google####.com
File system changes:
Creates the following files:
  • /data/data/####/.com_jrmehd_tbkvpiga.meta
  • /data/data/####/12c01a192368454817cc09526b1fad84ts99nb.qpov
  • /data/data/####/12c01a192368454817cc09526b1fad84ts99nb.qpov (deleted)
  • /data/data/####/19
  • /data/data/####/2023-11-23PM022543.str
  • /data/data/####/29
  • /data/data/####/5PPML7CIKWM5V7Z5WH9VNOYUD8ZMC0RK.dex
  • /data/data/####/5PPML7CIKWM5V7Z5WH9VNOYUD8ZMC0RK.dex.flock (deleted)
  • /data/data/####/7XJM4JNIBD4LHC1A29SJT597JGYBE9DD.dex
  • /data/data/####/7XJM4JNIBD4LHC1A29SJT597JGYBE9DD.dex.flock (deleted)
  • /data/data/####/81H5NBWRL4MKMW8QU1VD8MWI5EHP5EL.dex
  • /data/data/####/81H5NBWRL4MKMW8QU1VD8MWI5EHP5EL.dex.flock (deleted)
  • /data/data/####/81H5NBWRL4MKMW8QU1VD8MWI5EHP5EL.zip
  • /data/data/####/9UMM8W1W2TF17XTFBEC2DJ9BEVUYURY.zip
  • /data/data/####/AI6BQ8HF19ZMWSWYPEACW1JFIPWNXP8H.dex
  • /data/data/####/AI6BQ8HF19ZMWSWYPEACW1JFIPWNXP8H.dex.flock (deleted)
  • /data/data/####/B2IH6EK94PMPHJIKJEO7SM6W5JQ2VEFW.dex
  • /data/data/####/B2IH6EK94PMPHJIKJEO7SM6W5JQ2VEFW.dex.flock (deleted)
  • /data/data/####/C2TGBIUJ3ADQ0HURMGCU0ORUG0ETXS1L.dex
  • /data/data/####/C2TGBIUJ3ADQ0HURMGCU0ORUG0ETXS1L.dex.flock (deleted)
  • /data/data/####/CN3EVZPMXMJUIWNXKB5STZZDU8JFOFCD.dex
  • /data/data/####/CN3EVZPMXMJUIWNXKB5STZZDU8JFOFCD.dex.flock (deleted)
  • /data/data/####/H9X2P3OIKWULZ3VHKPLN7OYQ9WN2KKZ4.dex
  • /data/data/####/H9X2P3OIKWULZ3VHKPLN7OYQ9WN2KKZ4.dex.flock (deleted)
  • /data/data/####/IECPkgStoreInfo
  • /data/data/####/J10JIXXEQ5GHZ8HA5BVTJF2LFB18CFOC.dex
  • /data/data/####/J10JIXXEQ5GHZ8HA5BVTJF2LFB18CFOC.dex.flock (deleted)
  • /data/data/####/J2YHI6GP0XU5LFIW7IOJCMQ81BU2ZARS.dex
  • /data/data/####/J2YHI6GP0XU5LFIW7IOJCMQ81BU2ZARS.dex.flock (deleted)
  • /data/data/####/J94FED5AMXKHV0HE1Z3977QTNZDO4NSK.dex
  • /data/data/####/J94FED5AMXKHV0HE1Z3977QTNZDO4NSK.dex.flock (deleted)
  • /data/data/####/JXK7Q5TU618H7CPMLFZ1VBEPBFPG0B8G.dex
  • /data/data/####/JXK7Q5TU618H7CPMLFZ1VBEPBFPG0B8G.dex.flock (deleted)
  • /data/data/####/K199BN0RH0U0Y04EATF5CAO29UXHL69.dex
  • /data/data/####/K199BN0RH0U0Y04EATF5CAO29UXHL69.dex.flock (deleted)
  • /data/data/####/K199BN0RH0U0Y04EATF5CAO29UXHL69.zip
  • /data/data/####/KXTTV7ORTCA8Y40EUXBDGUWIXI1L9UP.dex
  • /data/data/####/KXTTV7ORTCA8Y40EUXBDGUWIXI1L9UP.dex.flock (deleted)
  • /data/data/####/KXTTV7ORTCA8Y40EUXBDGUWIXI1L9UP.zip
  • /data/data/####/LAYUW8TWALJPJ5L3BUS2L79R6ZEUY7M.dex
  • /data/data/####/LAYUW8TWALJPJ5L3BUS2L79R6ZEUY7M.dex.flock (deleted)
  • /data/data/####/LAYUW8TWALJPJ5L3BUS2L79R6ZEUY7M.zip
  • /data/data/####/NAQHUISHK1IX1ZI0V6ONKMQKDFAUNUB4.dex
  • /data/data/####/NAQHUISHK1IX1ZI0V6ONKMQKDFAUNUB4.dex.flock (deleted)
