Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.Locker.17995

Added to the Dr.Web virus database: 2024-04-04

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Locker.1477.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(TLS/1.0) 1####.177.14.94:443
  • TCP(TLS/1.0) rr2---s####.g####.com:443
  • TCP(TLS/1.0) digital####.google####.com:443
  • TCP(TLS/1.0) rr4---s####.g####.com:443
  • TCP(TLS/1.0) www.go####.ru:443
  • TCP(TLS/1.0) o####.vk.com:443
  • TCP(TLS/1.0) and####.a####.go####.com:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) cdn1-sm####.ph####.com:443
  • TCP(TLS/1.0) cdn1d-s####.ph####.com:443
  • TCP(TLS/1.0) u####.com:443
  • TCP(TLS/1.0) and####.google####.com:443
  • TCP(TLS/1.0) a####.vk.com:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.0) f####.gst####.com:443
  • TCP(TLS/1.0) analy####.go####.com:443
  • TCP(TLS/1.0) rr9---s####.g####.com:443
  • TCP(TLS/1.0) i####.vk.com:443
  • TCP(TLS/1.0) mc.ya####.ru:443
  • TCP(TLS/1.0) pla####.google####.com:443
  • TCP(TLS/1.0) sun####.use####.com:443
  • TCP(TLS/1.0) www.por####.com:443
  • TCP(TLS/1.0) sto####.google####.com:443
  • TCP(TLS/1.0) s####.g.doublec####.net:443
  • TCP(TLS/1.2) 74.1####.131.100:443
  • TCP(TLS/1.2) 74.1####.131.94:443
  • TCP(TLS/1.2) 1####.177.14.94:443
  • TCP(TLS/1.2) digital####.google####.com:443
  • UDP digital####.google####.com:443
DNS requests:
  • a####.vk.com
  • analy####.go####.com
  • and####.a####.go####.com
  • and####.cli####.go####.com
  • and####.google####.com
  • cdn1-sm####.ph####.com
  • cdn1d-s####.ph####.com
  • digital####.google####.com
  • ei.ph####.com
  • f####.gst####.com
  • gmscomp####.google####.com
  • i####.vk.com
  • l####.vk.com
  • m####.traffic####.net
  • mc.ya####.ru
  • o####.vk.com
  • p####.google####.com
  • pla####.google####.com
  • pla####.googleu####.com
  • rr2---s####.g####.com
  • rr4---s####.g####.com
  • rr9---s####.g####.com
  • s####.g.doublec####.net
  • ss.ph####.com
  • st####.vk.com
  • sto####.google####.com
  • sun####.use####.com
  • u####.com
  • www.go####.com
  • www.go####.ru
  • www.google-####.com
  • www.googlet####.com
  • www.por####.com
File system changes:
Creates the following files:
  • /data/data/####/0009aa2738100947_0
  • /data/data/####/005d2ce6ee2cd37f_0
  • /data/data/####/00b8f7dd06b5077f_0
  • /data/data/####/03350a3d9434aa8c_0
  • /data/data/####/03e3a094c7871985_0
  • /data/data/####/044bb58bb12586f9_0
  • /data/data/####/05802324ba823c16_0 (deleted)
  • /data/data/####/05d3354415927652_0
  • /data/data/####/073ff14153abcb86_0
  • /data/data/####/080228616cfef3d1_0
  • /data/data/####/091770d4d798b659_0
  • /data/data/####/0a0fafc5f6d168c0_0
  • /data/data/####/0a0fafc5f6d168c0_1
  • /data/data/####/0b307bb2d0965b10_0
  • /data/data/####/0b307bb2d0965b10_1
  • /data/data/####/0c53ddf3ba7b0aec_0
  • /data/data/####/0c85cef74cacf52f_0
  • /data/data/####/0d5558a2609e723b_0
  • /data/data/####/0e8f995a9ac4e8ee_0
  • /data/data/####/0f8a23345729b293_0
  • /data/data/####/10ba6a50c9f1f70f_0
  • /data/data/####/11d75f4536d7ed49_0
  • /data/data/####/11d75f4536d7ed49_0 (deleted)
