Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.Siggen.7972

Added to the Dr.Web virus database: 2018-04-19

Virus description added:

Technical information

Malicious functions:
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) mo####.zhu####.s####.com:80
  • TCP(HTTP/1.1) bc.g####.gosu####.com:80
  • TCP(HTTP/1.1) down####.eoema####.com:80
  • TCP(HTTP/1.1) get.s####.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) amdc####.m.ta####.com:80
  • TCP(HTTP/1.1) down####.zhu####.s####.####.com:80
  • TCP(HTTP/1.1) a####.b####.qq.com:8011
  • TCP(HTTP/1.1) q.q####.cn:80
  • TCP(HTTP/1.1) i####.sogo####.com.####.com:80
  • TCP(HTTP/1.1) de####.ping####.zhu####.####.com:80
  • TCP(HTTP/1.1) dl.zhu####.s####.####.com:80
  • TCP(TLS/1.0) msg.umengc####.com:443
  • TCP(TLS/1.0) mo####.zhu####.s####.com:443
  • TCP umengj####.m.ta####.com:443
  • TCP 1####.11.61.106:443
DNS requests:
  • a####.b####.qq.com
  • ag####.m.ta####.com
  • amdc####.m.ta####.com
  • and####.b####.qq.com
  • d####.zhu####.s####.com
  • d2.eoema####.com
  • de####.ping####.zhu####.####.com
  • dl.zhu####.s####.com
  • down####.eoema####.com
  • down####.zhu####.s####.com
  • get.s####.com
  • i####.sogo####.com
  • i####.sogo####.com
  • i####.sogo####.com
  • i####.sogo####.com
  • img.sogo####.com
  • mo####.zhu####.s####.com
  • msg.umengc####.com
  • p####.s####.com
  • q.q####.cn
  • umen####.m.ta####.com
  • umengj####.m.ta####.com
HTTP GET requests:
  • bc.g####.gosu####.com/app0/109/109616/apk/1886137.apk?channel_id=####
  • de####.ping####.zhu####.####.com/?_dv=####&_di=kUr####&_dc=iot####
  • dl.zhu####.s####.####.com/files/year_2018/day_20180128/20180128_bad96d48...
  • down####.eoema####.com/app?id=####&client_id=####&channel_id=####&dn=####
  • down####.zhu####.s####.####.com/focusimage/3a/f2/3af22b914b0b7ca32855d40...
  • i####.sogo####.com.####.com/app/a/100540008/029956794a0458de29479b24e256...
  • i####.sogo####.com.####.com/app/a/100540008/1ce3a53a3ca15bceeca315c35a32...
  • i####.sogo####.com.####.com/app/a/100540008/26630396ff3f9a06bcf5b8e333f8...
  • i####.sogo####.com.####.com/app/a/100540008/28585bed94c81dbd47144ceabdd4...
  • i####.sogo####.com.####.com/app/a/100540008/32eb50a82f5fd30ee147d00efc5e...
  • i####.sogo####.com.####.com/app/a/100540008/34224090419eb89b8574381e2bcc...
  • i####.sogo####.com.####.com/app/a/100540008/39c141fa0caca68a18632be83a44...
  • i####.sogo####.com.####.com/app/a/100540008/3f37c41a4064a7146900eba67e83...
  • i####.sogo####.com.####.com/app/a/100540008/4888616af8568bdff49f9619d891...
  • i####.sogo####.com.####.com/app/a/100540008/4d86bdfb784300c0cc79ec551aad...
  • i####.sogo####.com.####.com/app/a/100540008/5ca626f0aaacaf485b239f7e92a3...
  • i####.sogo####.com.####.com/app/a/100540008/6020a3e4d715e07b71a79b90b1f5...
  • i####.sogo####.com.####.com/app/a/100540008/76265e571b3254c7f64d5c44487a...
  • i####.sogo####.com.####.com/app/a/100540008/86a232c9961dc79354fa76295492...
  • i####.sogo####.com.####.com/app/a/100540008/903e11cb4436fc27961dd567f3a6...
  • i####.sogo####.com.####.com/app/a/100540008/904e26929739dec84b6cb93fdae4...
  • i####.sogo####.com.####.com/app/a/100540008/9e8ab83713074c205b2b93e21781...