  • /data/data/####/P9DATNKIWWYTFFFPCL57VOMY50FMC834.dex
  • /data/data/####/P9DATNKIWWYTFFFPCL57VOMY50FMC834.dex.flock (deleted)
  • /data/data/####/QKAHBM61UGJ4WB85L4FQK88QIBDE5G4W.dex
  • /data/data/####/SU8B2CJO426LD2SKLFM7WBJNG7SEDBT.dex
  • /data/data/####/SU8B2CJO426LD2SKLFM7WBJNG7SEDBT.dex.flock (deleted)
  • /data/data/####/SU8B2CJO426LD2SKLFM7WBJNG7SEDBT.zip
  • /data/data/####/TNDS3XOT5BF2I3D92C3CH8GWP45NIO6.dex
  • /data/data/####/TNDS3XOT5BF2I3D92C3CH8GWP45NIO6.dex.flock (deleted)
  • /data/data/####/TNDS3XOT5BF2I3D92C3CH8GWP45NIO6.zip
  • /data/data/####/TRTS3DGTTZZEIZX9IO74D88G101JU0Q.dex
  • /data/data/####/TRTS3DGTTZZEIZX9IO74D88G101JU0Q.dex.flock (deleted)
  • /data/data/####/TRTS3DGTTZZEIZX9IO74D88G101JU0Q.zip
  • /data/data/####/VDB60NBYBDWLXG5YE1GR959BNSAVQ5LT.dex
  • /data/data/####/VDB60NBYBDWLXG5YE1GR959BNSAVQ5LT.dex.flock (deleted)
  • /data/data/####/WH5HJZSRP8Y4A8W2UPB54Y4I1YHDPMX.dex
  • /data/data/####/WH5HJZSRP8Y4A8W2UPB54Y4I1YHDPMX.dex.flock (deleted)
  • /data/data/####/WH5HJZSRP8Y4A8W2UPB54Y4I1YHDPMX.zip
  • /data/data/####/X285PAU56IG9KOL4DNNFBB4SG0WZ2N2S.dex
  • /data/data/####/X285PAU56IG9KOL4DNNFBB4SG0WZ2N2S.dex.flock (deleted)
  • /data/data/####/XP9YH7GI8WIHFBZX41PBJOAM147MKW7K.dex
  • /data/data/####/XP9YH7GI8WIHFBZX41PBJOAM147MKW7K.dex.flock (deleted)
  • /data/data/####/XUGP9MEDI20XOK1WX3NNNB8CK4KR2ZAW.dex
  • /data/data/####/XUGP9MEDI20XOK1WX3NNNB8CK4KR2ZAW.dex.flock (deleted)
  • /data/data/####/Y9NSOHO6OXEUHDVAOOD19JWIPGFTVWV9.dex
  • /data/data/####/Y9NSOHO6OXEUHDVAOOD19JWIPGFTVWV9.dex.flock (deleted)
  • /data/data/####/YPZSKTKUS9YUDH3YWWLD9VWML8F5FS7X.dex
  • /data/data/####/YPZSKTKUS9YUDH3YWWLD9VWML8F5FS7X.dex.flock (deleted)
  • /data/data/####/Z5O3MLHQ2TWH3496X3NHJ32XJJ1WSJCO.dex
  • /data/data/####/Z5O3MLHQ2TWH3496X3NHJ32XJJ1WSJCO.dex.flock (deleted)
  • /data/data/####/ZAAXIAWHODAHHJION2OB0M68X76UJYZ8.dex
  • /data/data/####/ZAAXIAWHODAHHJION2OB0M68X76UJYZ8.dex.flock (deleted)
  • /data/data/####/com.android.launcher3.prefs.xml
  • /data/data/####/empty_classes.dex
  • /data/data/####/empty_classes.zip
  • /data/data/####/proc_auxv
  • /data/data/####/sealeh.bdc
  • /data/data/####/spUtils.xml
  • /data/data/####/working
Miscellaneous:
Executes the following shell scripts:
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/81H5NBWRL4MKMW8QU1VD8MWI5EHP5EL.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/K199BN0RH0U0Y04EATF5CAO29UXHL69.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/KXTTV7ORTCA8Y40EUXBDGUWIXI1L9UP.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/LAYUW8TWALJPJ5L3BUS2L79R6ZEUY7M.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/TNDS3XOT5BF2I3D92C3CH8GWP45NIO6.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/TRTS3DGTTZZEIZX9IO74D88G101JU0Q.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/WH5HJZSRP8Y4A8W2UPB54Y4I1YHDPMX.zip