  • /data/data/####/11e6d0c100ef6553_0
  • /data/data/####/11e6d0c100ef6553_0 (deleted)
  • /data/data/####/11e6d0c100ef6553_1
  • /data/data/####/1292e213a9140314_0
  • /data/data/####/1292e213a9140314_1
  • /data/data/####/1329a642da2f1bfb_0
  • /data/data/####/1350f99dcbe03799_0
  • /data/data/####/1350f99dcbe03799_1
  • /data/data/####/13ef06af0160dc86_0
  • /data/data/####/145c14ccb64272cc_0
  • /data/data/####/164fde6a872a0847_0
  • /data/data/####/164fde6a872a0847_1
  • /data/data/####/17bf0bd323751205_0
  • /data/data/####/18c1f4909b620648_0
  • /data/data/####/19f93969b326df96_0
  • /data/data/####/1acc56f59ab0a126_0
  • /data/data/####/1b32d37626ca1ce2_0
  • /data/data/####/1b397839ddfc5955_0
  • /data/data/####/1b9a938177f44483_0
  • /data/data/####/1bbf18d9456f763d_0
  • /data/data/####/1bfc2601552e3bc8_0
  • /data/data/####/1c7cd6f372c85efc_0
  • /data/data/####/1c7cd6f372c85efc_1
  • /data/data/####/1cee7b83026de50d_0
  • /data/data/####/1d41fdf25870c3f2_0
  • /data/data/####/1e2cfa9a45f6cf33_0
  • /data/data/####/1e356e94bb5a13e9_0 (deleted)
  • /data/data/####/1e3b77baae7964e9_0
  • /data/data/####/1e7139b7e75001a9_0
  • /data/data/####/1e7139b7e75001a9_1
  • /data/data/####/1f26191c59d9f7ea_0 (deleted)
  • /data/data/####/1f97f7f5f24b5ee4_0
  • /data/data/####/1fda99d0c2eaf8cb_0
  • /data/data/####/1fda99d0c2eaf8cb_1
  • /data/data/####/20de1d6f5ab9f279_0
  • /data/data/####/234d397fa6340d41_0
  • /data/data/####/234d397fa6340d41_1
  • /data/data/####/24449f8686913b34_0
  • /data/data/####/2707081dee1edb72_0
  • /data/data/####/2940195bd9870d6e_0
  • /data/data/####/2940195bd9870d6e_1
  • /data/data/####/29f3003d38343837_0
  • /data/data/####/2a1ac2855cb07f3c_0
  • /data/data/####/2a1ac2855cb07f3c_0 (deleted)
  • /data/data/####/2c8ab5fabb614ca3_0
  • /data/data/####/2c8ab5fabb614ca3_0 (deleted)
  • /data/data/####/2c8ab5fabb614ca3_1
  • /data/data/####/2cc6e69adb153e05_0
  • /data/data/####/2cc6e69adb153e05_1
  • /data/data/####/2cc80dabc69f58b6_0
  • /data/data/####/2d0da56075aa93fd_0 (deleted)
  • /data/data/####/2e25b5535022d484_0
  • /data/data/####/2fd38243a7946951_0
  • /data/data/####/307bf8d17a297df7_0
  • /data/data/####/31b42fab07a0a649_0
  • /data/data/####/322dfe8ac70a0894_0
  • /data/data/####/331f90a99c54505f_0
  • /data/data/####/33444fc9af9b8014_0 (deleted)
  • /data/data/####/33722cf88a938c86_0
  • /data/data/####/3969730f2df4f8aa_0
  • /data/data/####/3ea4d78ea985ea67_0
  • /data/data/####/433d2ac4129c580c_0
  • /data/data/####/43c5adcef696a48a_0
  • /data/data/####/43c5adcef696a48a_1
  • /data/data/####/4a6d0735747b10b1_0
  • /data/data/####/4a6d0735747b10b1_0 (deleted)
  • /data/data/####/4baac7b2158954a0_0
  • /data/data/####/4cb013792b196a35_0
  • /data/data/####/4cb013792b196a35_1
  • /data/data/####/4d0ae58deeea5e80_0
  • /data/data/####/4e1274997c780cf9_0
  • /data/data/####/4ed0070704a56e97_0
  • /data/data/####/4fbbc0fa890f8837_0
  • /data/data/####/51a3dbab54707e87_0
  • /data/data/####/5273ac1a77ef4c88_0
  • /data/data/####/540ec379d219d622_0
  • /data/data/####/540ec379d219d622_1
