Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.Triada.5131

Added to the Dr.Web virus database: 2021-11-02

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Click.311.origin
  • Android.DownLoader.1007.origin
  • Android.DownLoader.1051.origin
  • Android.DownLoader.981.origin
  • Android.Mobifun.30.origin
  • Android.Packed.55438
  • Android.RemoteCode.231.origin
  • Android.RemoteCode.319.origin
  • Android.Triada.4567
  • Android.Triada.5071
  • Android.Triada.510.origin
  • Android.Triada.537.origin
  • Android.Triada.573.origin
Threat detection based on machine learning.
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) z.c####.com:80
  • TCP(HTTP/1.1) cdn.pop####.net:80
  • TCP(HTTP/1.1) api.bi####.com:80
  • TCP(HTTP/1.1) y####.k8####.com:80
  • TCP(HTTP/1.1) sdk-eve####.ap-sout####.log.####.com:80
  • TCP(HTTP/1.1) geo.appclic####.com:80
  • TCP(HTTP/1.1) p####.pay####.com:80
  • TCP(HTTP/1.1) gc4####.9####.com:80
  • TCP(HTTP/1.1) jz####.mc####.com:12029
  • TCP(HTTP/1.1) www.variety####.com:80
  • TCP(HTTP/1.1) ro####.infol####.com:80
  • TCP(HTTP/1.1) www.d####.xyz:80
  • TCP(HTTP/1.1) cdn.vig####.com:80
  • TCP(HTTP/1.1) t####.c8####.com:13002
  • TCP(HTTP/1.1) d.moce####.com:80
  • TCP(HTTP/1.1) fung####.ly####.com:80
  • TCP(HTTP/1.1) api.applove####.com:80
  • TCP(HTTP/1.1) 1####.128.85.140:80
  • TCP(HTTP/1.1) u.y####.com:80
  • TCP(HTTP/1.1) hw9####.new####.com:80
  • TCP(HTTP/1.1) s####.appclic####.com:80
  • TCP(HTTP/1.1) d####.dd7####.com:80
  • TCP(HTTP/1.1) www-bin####.dual-a-####.a-ms####.net:80
  • TCP(HTTP/1.1) s####.b####.com:80
  • TCP(HTTP/1.1) h####.app####.com:80
  • TCP(HTTP/1.1) d.moce####.com:9091
  • TCP(HTTP/1.1) sdk.appclic####.com:80
  • TCP(HTTP/1.1) ga_####.appclic####.com:80
  • TCP(HTTP/1.1) z4####.ep####.com:14002
  • TCP(HTTP/1.1) a####.r####.com:13002
  • TCP(TLS/1.0) c####.pay####.com:443
  • TCP(TLS/1.0) rgk.zu####.cn:443
  • TCP(TLS/1.0) de.t####.com:443
  • TCP(TLS/1.0) imagesy####.pubm####.com:443
  • TCP(TLS/1.0) 5.ah####.com:443
  • TCP(TLS/1.0) fo####.site:443
  • TCP(TLS/1.0) u.o####.net:443
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.0) s####.1rx.io:443
  • TCP(TLS/1.0) api.vig####.com:443
  • TCP(TLS/1.0) d####.pop####.net:443
  • TCP(TLS/1.0) p####.ups-a####.aolp-ds####.####.cloud:443
  • TCP(TLS/1.0) gd.a.s####.com:443
  • TCP(TLS/1.0) onetag####.com:443
  • TCP(TLS/1.0) ssc####.33ac####.com:443
  • TCP(TLS/1.0) g.geo####.com:443
  • TCP(TLS/1.0) ro####.infol####.com:443
  • TCP(TLS/1.0) packag####.oss-ap-####.aliy####.com:443
  • TCP(TLS/1.0) 1####.194.220.95:443
  • TCP(TLS/1.0) s.c####.to:443
  • TCP(TLS/1.0) b1####.zem####.com:443
  • TCP(TLS/1.0) hcap####.com:443