  • i####.sogo####.com.####.com/app/a/100540008/a616ea3e789c811a229e434376c2...
  • i####.sogo####.com.####.com/app/a/100540008/d3b01e4c22d3e2f3086a71017e03...
  • i####.sogo####.com.####.com/app/a/100540008/ebe3f0c5701ef1914d26f8b6677e...
  • i####.sogo####.com.####.com/app/a/100540008/ee4723cecd98384e5ce6df11718f...
  • i####.sogo####.com.####.com/app/a/100540008/ffeb069b3889043a7c6c9a916ee3...
  • i####.sogo####.com.####.com/app/a/100540014/1bf3d4e5adcc8a6fb9461cb99f2d...
  • i####.sogo####.com.####.com/app/a/100540014/2de8f8fea1b21491136cad9e2f3d...
  • i####.sogo####.com.####.com/app/a/100540014/62a6d92a21c2afede2d0d9c9fbaa...
  • i####.sogo####.com.####.com/app/a/100540014/7a7aa400a7c9631142114bd074c4...
  • i####.sogo####.com.####.com/app/a/100540014/a2afd4f1971d89c00b0bdb13ba8d...
  • i####.sogo####.com.####.com/app/a/100540020/04152d1949182926fef83e4a3019...
  • i####.sogo####.com.####.com/app/a/100540020/1420f9d00604fa5341cc2910b89e...
  • i####.sogo####.com.####.com/app/a/100540020/17da95e9b3bfcb4437aa27f88974...
  • i####.sogo####.com.####.com/app/a/100540020/193db7240a1603c6e12ad552267b...
  • i####.sogo####.com.####.com/app/a/100540020/26630396ff3f9a06bcf5b8e333f8...
  • i####.sogo####.com.####.com/app/a/100540020/2df9ebec13feaee925ecfbba3462...
  • i####.sogo####.com.####.com/app/a/100540020/31bd72e6734b38bd0cdce4394a7e...
  • i####.sogo####.com.####.com/app/a/100540020/3243dbb4e77a6e29e5b60aab84d0...
  • i####.sogo####.com.####.com/app/a/100540020/32eb50a82f5fd30ee147d00efc5e...
  • i####.sogo####.com.####.com/app/a/100540020/3f37c41a4064a7146900eba67e83...
  • i####.sogo####.com.####.com/app/a/100540020/3fe8a0cb037458682c4932cd3c7c...
  • i####.sogo####.com.####.com/app/a/100540020/47efd1ce855e107fdc9822e74bd7...
  • i####.sogo####.com.####.com/app/a/100540020/4888616af8568bdff49f9619d891...
  • i####.sogo####.com.####.com/app/a/100540020/4ecdd9708644ce19979a2a006980...
  • i####.sogo####.com.####.com/app/a/100540020/54a7541db6f2345e17931c2523b6...
  • i####.sogo####.com.####.com/app/a/100540020/5ef207d552f8390f703422270356...
  • i####.sogo####.com.####.com/app/a/100540020/725aea4b93836bd17c24507b0b5e...
  • i####.sogo####.com.####.com/app/a/100540020/7640b5c91afcaba0734b66e2b6df...
  • i####.sogo####.com.####.com/app/a/100540020/7df9421e0354049048d4eb3f91f0...
  • i####.sogo####.com.####.com/app/a/100540020/83a86695db0b979069d01a07abc2...
  • i####.sogo####.com.####.com/app/a/100540020/8554f3877ca7fdbcb0adc0c74896...
  • i####.sogo####.com.####.com/app/a/100540020/86a232c9961dc79354fa76295492...
  • i####.sogo####.com.####.com/app/a/100540020/8f65c1752acb388548b4810a23e6...
  • i####.sogo####.com.####.com/app/a/100540020/8f8fd4142b5df8e6789f758fbe3b...
  • i####.sogo####.com.####.com/app/a/100540020/9073f72db4870a283ddae7a3ca5b...
  • i####.sogo####.com.####.com/app/a/100540020/958bff04c6669fcd0fa2083e2ced...
  • i####.sogo####.com.####.com/app/a/100540020/973fdf2f30cf13c591b22f4a12b8...
  • i####.sogo####.com.####.com/app/a/100540020/9e517b0ec8e327bfc5c567d25101...