  • /data/data/####/5675426d887a623d_0
  • /data/data/####/570ec95f5867cf1b_0 (deleted)
  • /data/data/####/578dc563d363c513_0
  • /data/data/####/578dc563d363c513_1
  • /data/data/####/58246537f2bb0f4e_0
  • /data/data/####/585a99a97f54440c_0
  • /data/data/####/58b30bc08e758eae_0
  • /data/data/####/598a7689569232f7_0
  • /data/data/####/59994183382f1805_0
  • /data/data/####/5b86313417ca7d85_0
  • /data/data/####/5b8b529219f34b11_0
  • /data/data/####/5bdacd5faa117894_0
  • /data/data/####/5c26398721a255fd_0
  • /data/data/####/5c721249efb29f8b_0
  • /data/data/####/5cdf79a1bbfdca83_0
  • /data/data/####/5cf199673ad8f28d_0
  • /data/data/####/5e7c20735551965c_0
  • /data/data/####/5e7c20735551965c_1
  • /data/data/####/5e7cf102bdf4bbbf_0
  • /data/data/####/5f0fd6e4ebb0fadb_0
  • /data/data/####/5f6855c1efcfda9d_0
  • /data/data/####/5f6855c1efcfda9d_1
  • /data/data/####/601f98d205444d2f_0
  • /data/data/####/61566885d84fda31_0
  • /data/data/####/61566885d84fda31_1
  • /data/data/####/61a537e0025801b5_0
  • /data/data/####/62c7a4b13f61aac3_0
  • /data/data/####/64cf3de1ccdc8cc7_0
  • /data/data/####/66f53875ef135f74_0
  • /data/data/####/68159e228a42a009_0
  • /data/data/####/68159e228a42a009_1
  • /data/data/####/69d09e123288e573_0
  • /data/data/####/6b8b5e0624fbff0d_0
  • /data/data/####/6d2b1920660b91a3_0
  • /data/data/####/6d2b1920660b91a3_0 (deleted)
  • /data/data/####/6d8fa8786e2b3505_0
  • /data/data/####/6da0ab2b7b0d1b14_0
  • /data/data/####/6f88078c994800e7_0
  • /data/data/####/6fa1c75808ae4245_0
  • /data/data/####/70b62c8a9396e5a8_0 (deleted)
  • /data/data/####/720eb29b34c8fe43_0
  • /data/data/####/74317f94aa15fca0_0
  • /data/data/####/7688ad4166151327_0
  • /data/data/####/78c68412d2aa9587_0
  • /data/data/####/7b13364cfbb87544_0
  • /data/data/####/7caf9e4f14526c92_0
  • /data/data/####/7df8afbee97fb83a_0
  • /data/data/####/7f0bc66520f06ba6_0
  • /data/data/####/7f406572474261b2_0
  • /data/data/####/7f406572474261b2_1
  • /data/data/####/7fe8d4ddb2321699_0
  • /data/data/####/82b72031f8417c3e_0
  • /data/data/####/82bde2ee0907eec4_0
  • /data/data/####/837eb9b3d2b9cbe8_0
  • /data/data/####/8451c393ae192c8a_0
  • /data/data/####/8555d33f05907af2_0
  • /data/data/####/86749cea5de6da04_0
  • /data/data/####/86749cea5de6da04_0 (deleted)
  • /data/data/####/8888bac454c36fa6_0
  • /data/data/####/8888bac454c36fa6_1
  • /data/data/####/88f3412ea65426c0_0
  • /data/data/####/88fd62bc1f62503f_0
  • /data/data/####/89dac3eee87297a3_0
  • /data/data/####/8b549fd1a0d3bd98_0
  • /data/data/####/8b7cbd5f087b00af_0
  • /data/data/####/8be774a9c223d655_0
  • /data/data/####/8c7af6cc9d01dad8_0
  • /data/data/####/9108717da30fae4b_0
  • /data/data/####/91a41e90cd36d169_0
  • /data/data/####/92b3c0dc238d71ac_0
  • /data/data/####/92f00384b66f754a_0
  • /data/data/####/93b289e14440ed98_0
  • /data/data/####/9402ef73a016ffbb_0
  • /data/data/####/9402ef73a016ffbb_0 (deleted)
  • /data/data/####/94aee15e09161fe2_0
  • /data/data/####/94d5afe0f2ecff9a_0 (deleted)
  • /data/data/####/95cae56d052c205b_0
  • /data/data/####/97d8928f5a8e8521_0