  • TCP(TLS/1.0) s####.go.so####.com:443
  • TCP(TLS/1.0) android####.go####.com:443
  • TCP(TLS/1.0) m####.ad####.org:443
  • TCP(TLS/1.0) m####.b####.com:443
  • TCP(TLS/1.0) dsp.adke####.com:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) wcf.seven####.com:443
  • TCP(TLS/1.0) ssum####.casalem####.com.####.net:443
  • TCP(TLS/1.0) jsc.adske####.com:443
  • TCP(TLS/1.0) a.rf####.com.####.net:443
  • TCP(TLS/1.0) e####.vap.l####.com:443
  • TCP(TLS/1.0) s####.appclic####.com:443
  • TCP(TLS/1.0) 74.1####.205.95:443
  • TCP(TLS/1.0) p####.ups####.aolp-ds####.####.cloud:443
  • TCP(TLS/1.2) 1####.194.220.95:443
  • TCP(TLS/1.2) 64.2####.164.101:443
  • TCP(TLS/1.2) 74.1####.205.139:443
  • TCP(TLS/1.2) 74.1####.131.94:443
  • UDP 74.1####.131.95:443
  • UDP 1####.194.220.95:443
DNS requests:
  • 5.ah####.com
  • a####.r####.com
  • android####.go####.com
  • ap.l####.com
  • api.applove####.com
  • api.bi####.com
  • api.vig####.com
  • b1####.zem####.com
  • c####.pay####.com
  • cdn.pop####.net
  • cdn.vig####.com
  • d####.dd7####.com
  • d####.pop####.net
  • d.moce####.com
  • de.t####.com
  • dsp.adke####.com
  • dwq.fs####.com
  • fo####.site
  • fung####.ly####.com
  • ga_####.appclic####.com
  • gc4####.9####.com
  • geo.appclic####.com
  • h####.app####.com
  • h5s####.com
  • hcap####.com
  • hw9####.new####.com
  • ib.a####.com
  • im####.pubm####.com
  • jsc.adske####.com
  • jz####.mc####.com
  • m####.ad####.org
  • m####.b####.com
  • m####.go####.com
  • newas####.hcap####.com
  • nu####.js####.com
  • onetag####.com
  • p####.adverti####.com
  • p####.pay####.com
  • p.cli####.net
  • p.rf####.com
  • packag####.oss-ap-####.aliy####.com
  • pv.s####.com
  • resou####.infol####.com
  • rgk.zu####.cn
  • ro####.infol####.com
  • s####.1rx.io
  • s####.appclic####.com
  • s####.b####.com
  • s####.go.so####.com
  • s.c####.to
  • sdk-eve####.ap-sout####.log.####.com
  • sdk.appclic####.com
  • ssc####.33ac####.com
  • ssum####.casalem####.com
  • t####.c8####.com
  • u.o####.net
  • u.y####.com
  • ups.analy####.y####.com
  • wcf.seven####.com
  • web-eve####.ap-sout####.log.####.com
  • www.b####.com
  • www.d####.xyz
  • www.google-####.com
  • www.googlet####.com
  • www.h5s####.com
  • www.variety####.com
  • y####.k8####.com
  • z4####.ep####.com
  • z9.c####.com
HTTP GET requests:
  • 5.ah####.com:443/thirdsdk/flowcashpack/123/TK-209a-202106251800d
  • 5.ah####.com:443/thirdsdk/flowcashpack/160/num-29072a-202110251610d
  • 5.ah####.com:443/thirdsdk/flowcashpack/82/MF-1.19a-202104301548d
  • api.applove####.com/api/v3/cache/get?osv=####&srnc=####&token=####&ds=##...
  • api.applove####.com/api/v3/template/get?slot_id=####&update_time=####&us...