  • i####.sogo####.com.####.com/app/a/100540020/9e8ab83713074c205b2b93e21781...
  • i####.sogo####.com.####.com/app/a/100540020/b2fb308212fa29f724e6fdeba294...
  • i####.sogo####.com.####.com/app/a/100540020/c30736610ad2664fe9cfc3671d36...
  • i####.sogo####.com.####.com/app/a/100540020/c5acc987ad03efed43b16e1ac015...
  • i####.sogo####.com.####.com/app/a/100540020/cb483dcd6c2613f6b0d62e938a2e...
  • i####.sogo####.com.####.com/app/a/100540020/cffd6be60c7848854077c8ee3712...
  • i####.sogo####.com.####.com/app/a/100540020/d9f9b7477412ddbe4374e375fccc...
  • i####.sogo####.com.####.com/app/a/100540020/dd9b65b33595f1a6b567e3f0691c...
  • i####.sogo####.com.####.com/app/a/100540020/e121ddd2552582cd63970dd3d258...
  • i####.sogo####.com.####.com/app/a/100540020/e4e2f16d873fbca9a14f19798859...
  • i####.sogo####.com.####.com/app/a/100540020/edfaa26a54e5dd49309b4e25eb7f...
  • i####.sogo####.com.####.com/app/a/100540020/ffeb069b3889043a7c6c9a916ee3...
  • i####.sogo####.com.####.com/app/a/11220004/01baef197c5ea08b0f5fb59febc09...
  • i####.sogo####.com.####.com/app/a/11220004/027834af8cd73597d0198b3ec4ac1...
  • i####.sogo####.com.####.com/app/a/11220004/0547fefe84be5766688f6eedc521d...
  • i####.sogo####.com.####.com/app/a/11220004/0a35aa1ec2d5af6f6a8ab73d54260...
  • i####.sogo####.com.####.com/app/a/11220004/0a9b038f6064ae2ec3f2c5e07973b...
  • i####.sogo####.com.####.com/app/a/11220004/211774be29b7c5b6d466fdf5f310b...
  • i####.sogo####.com.####.com/app/a/11220004/2e603a7f5b29a479e6848a2546fef...
  • i####.sogo####.com.####.com/app/a/11220004/31e0cc54ab778100d72e9b68de1c8...
  • i####.sogo####.com.####.com/app/a/11220004/3b0d74d8a56e76a269b6f7783d759...
  • i####.sogo####.com.####.com/app/a/11220004/4b73fdb8effbf63ebf0333233d58a...
  • i####.sogo####.com.####.com/app/a/11220004/5a79e4efd20ec5b6790d07358cab9...
  • i####.sogo####.com.####.com/app/a/11220004/5c50cd0149c0749f6560fa9a9981a...
  • i####.sogo####.com.####.com/app/a/11220004/625f7ec338df5360ffb5c202299a6...
  • i####.sogo####.com.####.com/app/a/11220004/66fd2806a8769cc53ad720c0bfeb2...
  • i####.sogo####.com.####.com/app/a/11220004/6b540beaecc2ed371138c3b7e58c9...
  • i####.sogo####.com.####.com/app/a/11220004/746a19b8088b265a60340ea988037...
  • i####.sogo####.com.####.com/app/a/11220004/82143aed9a30d536e1944ab972390...
  • i####.sogo####.com.####.com/app/a/11220004/866bbca7f00f134789809d7a11a13...
  • i####.sogo####.com.####.com/app/a/11220004/881a6a02960f133c709ebe78d4ad5...
  • i####.sogo####.com.####.com/app/a/11220004/8d2593e38f9571956e965f1bdb059...
  • i####.sogo####.com.####.com/app/a/11220004/8d55dad8be873512aeb8aad5f4c82...
  • i####.sogo####.com.####.com/app/a/11220004/953bb612248b57c8901a3971ea579...
  • i####.sogo####.com.####.com/app/a/11220004/a89576eedc5d57e89ed41c32be5ba...
  • i####.sogo####.com.####.com/app/a/11220004/aa61cc53db03f4623600e897fdacd...
  • i####.sogo####.com.####.com/app/a/11220004/b2dd7281b0184a1876e316b337ee2...
  • i####.sogo####.com.####.com/app/a/11220004/b5485f1ba28bd651ae9f79ca91fd8...