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/5PPML7CIKWM5V7Z5WH9VNOYUD8ZMC0RK.dex --oat-file=/data/user/0/<Package>/cache/<Package>/5PPML7CIKWM5V7Z5WH9VNOYUD8ZMC0RK.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/7XJM4JNIBD4LHC1A29SJT597JGYBE9DD.dex --oat-file=/data/user/0/<Package>/cache/<Package>/7XJM4JNIBD4LHC1A29SJT597JGYBE9DD.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/AI6BQ8HF19ZMWSWYPEACW1JFIPWNXP8H.dex --oat-file=/data/user/0/<Package>/cache/<Package>/AI6BQ8HF19ZMWSWYPEACW1JFIPWNXP8H.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/B2IH6EK94PMPHJIKJEO7SM6W5JQ2VEFW.dex --oat-file=/data/user/0/<Package>/cache/<Package>/B2IH6EK94PMPHJIKJEO7SM6W5JQ2VEFW.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/C2TGBIUJ3ADQ0HURMGCU0ORUG0ETXS1L.dex --oat-file=/data/user/0/<Package>/cache/<Package>/C2TGBIUJ3ADQ0HURMGCU0ORUG0ETXS1L.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/CN3EVZPMXMJUIWNXKB5STZZDU8JFOFCD.dex --oat-file=/data/user/0/<Package>/cache/<Package>/CN3EVZPMXMJUIWNXKB5STZZDU8JFOFCD.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/H9X2P3OIKWULZ3VHKPLN7OYQ9WN2KKZ4.dex --oat-file=/data/user/0/<Package>/cache/<Package>/H9X2P3OIKWULZ3VHKPLN7OYQ9WN2KKZ4.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/J10JIXXEQ5GHZ8HA5BVTJF2LFB18CFOC.dex --oat-file=/data/user/0/<Package>/cache/<Package>/J10JIXXEQ5GHZ8HA5BVTJF2LFB18CFOC.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/J2YHI6GP0XU5LFIW7IOJCMQ81BU2ZARS.dex --oat-file=/data/user/0/<Package>/cache/<Package>/J2YHI6GP0XU5LFIW7IOJCMQ81BU2ZARS.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/J94FED5AMXKHV0HE1Z3977QTNZDO4NSK.dex --oat-file=/data/user/0/<Package>/cache/<Package>/J94FED5AMXKHV0HE1Z3977QTNZDO4NSK.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/JXK7Q5TU618H7CPMLFZ1VBEPBFPG0B8G.dex --oat-file=/data/user/0/<Package>/cache/<Package>/JXK7Q5TU618H7CPMLFZ1VBEPBFPG0B8G.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/NAQHUISHK1IX1ZI0V6ONKMQKDFAUNUB4.dex --oat-file=/data/user/0/<Package>/cache/<Package>/NAQHUISHK1IX1ZI0V6ONKMQKDFAUNUB4.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/P9DATNKIWWYTFFFPCL57VOMY50FMC834.dex --oat-file=/data/user/0/<Package>/cache/<Package>/P9DATNKIWWYTFFFPCL57VOMY50FMC834.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/QKAHBM61UGJ4WB85L4FQK88QIBDE5G4W.dex --oat-file=/data/user/0/<Package>/cache/<Package>/QKAHBM61UGJ4WB85L4FQK88QIBDE5G4W.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/VDB60NBYBDWLXG5YE1GR959BNSAVQ5LT.dex --oat-file=/data/user/0/<Package>/cache/<Package>/VDB60NBYBDWLXG5YE1GR959BNSAVQ5LT.