  • /data/data/####/98dc94c9f2743755_0
  • /data/data/####/992a44c9b39a3167_0
  • /data/data/####/992a790b86229dd1_0
  • /data/data/####/992a790b86229dd1_0 (deleted)
  • /data/data/####/9a1bf0afe324c249_0
  • /data/data/####/9a29cfaee1da2c65_0
  • /data/data/####/9a29cfaee1da2c65_1
  • /data/data/####/9a2c76c9883776d3_0
  • /data/data/####/9b44ac27c552226b_0 (deleted)
  • /data/data/####/9b8b8356be03d1e8_0
  • /data/data/####/9c0b6cf9b01f42c1_0
  • /data/data/####/9c0b6cf9b01f42c1_1
  • /data/data/####/9c3d04d65c3a7266_0
  • /data/data/####/9c3d04d65c3a7266_1
  • /data/data/####/9c69027e25fc542c_0
  • /data/data/####/9cc5bfe0a208a74c_0 (deleted)
  • /data/data/####/9d0b22822909b122_0
  • /data/data/####/9d18d7f59ef78062_0
  • /data/data/####/9d9e5c446845272e_0
  • /data/data/####/9debadc9b7b69ebf_0
  • /data/data/####/9ed80db94e551edc_0
  • /data/data/####/9fee0448286141e3_0
  • /data/data/####/BkRMDLQQs.dex
  • /data/data/####/BkRMDLQQs.dex.flock (deleted)
  • /data/data/####/CURRENT
  • /data/data/####/Cookies-journal
  • /data/data/####/Databases.db-journal
  • /data/data/####/MANIFEST-000001
  • /data/data/####/QuotaManager-journal
  • /data/data/####/RCrzAazlFkOpO.dex
  • /data/data/####/RCrzAazlFkOpO.dex (deleted)
  • /data/data/####/RCrzAazlFkOpO.dex.flock (deleted)
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a0cd52a956bfc498_0
  • /data/data/####/a1a0eb390b604316_0
  • /data/data/####/a1a0eb390b604316_1
  • /data/data/####/a2d74e991d6b1289_0 (deleted)
  • /data/data/####/a37b38fae3a3eecf_0
  • /data/data/####/a51785f840e9f0c4_0
  • /data/data/####/a55313f7781ba2d3_0
  • /data/data/####/a55313f7781ba2d3_1
  • /data/data/####/a6eb50552dc91e8b_0
  • /data/data/####/a799eb505b6e23d3_0
  • /data/data/####/a799eb505b6e23d3_1
  • /data/data/####/a7bd07525b82491a_0
  • /data/data/####/a7c8f5689ddb0597_0
  • /data/data/####/a97da596e5214df1_0
  • /data/data/####/a9c3fdb0dbe80f7a_0
  • /data/data/####/aa88e9253c4c929a_0
  • /data/data/####/abc2346775a0c9ee_0
  • /data/data/####/ac538bfdb5450af9_0
  • /data/data/####/aca2dd426caf1d36_0
  • /data/data/####/ad4ff05aec6d989b_0
  • /data/data/####/ad4ff05aec6d989b_0 (deleted)
  • /data/data/####/aeafe34adc808330_0
  • /data/data/####/aeafe34adc808330_0 (deleted)
  • /data/data/####/aeafe34adc808330_1
  • /data/data/####/af3217cc0b1c71a7_0
  • /data/data/####/b1416f5034a7e94f_0
  • /data/data/####/b443dc01d1ec21eb_0
  • /data/data/####/b64c77808b93bff5_0 (deleted)
  • /data/data/####/b7a97a2c9164bb0c_0
  • /data/data/####/b8fc8136dbe01967_0
  • /data/data/####/bdf3ad2ec34e71d2_0
  • /data/data/####/be38d9b78a80bac7_0
  • /data/data/####/be78f16bb6430268_0
  • /data/data/####/be97427b03d8575a_0
  • /data/data/####/bf4343bf9c2135ec_0
  • /data/data/####/bfafee69b2a5c49f_0
  • /data/data/####/bfafee69b2a5c49f_1
  • /data/data/####/c1342ddef36eb86f_0
  • /data/data/####/c1b34f212f26feba_0
  • /data/data/####/c1e9d7cd162720f5_0
  • /data/data/####/c21051760a599957_0
  • /data/data/####/c21051760a599957_1
  • /data/data/####/c267850bf715bd6c_0
  • /data/data/####/c459e03682360c44_0
  • /data/data/####/c57b6524763fe785_0