  • i####.sogo####.com.####.com/app/a/11220004/b68575c2c9fdc7e89dc06aa58811c...
  • i####.sogo####.com.####.com/app/a/11220004/b930abbd5785a34f35db9e264cbcf...
  • i####.sogo####.com.####.com/app/a/11220004/bee4515b249bea7c67d768f27648b...
  • i####.sogo####.com.####.com/app/a/11220004/c32414f9c3b31308340d82fbbde10...
  • i####.sogo####.com.####.com/app/a/11220004/d0acf4dc53a21081fde010da93fe0...
  • i####.sogo####.com.####.com/app/a/11220004/d2fb5fb271dfe83344029579eb96d...
  • i####.sogo####.com.####.com/app/a/11220004/d3bfeb37cddcc1ef8ae250b3a7ecd...
  • i####.sogo####.com.####.com/app/a/11220004/dd2a4f7937e997702a6df10bd66ae...
  • i####.sogo####.com.####.com/app/a/11220004/dff2bc198c22eab7c5963bf6efec8...
  • i####.sogo####.com.####.com/app/a/11220004/e353f4bbc6d12b0e51fc9cf8072e9...
  • i####.sogo####.com.####.com/app/a/11220004/e378f6c5e9c4bfa6fd68a022fe19f...
  • i####.sogo####.com.####.com/app/a/11220004/eba005bb25438b14bc6983db117e7...
  • i####.sogo####.com.####.com/app/a/11220004/f07d93136ad99ce1c83136a098a17...
  • i####.sogo####.com.####.com/app/a/11220004/ffe076dfda27a01620b37916ecc87...
  • mo####.zhu####.s####.com/android/app/getcomment.html?iv=####&appid=####&...
  • mo####.zhu####.s####.com/android/checkjarupdate.html?uid=####&vn=####&ch...
  • mo####.zhu####.s####.com/android/config/device.html?iv=####&uid=####&vn=...
  • mo####.zhu####.s####.com/android/config/device_entry.html?iv=####&rom=##...
  • mo####.zhu####.s####.com/android/downbind.html?iv=####&etoken=####&token...
  • mo####.zhu####.s####.com/android/download.html?app_id=####&sogouid=####&...
  • mo####.zhu####.s####.com/android/folder/ads/link.html?iv=####&type=####&...
  • mo####.zhu####.s####.com/android/list/relation.html?s=####&iv=####&l=###...
  • mo####.zhu####.s####.com/android/nav/config.html?iv=####&uid=####&vn=###...
  • mo####.zhu####.s####.com/android/navigator.html?iv=####&cg=####&uid=####...
  • mo####.zhu####.s####.com/android/news/channel.html?&uid=####&vn=####&cha...
  • mo####.zhu####.s####.com/android/notify.html?uid=####&vn=####&channel=##...
  • mo####.zhu####.s####.com/android/popup.html?iv=####&gid=####&dpi=####&ui...
  • mo####.zhu####.s####.com/android/rank/toplist.html?id=####&limit=####&gr...
  • mo####.zhu####.s####.com/android/residentRec.html?iv=####&uid=####&vn=##...
  • mo####.zhu####.s####.com/android/serverconfig.html?iv=####&mf=####&on=##...
  • mo####.zhu####.s####.com/android/sosodetail.html?iv=####&sosoid=####&uid...
  • mo####.zhu####.s####.com/android/weather.html?iv=####&bts=####&type=####...
  • mo####.zhu####.s####.com/m/appDetail.html?id=####&iv=####&imei=####&uid=...
  • mo####.zhu####.s####.com/m/author.html?l=####&aid=####&s=####&iv=####&q=...
  • mo####.zhu####.s####.com/m/focus.html?iv=####&tid=####&uid=####&vn=####&...
  • mo####.zhu####.s####.com/m/install.html?iv=####&is_first=####&uid=####&v...
  • mo####.zhu####.s####.com/m/likeApp.html?iv=####&tid=####&uid=####&vn=###...
  • mo####.zhu####.s####.com/m/recommend.html?s=####&token=####&iv=####&c=##...
  • mo####.zhu####.s####.com/misc/root/gets.html?key=####&ret=####&uid=####&...