  • cdn.pop####.net/show.js
  • cdn.vig####.com/api/vglnk.js
  • d####.dd7####.com/upload/hw/batdex20191010.jar
  • d####.dd7####.com/upload/hw/c1005dex20190527.jar
  • d####.dd7####.com/upload/hw/h5rq20191022.jar
  • d####.dd7####.com/upload/hw/kklz02dex20200414.jar
  • d####.dd7####.com/upload/hw/lsdk20200506.jar
  • d####.dd7####.com/upload/hw/mf20200508.jar
  • d####.dd7####.com/upload/hw/qcdex20200316.jar
  • d####.dd7####.com/upload/plog/cy1028.jar
  • d####.dd7####.com/upload/plog/djso1101.jar
  • d####.dd7####.com/upload/plog/hx0409.jar
  • d####.dd7####.com/upload/plog/jar20190515.jar
  • d####.dd7####.com/upload/plog/jrw20210630.jar
  • d####.dd7####.com/upload/plog/kk20201106.jar
  • d####.dd7####.com/upload/plog/ps20210219.jar
  • d####.dd7####.com/upload/plog/sdk0625.jar
  • d####.dd7####.com/upload/plog/sh290_20210810.jar
  • d####.dd7####.com/upload/plog/skk20210416.jar
  • d####.dd7####.com/upload/plog/xianmm0512.jar
  • d####.dd7####.com/upload/plog/yeah0510.jar
  • fo####.site:443/ewewew/s20211101220628.1
  • fung####.ly####.com/cdn-cgi/challenge-platform/h/b/orchestrate/managed/v...
  • fung####.ly####.com/cdn-cgi/images/browser-bar.png?137675####
  • fung####.ly####.com/cdn-cgi/images/cf-no-screenshot-warn.png
  • fung####.ly####.com/cdn-cgi/images/trace/captcha/nojs/h/transparent.gif?...
  • fung####.ly####.com/cdn-cgi/images/trace/managed/js/transparent.gif?ray=...
  • fung####.ly####.com/cdn-cgi/styles/cf.errors.css
  • fung####.ly####.com/favicon.ico
  • fung####.ly####.com/lym07ly09
  • ga_####.appclic####.com/ad/user_model.js?time=####
  • ga_####.appclic####.com/favicon.ico
  • ga_####.appclic####.com/list.html?list=####&user=####&uuid=####&app=####...
  • ga_####.appclic####.com/style/css/list.css
  • ga_####.appclic####.com/style/css/public.min.css
  • ga_####.appclic####.com/style/js/jquery-3.1.1.min.js
  • ga_####.appclic####.com/style/js/jquery.mmenu.all.js
  • ga_####.appclic####.com/style/js/main.js
  • ga_####.appclic####.com/style/js/swiper.min.css
  • ga_####.appclic####.com/style/js/swiper.min.js
  • gc4####.9####.com/zsyunsxda
  • gc4####.9####.com/zsyunsxda/
  • gd.a.s####.com:443/cityjson
  • geo.appclic####.com/
  • h####.app####.com/allgame/ICON/wjzz/icon160.jpg
  • h####.app####.com/allgame/ICON/zhengfuyinhe/icon160.jpg
  • p####.pay####.com/s-r/332/60063a81055a8
  • packag####.oss-ap-####.aliy####.com:443/Ipv2_20211009/Ipv2_20211009_2
  • packag####.oss-ap-####.aliy####.com:443/browser_lada_20210507/browser_la...
  • packag####.oss-ap-####.aliy####.com:443/device_info/device_info_20210722
  • packag####.oss-ap-####.aliy####.com:443/js_browser_0312/js_browser_0312_...
  • packag####.oss-ap-####.aliy####.com:443/js_htp_20210604/js_htp_20210604_2
  • packag####.oss-ap-####.aliy####.com:443/js_soa_2/js_soa_2_20210926
  • packag####.oss-ap-####.aliy####.com:443/js_testpoca/js_testpoca_20210205
  • packag####.oss-ap-####.aliy####.com:443/js_wpn/js_wpn_20210412
  • packag####.oss-ap-####.aliy####.com:443/js_yy/js_yy_20210830
  • packag####.oss-ap-####.aliy####.com:443/js_yynews_2_20211026/js_yynews_2...
  • packag####.oss-ap-####.aliy####.com:443/stg/stg_201119
  • packag####.oss-ap-####.aliy####.com:443/test_inner/inner_20210804
  • ro####.infol####.com/gsd?evt=afterGSD&pid=3288809&wsid=0&pdom=www.h5sgam...