  • /data/data/####/c648e4e976fb0dc1_0
  • /data/data/####/c66cbcaaca3423e2_0
  • /data/data/####/c66cbcaaca3423e2_0 (deleted)
  • /data/data/####/c7efdd651fdb3793_0
  • /data/data/####/c7efdd651fdb3793_1
  • /data/data/####/c81f9fbe640ddcb3_0
  • /data/data/####/c81f9fbe640ddcb3_1
  • /data/data/####/c84568f3a0056025_0
  • /data/data/####/ca01c626dac3d3b6_0
  • /data/data/####/ca7d520125763a9a_0
  • /data/data/####/cb25c89dda830d30_0
  • /data/data/####/cb25c89dda830d30_1
  • /data/data/####/cba9c646ad404a91_0
  • /data/data/####/ccb6ae163afebfc0_0
  • /data/data/####/ce99954b54aff87b_0
  • /data/data/####/cf49f66da0442e71_0
  • /data/data/####/com.pdg_preferences.xml
  • /data/data/####/d0ab652ce047658c_0
  • /data/data/####/d1c164340c5af8f8_0
  • /data/data/####/d54b8c5585ef57b5_0
  • /data/data/####/d5620f450936b8a7_0
  • /data/data/####/d646c4e5a2117ec8_0
  • /data/data/####/d8dbd033c6fd20fe_0
  • /data/data/####/d9e3358350e75f49_0
  • /data/data/####/dadff8281c59e272_0
  • /data/data/####/db272465fab3fc3e_0
  • /data/data/####/dc5d2e54512c7360_0
  • /data/data/####/dc5d2e54512c7360_1
  • /data/data/####/dd6fdc7cccbceaa5_0
  • /data/data/####/ddd659c9e52b3d3b_0
  • /data/data/####/ddd659c9e52b3d3b_0 (deleted)
  • /data/data/####/de8bbf10deb8ac3c_0 (deleted)
  • /data/data/####/e04ecf0bca57320a_0
  • /data/data/####/e04ecf0bca57320a_0 (deleted)
  • /data/data/####/e0bc0485b8baee67_0
  • /data/data/####/e13982c0d4ecb9a7_0
  • /data/data/####/e13982c0d4ecb9a7_1
  • /data/data/####/e1452b62957896c5_0
  • /data/data/####/e1452b62957896c5_1
  • /data/data/####/e338158aabf30988_0
  • /data/data/####/e3ecefbb85a91ee8_0
  • /data/data/####/e5af8aefe7b8c11e_0
  • /data/data/####/e70e7c8410d18152_0
  • /data/data/####/e812243ad5882a47_0
  • /data/data/####/e833af0d5d78ae38_0
  • /data/data/####/e8ebc48b560e9165_0
  • /data/data/####/e8ebc48b560e9165_1
  • /data/data/####/e96956d50ad6242b_0
  • /data/data/####/ea167296b58305d7_0
  • /data/data/####/ea167296b58305d7_1
  • /data/data/####/eaf651a3da0d3561_0
  • /data/data/####/eaf651a3da0d3561_0 (deleted)
  • /data/data/####/ec3f9ed56b355274_0
  • /data/data/####/ecb8508e90c7c7da_0
  • /data/data/####/ece8a33c1359b06c_0
  • /data/data/####/ed9740e982709b5f_0
  • /data/data/####/effd37cf07a9b470_0 (deleted)
  • /data/data/####/f28a8169613b6b33_0
  • /data/data/####/f5f56a6ce7097b56_0
  • /data/data/####/f5fa9c6556e1c73b_0
  • /data/data/####/f5fa9c6556e1c73b_1
  • /data/data/####/f66190232104951a_0
  • /data/data/####/f66190232104951a_1
  • /data/data/####/f6b4dba6b338e544_0 (deleted)
  • /data/data/####/f8255c9a080b8c64_0
  • /data/data/####/fc9817eb95e72ae2_0
  • /data/data/####/fcf080fe10f43814_0
  • /data/data/####/fdd8cdacf7315389_0
  • /data/data/####/fe675af91fec73af_0
  • /data/data/####/index
  • /data/data/####/mSiCuFI.dex
  • /data/data/####/mSiCuFI.dex.flock (deleted)
  • /data/data/####/metrics_guid
  • /data/data/####/temp-index
  • /data/data/####/the-real-index
  • /data/misc/####/primary.prof
Miscellaneous:
Gets information about network.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android