  • q.q####.cn/qqapp/100294784/7FEC9FB6199339025BB67A54EE40ED97/100
  • q.q####.cn/qqapp/100294784/AFE25EF0C0DC6DF8D8ADA9CB0610D5D7/100
  • q.q####.cn/qqapp/100294784/EE32E8FC581E8DCCA29B37C366E48A36/100
  • q.q####.cn/qqapp/100863168/7F170C77A48FE871240D4A19F6DB87E0/100
  • q.q####.cn/qqapp/100863168/D95A5DC45C0DF5D1A8E6EBA6F2D3627F/100
  • q.q####.cn/qqapp/111111/942FEA70050EEAFBD4DCE2C1FC775E56/100
HTTP POST requests:
  • a####.b####.qq.com:8011/rqd/async
  • amdc####.m.ta####.com/amdc/mobileDispatch?appkey=####&deviceId=####&plat...
  • and####.b####.qq.com/rqd/async
  • get.s####.com/q
  • mo####.zhu####.s####.com/android/app/usercomment.html?iv=####&pn=####&an...
  • mo####.zhu####.s####.com/android/checkapptotal.html?iv=####&sdkversion=#...
  • mo####.zhu####.s####.com/android/checkupdate.html?andid=####
  • mo####.zhu####.s####.com/android/credit/gettask.html?pn=####&andid=####
  • mo####.zhu####.s####.com/android/folder/game/type.html?iv=####&gid=####&...
  • mo####.zhu####.s####.com/android/loadscreen.html?dpi=####&iv=####&uid=##...
  • mo####.zhu####.s####.com/android/updateNotify.html?iv=####&dpi=####&sdkv...
Modified file system:
Creates the following files:
  • /data/data/####/-1187542363-418300586
  • /data/data/####/-1197960752-737457217
  • /data/data/####/-11979607521371856410
  • /data/data/####/-1212145440816787880
  • /data/data/####/-1264443161-418300586
  • /data/data/####/-1367788438816787880
  • /data/data/####/-1395385873943068379
  • /data/data/####/-1398008200-1652148015
  • /data/data/####/-1452697297-137365547
  • /data/data/####/-1452697297-1379035111
  • /data/data/####/-1452697297-168084498
  • /data/data/####/-14526972971872240635
  • /data/data/####/-146747642969172450
  • /data/data/####/-14987793681794790278
  • /data/data/####/-1578119070864233628
  • /data/data/####/-1707433842-1143153521
  • /data/data/####/-1707433842669957691
  • /data/data/####/-1746339038-2059954524
  • /data/data/####/-1749258477912840581
  • /data/data/####/-1749258490625971026
  • /data/data/####/-18706069151695687441
  • /data/data/####/-1962170387-1328637980
  • /data/data/####/-19621703871505568740
  • /data/data/####/-1970197987841812920
  • /data/data/####/-2008844855816787880
  • /data/data/####/-303792729-1459821925
  • /data/data/####/-616505053-186819608
  • /data/data/####/-6165050531101798923
  • /data/data/####/-6165050531387570951
  • /data/data/####/-7168233981245213593
  • /data/data/####/-727463228491519320
  • /data/data/####/-745582236816787880
  • /data/data/####/-766481487-1465872353
  • /data/data/####/-766481487-1504103355
  • /data/data/####/-766481487-1550561079
  • /data/data/####/-766481487-165260068
  • /data/data/####/-766481487-441943201
  • /data/data/####/-766481487-689196242
  • /data/data/####/-7664814871404593948
  • /data/data/####/-7664814871783778880
  • /data/data/####/-7664814871813493578
  • /data/data/####/-76648148740522333
  • /data/data/####/-766481487572171035
  • /data/data/####/-766481487605295112
  • /data/data/####/-76648148761235330
  • /data/data/####/-766481487969119891
  • /data/data/####/-823235554485188709
  • /data/data/####/-8814602701618760556
  • /data/data/####/-911171830-751558606
  • /data/data/####/-9194488361649347330
  • /data/data/####/-9194488401541804658
  • /data/data/####/-919448850-1302225068
  • /data/data/####/1067005471-1083587637
  • /data/data/####/1067005471-1240467643
  • /data/data/####/1067005471-1389116703
  • /data/data/####/1067005471-1450259532
  • /data/data/####/1067005471-2089571649
  • /data/data/####/1067005471-2142130631
  • /data/data/####/1067005471-508934478
  • /data/data/####/1067005471-719579862
  • /data/data/####/10670054711116933942