  • ro####.infol####.com/js/1763.004-3.025/icemobile.js
  • ro####.infol####.com/js/infolinks_main.js
  • s####.appclic####.com/stg?channel=####&sdk=####
  • s####.appclic####.com:443/stg?channel=####&sdk=####
  • s####.b####.com/redirect?s=####&at=####&rt=####&s1=####
  • sdk-eve####.ap-sout####.log.####.com/logstores/web-ads/track?APIVersion=...
  • sdk.appclic####.com/check?channel=####&geo=####
  • www-bin####.dual-a-####.a-ms####.net/
  • www.variety####.com/f7220841d4f3911b2e5cf8e8ae6fe5e2/invoke.js
  • y####.k8####.com/cocoDY/app-5329125.zip
  • y####.k8####.com/dtbx/liangzong/hwlz06.zip
  • y####.k8####.com/dtbx/xingchuang/D10233_20210726.zip
  • y####.k8####.com/dtbx/yunshi/awli-release.zip
  • y####.k8####.com/hwyw/akertuns.zip
  • y####.k8####.com/hwyw/erfdoc9e54utr9gf7e455968y.zip
  • y####.k8####.com/hwyw/staunkert.zip
  • y####.k8####.com/plugins/applh0723.zip
  • y####.k8####.com/plugins/dp2.zip
  • y####.k8####.com/plugins/yz058Uc30i0913.zip
  • y####.k8####.com/zhuti/7y21yueermobi.zip
  • y####.k8####.com/zhuti/7y27jsdededkk.zip
  • y####.k8####.com/zhuti/8y17xinghao.zip
  • z.c####.com/stat.htm?id=####&cnzz_eid=####
HTTP POST requests:
  • a####.r####.com:13002/84gcjmo/
  • a####.r####.com:13002/ck0k66o/
  • a####.r####.com:13002/v1jyved/
  • api.bi####.com/un
  • c####.pay####.com:443/1/j?a=####
  • d.moce####.com/wap/gateway
  • d.moce####.com:9091/wap/gateway
  • fung####.ly####.com/cdn-cgi/challenge-platform/h/b/flow/ov1/0.1774455890...
  • ga_####.appclic####.com/api.php?req=####
  • hw9####.new####.com/api/activite
  • hw9####.new####.com/api/back
  • hw9####.new####.com/api/offer
  • hw9####.new####.com/api/tbdynamic
  • hw9####.new####.com/apidata/showeb
  • jz####.mc####.com:12029/hfdlls/
  • jz####.mc####.com:12029/i3v8nb/
  • jz####.mc####.com:12029/lfkdnr/
  • rgk.zu####.cn:443/v1/init?id=####
  • rgk.zu####.cn:443/v1/mr?id=####
  • sdk-eve####.ap-sout####.log.####.com/logstores/dev-log/track
  • t####.c8####.com:13002/4ad8fq/
  • t####.c8####.com:13002/a7atzr/
  • t####.c8####.com:13002/lgu4ds/
  • u.y####.com/api.php
  • u.y####.com/gst.php
  • u.y####.com/sal.php
  • u.y####.com/v4.php
  • u.y####.com/vereport.php
  • wcf.seven####.com:443/FBService.svc/rt432t45t45
  • www.d####.xyz/Orders/getlive?channel=####&Slevi=####&anmac=####&anosv=##...