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/X285PAU56IG9KOL4DNNFBB4SG0WZ2N2S.dex --oat-file=/data/user/0/<Package>/cache/<Package>/X285PAU56IG9KOL4DNNFBB4SG0WZ2N2S.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/XP9YH7GI8WIHFBZX41PBJOAM147MKW7K.dex --oat-file=/data/user/0/<Package>/cache/<Package>/XP9YH7GI8WIHFBZX41PBJOAM147MKW7K.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/XUGP9MEDI20XOK1WX3NNNB8CK4KR2ZAW.dex --oat-file=/data/user/0/<Package>/cache/<Package>/XUGP9MEDI20XOK1WX3NNNB8CK4KR2ZAW.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/Y9NSOHO6OXEUHDVAOOD19JWIPGFTVWV9.dex --oat-file=/data/user/0/<Package>/cache/<Package>/Y9NSOHO6OXEUHDVAOOD19JWIPGFTVWV9.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/YPZSKTKUS9YUDH3YWWLD9VWML8F5FS7X.dex --oat-file=/data/user/0/<Package>/cache/<Package>/YPZSKTKUS9YUDH3YWWLD9VWML8F5FS7X.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/Z5O3MLHQ2TWH3496X3NHJ32XJJ1WSJCO.dex --oat-file=/data/user/0/<Package>/cache/<Package>/Z5O3MLHQ2TWH3496X3NHJ32XJJ1WSJCO.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/ZAAXIAWHODAHHJION2OB0M68X76UJYZ8.dex --oat-file=/data/user/0/<Package>/cache/<Package>/ZAAXIAWHODAHHJION2OB0M68X76UJYZ8.dex --compiler-filter=verify-none --instruction-set=x86
  • getprop ro.dalvik.vm.isa.arm
  • getprop ro.dalvik.vm.isa.arm64
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/5PPML7CIKWM5V7Z5WH9VNOYUD8ZMC0RK.dex --oat-file=/data/user/0/<Package>/cache/<Package>/5PPML7CIKWM5V7Z5WH9VNOYUD8ZMC0RK.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/7XJM4JNIBD4LHC1A29SJT597JGYBE9DD.dex --oat-file=/data/user/0/<Package>/cache/<Package>/7XJM4JNIBD4LHC1A29SJT597JGYBE9DD.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/AI6BQ8HF19ZMWSWYPEACW1JFIPWNXP8H.dex --oat-file=/data/user/0/<Package>/cache/<Package>/AI6BQ8HF19ZMWSWYPEACW1JFIPWNXP8H.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/B2IH6EK94PMPHJIKJEO7SM6W5JQ2VEFW.dex --oat-file=/data/user/0/<Package>/cache/<Package>/B2IH6EK94PMPHJIKJEO7SM6W5JQ2VEFW.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/C2TGBIUJ3ADQ0HURMGCU0ORUG0ETXS1L.dex --oat-file=/data/user/0/<Package>/cache/<Package>/C2TGBIUJ3ADQ0HURMGCU0ORUG0ETXS1L.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/CN3EVZPMXMJUIWNXKB5STZZDU8JFOFCD.dex --oat-file=/data/user/0/<Package>/cache/<Package>/CN3EVZPMXMJUIWNXKB5STZZDU8JFOFCD.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/H9X2P3OIKWULZ3VHKPLN7OYQ9WN2KKZ4.dex --oat-file=/data/user/0/<Package>/cache/<Package>/H9X2P3OIKWULZ3VHKPLN7OYQ9WN2KKZ4.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/J10JIXXEQ5GHZ8HA5BVTJF2LFB18CFOC.dex --oat-file=/data/user/0/<Package>/cache/<Package>/J10JIXXEQ5GHZ8HA5BVTJF2LFB18CFOC.