  • /data/data/####/10670054711197431792
  • /data/data/####/10670054711842551603
  • /data/data/####/10670054711874402806
  • /data/data/####/1067005471354759066
  • /data/data/####/1067005471902182357
  • /data/data/####/1067005472-1373297102
  • /data/data/####/1067005472-1437826579
  • /data/data/####/1067005472-890485686
  • /data/data/####/10670054721022524785
  • /data/data/####/1067005472874922341
  • /data/data/####/1067005473-1206985082
  • /data/data/####/1067005473-1261117741
  • /data/data/####/1067005473-1426690100
  • /data/data/####/1067005473-1427392443
  • /data/data/####/1067005473-1559059175
  • /data/data/####/1067005473-1680864941
  • /data/data/####/1067005473-2103404554
  • /data/data/####/1067005473-2117615099
  • /data/data/####/1067005473-220866662
  • /data/data/####/1067005473-31905033
  • /data/data/####/1067005473-319441846
  • /data/data/####/1067005473-326880457
  • /data/data/####/1067005473-404668285
  • /data/data/####/1067005473-431773751
  • /data/data/####/1067005473-442583552
  • /data/data/####/1067005473-502826239
  • /data/data/####/1067005473-567298229
  • /data/data/####/1067005473-78536816
  • /data/data/####/1067005473-897109966
  • /data/data/####/10670054731146281337
  • /data/data/####/10670054731155165561
  • /data/data/####/10670054731164964155
  • /data/data/####/10670054731231807448
  • /data/data/####/10670054731269421513
  • /data/data/####/10670054731270101354
  • /data/data/####/10670054731434467932
  • /data/data/####/10670054731696872702
  • /data/data/####/10670054731778727831
  • /data/data/####/10670054731808091391
  • /data/data/####/10670054731815454656
  • /data/data/####/10670054731831566611
  • /data/data/####/10670054731908821462
  • /data/data/####/10670054731975306561
  • /data/data/####/10670054732037728577
  • /data/data/####/1067005473676768741
  • /data/data/####/1067005473724652253
  • /data/data/####/1067005473810398055
  • /data/data/####/1067005473813589856
  • /data/data/####/1067005473924237492
  • /data/data/####/1067005473993524422
  • /data/data/####/11199820062094659546
  • /data/data/####/1190131415-1319773466
  • /data/data/####/1293511314-1999935353
  • /data/data/####/146778628740978545
  • /data/data/####/14874618481695687441
  • /data/data/####/1524900164-1999935353
  • /data/data/####/1725560809770397271
  • /data/data/####/1743403315770397271
  • /data/data/####/1755234209-1144423017
  • /data/data/####/1755234209510067521
  • /data/data/####/175786437-35226084
  • /data/data/####/1846205418770397271
  • /data/data/####/1929027641382384656
  • /data/data/####/2034980719-2027816527
  • /data/data/####/21463160251397901333
  • /data/data/####/330806429485188709
  • /data/data/####/402561255485188709
  • /data/data/####/475418017-659928336
  • /data/data/####/7936201921755170144
  • /data/data/####/793620192878169909
  • /data/data/####/998391684-418300586
  • /data/data/####/ACCS_BINDumeng;58eee65d07fe654c91002627.xml
  • /data/data/####/ACCS_SDK.xml
  • /data/data/####/ACCS_SDK.xml (deleted)
  • /data/data/####/ACCS_SDK_CHANNEL.xml
  • /data/data/####/AGOO_BIND.xml
  • /data/data/####/Agoo_AppStore.xml
  • /data/data/####/Alvin2.xml
  • /data/data/####/Badge.Main.xml
  • /data/data/####/ContextData.xml
  • /data/data/####/DaemonServer
  • /data/data/####/MessageStore.db-journal
  • /data/data/####/MsgLogStore.db-journal
  • /data/data/####/NotificationCenter_Pre.xml
  • /data/data/####/PB_SP.xml
  • /data/data/####/PB_SP.xml.bak
  • /data/data/####/PingBackManager_Pre.xml
  • /data/data/####/SGLocSDK.xml
  • /data/data/####/SOGOUPLUS_CONFIG.xml
  • /data/data/####/account.db-journal
  • /data/data/####/accs.db-journal
  • /data/data/####/agoo.pid