  • z4####.ep####.com:14002/a2jyco/
  • z4####.ep####.com:14002/ajnhz5/
  • z4####.ep####.com:14002/uv2tay/
File system changes:
Creates the following files:
  • /data/data/####/.atmp9.dex
  • /data/data/####/.atmp9.dex.flock (deleted)
  • /data/data/####/.atmp9.jar
  • /data/data/####/.atmp_8.log
  • /data/data/####/.ki
  • /data/data/####/.m
  • /data/data/####/.t
  • /data/data/####/.wmgs
  • /data/data/####/011134986548f3458aa3e7e2a7fceb8d
  • /data/data/####/1.dex
  • /data/data/####/1.dex.flock (deleted)
  • /data/data/####/1.jar
  • /data/data/####/109127jvy
  • /data/data/####/109127jvy.dex
  • /data/data/####/109127jvy.dex.flock (deleted)
  • /data/data/####/2021_11_02readzibaoliangwuke.xml
  • /data/data/####/2118BF62061AA81849864E1FA899D952
  • /data/data/####/2118BF62061AA81849864E1FA899D952.dex
  • /data/data/####/2118BF62061AA81849864E1FA899D952.dex.flock (deleted)
  • /data/data/####/2118BF62061AA81849864E1FA899D952.temp
  • /data/data/####/2118BF62061AA81849864E1FA899D952.zip
  • /data/data/####/2bb935b8cfce2cde_0
  • /data/data/####/37D20B1E2F07E4F3F21755062BA40547
  • /data/data/####/3e2wssr.xml
  • /data/data/####/3e2wssr.xml.bak
  • /data/data/####/3e2wssr.xml.bak (deleted)
  • /data/data/####/3f6e00856d5eed02_0
  • /data/data/####/47AB7209AD7ACF4EB1EA636A3039D803
  • /data/data/####/4A20E7AD78924312CD8BC7F756DE340F
  • /data/data/####/4A20E7AD78924312CD8BC7F756DE340F.dex
  • /data/data/####/4A20E7AD78924312CD8BC7F756DE340F.dex.flock (deleted)
  • /data/data/####/4A20E7AD78924312CD8BC7F756DE340F.temp
  • /data/data/####/4A20E7AD78924312CD8BC7F756DE340F.zip
  • /data/data/####/5A064F2364D48401E82059BE1BFB3FC6
  • /data/data/####/5A064F2364D48401E82059BE1BFB3FC6.dex
  • /data/data/####/5A064F2364D48401E82059BE1BFB3FC6.dex.flock (deleted)
  • /data/data/####/5A064F2364D48401E82059BE1BFB3FC6.jar
  • /data/data/####/5A064F2364D48401E82059BE1BFB3FC6.temp
  • /data/data/####/636CD3B3EDFDE2D4D1D32F10D7347670
  • /data/data/####/636CD3B3EDFDE2D4D1D32F10D7347670.dex
  • /data/data/####/636CD3B3EDFDE2D4D1D32F10D7347670.dex.flock (deleted)
  • /data/data/####/636CD3B3EDFDE2D4D1D32F10D7347670.temp
  • /data/data/####/636CD3B3EDFDE2D4D1D32F10D7347670.zip
  • /data/data/####/6fb69037213d6bb4_0 (deleted)
  • /data/data/####/8FFE8235E5662DE0A07F13AC7491AB54
  • /data/data/####/90FCBC4E72D8C499954E2A48BD6A2C19
  • /data/data/####/90FCBC4E72D8C499954E2A48BD6A2C19.dex
  • /data/data/####/90FCBC4E72D8C499954E2A48BD6A2C19.dex.flock (deleted)
  • /data/data/####/90FCBC4E72D8C499954E2A48BD6A2C19.jar
  • /data/data/####/90FCBC4E72D8C499954E2A48BD6A2C19.temp
  • /data/data/####/92803EBB7D87B2E67FB0CEF6704D2D24
  • /data/data/####/95D59285D710EC3D31C7DC4E023745A4
  • /data/data/####/95D59285D710EC3D31C7DC4E023745A4.dex
  • /data/data/####/95D59285D710EC3D31C7DC4E023745A4.dex.flock (deleted)
  • /data/data/####/95D59285D710EC3D31C7DC4E023745A4.temp
  • /data/data/####/95D59285D710EC3D31C7DC4E023745A4.zip
  • /data/data/####/9B6F0F554183A3CD8361BE73C403E28B
  • /data/data/####/9B6F0F554183A3CD8361BE73C403E28B.dex