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/J2YHI6GP0XU5LFIW7IOJCMQ81BU2ZARS.dex --oat-file=/data/user/0/<Package>/cache/<Package>/J2YHI6GP0XU5LFIW7IOJCMQ81BU2ZARS.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/J94FED5AMXKHV0HE1Z3977QTNZDO4NSK.dex --oat-file=/data/user/0/<Package>/cache/<Package>/J94FED5AMXKHV0HE1Z3977QTNZDO4NSK.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/JXK7Q5TU618H7CPMLFZ1VBEPBFPG0B8G.dex --oat-file=/data/user/0/<Package>/cache/<Package>/JXK7Q5TU618H7CPMLFZ1VBEPBFPG0B8G.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/NAQHUISHK1IX1ZI0V6ONKMQKDFAUNUB4.dex --oat-file=/data/user/0/<Package>/cache/<Package>/NAQHUISHK1IX1ZI0V6ONKMQKDFAUNUB4.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/P9DATNKIWWYTFFFPCL57VOMY50FMC834.dex --oat-file=/data/user/0/<Package>/cache/<Package>/P9DATNKIWWYTFFFPCL57VOMY50FMC834.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/QKAHBM61UGJ4WB85L4FQK88QIBDE5G4W.dex --oat-file=/data/user/0/<Package>/cache/<Package>/QKAHBM61UGJ4WB85L4FQK88QIBDE5G4W.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/VDB60NBYBDWLXG5YE1GR959BNSAVQ5LT.dex --oat-file=/data/user/0/<Package>/cache/<Package>/VDB60NBYBDWLXG5YE1GR959BNSAVQ5LT.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/X285PAU56IG9KOL4DNNFBB4SG0WZ2N2S.dex --oat-file=/data/user/0/<Package>/cache/<Package>/X285PAU56IG9KOL4DNNFBB4SG0WZ2N2S.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/XP9YH7GI8WIHFBZX41PBJOAM147MKW7K.dex --oat-file=/data/user/0/<Package>/cache/<Package>/XP9YH7GI8WIHFBZX41PBJOAM147MKW7K.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/XUGP9MEDI20XOK1WX3NNNB8CK4KR2ZAW.dex --oat-file=/data/user/0/<Package>/cache/<Package>/XUGP9MEDI20XOK1WX3NNNB8CK4KR2ZAW.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/Y9NSOHO6OXEUHDVAOOD19JWIPGFTVWV9.dex --oat-file=/data/user/0/<Package>/cache/<Package>/Y9NSOHO6OXEUHDVAOOD19JWIPGFTVWV9.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/YPZSKTKUS9YUDH3YWWLD9VWML8F5FS7X.dex --oat-file=/data/user/0/<Package>/cache/<Package>/YPZSKTKUS9YUDH3YWWLD9VWML8F5FS7X.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/Z5O3MLHQ2TWH3496X3NHJ32XJJ1WSJCO.dex --oat-file=/data/user/0/<Package>/cache/<Package>/Z5O3MLHQ2TWH3496X3NHJ32XJJ1WSJCO.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/ZAAXIAWHODAHHJION2OB0M68X76UJYZ8.dex --oat-file=/data/user/0/<Package>/cache/<Package>/ZAAXIAWHODAHHJION2OB0M68X76UJYZ8.dex --compiler-filter=verify-none --instruction-set=x86
Loads the following dynamic libraries:
  • libcovault-appsec
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about installed apps.
Intercepts notifications.
Requests the system alert window permission.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android