  • /data/data/####/androidtool.db-journal
  • /data/data/####/app_config.xml
  • /data/data/####/app_config.xml (deleted)
  • /data/data/####/app_config.xml.bak
  • /data/data/####/app_preference.xml
  • /data/data/####/app_usage.db
  • /data/data/####/app_usage.db-journal
  • /data/data/####/bugly_db_-journal
  • /data/data/####/com.sogou.androidtool.push_service_setting.xml
  • /data/data/####/credit_share_preferences.xml
  • /data/data/####/downloads_classic.db-journal
  • /data/data/####/eudemon
  • /data/data/####/file_log.txt
  • /data/data/####/home_app_n
  • /data/data/####/home_app_p
  • /data/data/####/home_game_n
  • /data/data/####/home_game_p
  • /data/data/####/home_lb_n
  • /data/data/####/home_lb_p
  • /data/data/####/home_sf_n
  • /data/data/####/home_sf_p
  • /data/data/####/localRoot.json
  • /data/data/####/local_crash_lock
  • /data/data/####/location_config.xml
  • /data/data/####/message_accs_db
  • /data/data/####/message_accs_db-journal
  • /data/data/####/nav_app_selected
  • /data/data/####/nav_app_unselected
  • /data/data/####/nav_game_selected
  • /data/data/####/nav_game_unselected
  • /data/data/####/nav_manage_selected
  • /data/data/####/nav_manage_unselected
  • /data/data/####/nav_rank_selected
  • /data/data/####/nav_rank_unselected
  • /data/data/####/nav_select_selected
  • /data/data/####/nav_select_unselected
  • /data/data/####/patchmanage.db
  • /data/data/####/patchmanage.db-journal
  • /data/data/####/pb_db
  • /data/data/####/pb_db-journal
  • /data/data/####/pback
  • /data/data/####/security_info
  • /data/data/####/soso.db
  • /data/data/####/soso.db-journal
  • /data/data/####/sp_notification_permission.xml
  • /data/data/####/tab_config.json
  • /data/data/####/temp
  • /data/data/####/unupdateapp_v2.db
  • /data/data/####/unupdateapp_v2.db-journal
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/webviewCookiesChromiumPrivate.db-journal
  • /data/media/####/.nomedia
  • /data/media/####/.sg_firstlauch.cfg
  • /data/media/####/19763a79628947988d96155bdcf07fc2
  • /data/media/####/720022571dea492abb279ffe9cb9f588
  • /data/media/####/803daa19b7574805b17348ab4a5a06a3
  • /data/media/####/8d6aa1fd22fb4607bbcd5d484aab6b16
  • /data/media/####/Alvin2.xml
  • /data/media/####/ContextData.xml
  • /data/media/####/comMobileTicket170.apk
  • /data/media/####/deviceToken
  • /data/media/####/onehhoneclient88.apk
Miscellaneous:
Executes next shell scripts:
  • /system/bin/sh -c getprop ro.board.platform
  • /system/bin/sh -c type su
  • <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.m.taobao.com/agoo/report -D {"package":"<Package>","appKey":"umeng:58eee65d07fe654c91002627","utdid":"Wtg8mCnlnycDAGdzx1HcJBTj","sdkVersion":"221"} -I agoodm.m.taobao.com -O 80 -T -Z
  • cat /sys/class/net/wlan0/address
  • chmod 500 <Package Folder>/files/DaemonServer
  • chmod 777 <Package Folder>/cache
  • chmod 777 <Package Folder>/files
  • getprop ro.board.platform
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.kernel.qemu
  • getprop ro.miui.ui.version.name
  • getprop ro.smartisan.version
  • getprop ro.vivo.os.version
  • sh
Loads the following dynamic libraries:
  • Bugly
  • diff
  • rutx
  • sogouenc
  • tnet-3.1
  • uninstall
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-ECB-PKCS5Padding
  • AES-GCM-NoPadding
  • DES-CBC-PKCS5Padding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
  • AES-GCM-NoPadding
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about APN settings.
Gains access to information about active device administrators.
Gains access to information about installed applications.
Gains access to information about running applications.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android