  • /data/data/####/9B6F0F554183A3CD8361BE73C403E28B.dex.flock (deleted)
  • /data/data/####/9B6F0F554183A3CD8361BE73C403E28B.temp
  • /data/data/####/9B6F0F554183A3CD8361BE73C403E28B.zip
  • /data/data/####/BFDB36197AD62250D717DC665B6B32FF
  • /data/data/####/C3B2481BF31F7E7DF213B1679D8AFC65
  • /data/data/####/C926D733D4E308956A8587F7AD9FED7C
  • /data/data/####/C926D733D4E308956A8587F7AD9FED7C.dex
  • /data/data/####/C926D733D4E308956A8587F7AD9FED7C.dex.flock (deleted)
  • /data/data/####/C926D733D4E308956A8587F7AD9FED7C.jar
  • /data/data/####/C926D733D4E308956A8587F7AD9FED7C.temp
  • /data/data/####/Cookies-journal
  • /data/data/####/D1E212CE2246CA824FF329FE82DA5812
  • /data/data/####/D1E212CE2246CA824FF329FE82DA5812.dex
  • /data/data/####/D1E212CE2246CA824FF329FE82DA5812.dex.flock (deleted)
  • /data/data/####/D1E212CE2246CA824FF329FE82DA5812.jar
  • /data/data/####/D1E212CE2246CA824FF329FE82DA5812.temp
  • /data/data/####/E1A26EB104BC37CA228217F2AA6136CB
  • /data/data/####/E1A26EB104BC37CA228217F2AA6136CB.dex
  • /data/data/####/E1A26EB104BC37CA228217F2AA6136CB.dex.flock (deleted)
  • /data/data/####/E1A26EB104BC37CA228217F2AA6136CB.jar
  • /data/data/####/E1A26EB104BC37CA228217F2AA6136CB.temp
  • /data/data/####/E7C8A3F6E0E20F381FF38DF485FCE16E
  • /data/data/####/E7C8A3F6E0E20F381FF38DF485FCE16E.dex
  • /data/data/####/E7C8A3F6E0E20F381FF38DF485FCE16E.dex.flock (deleted)
  • /data/data/####/E7C8A3F6E0E20F381FF38DF485FCE16E.temp
  • /data/data/####/E7C8A3F6E0E20F381FF38DF485FCE16E.zip
  • /data/data/####/EC0DA9876DC2A33B72C2A6BBEE1FE801.dex
  • /data/data/####/EC0DA9876DC2A33B72C2A6BBEE1FE801.dex.flock (deleted)
  • /data/data/####/EC0DA9876DC2A33B72C2A6BBEE1FE801.jar
  • /data/data/####/F4B17ACF5290B91BC7F8C0FE52D16691
  • /data/data/####/F4B17ACF5290B91BC7F8C0FE52D16691.dex
  • /data/data/####/F4B17ACF5290B91BC7F8C0FE52D16691.dex.flock (deleted)
  • /data/data/####/F4B17ACF5290B91BC7F8C0FE52D16691.temp
  • /data/data/####/F4B17ACF5290B91BC7F8C0FE52D16691.zip
  • /data/data/####/F73811C2013B84778D431A6EE070420A
  • /data/data/####/F73811C2013B84778D431A6EE070420A.dex
  • /data/data/####/F73811C2013B84778D431A6EE070420A.dex.flock (deleted)
  • /data/data/####/F73811C2013B84778D431A6EE070420A.jar
  • /data/data/####/F73811C2013B84778D431A6EE070420A.temp
  • /data/data/####/MobikokCommonConfig.xml
  • /data/data/####/PreferenceDeviceConfig.xml
  • /data/data/####/RDEwMjMz_iuy_data.xml
  • /data/data/####/RDEwMjMz_uuid_data.xml
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/YnJvd3Nlcl9sYWRh%0A.abc
  • /data/data/####/ZS50bXAuZGVjLmphcg%3D%3D%0A.jar
  • /data/data/####/ZS50bXAuamFy%0A
  • /data/data/####/ZS5kZWMuamFy%0A.dex
  • /data/data/####/ZS5kZWMuamFy%0A.dex.flock (deleted)
  • /data/data/####/aG9zdF9zdGdfYmVzdF9zZGs%3D%0A
  • /data/data/####/aG9zdF9zdGdfYmVzdF9zZGs%3D%0A.abc
  • /data/data/####/aXB2Mg%3D%3D%0A.abc
  • /data/data/####/aa1dc02f14bd694ad17d1f188edfa210
  • /data/data/####/ai
  • /data/data/####/anNfYnJvd3Nlcl8wMzEy%0A.abc
  • /data/data/####/anNfZGV2aWNlX2luZm8%3D%0A.abc
  • /data/data/####/anNfaHRw%0A
  • /data/data/####/anNfaHRw%0A.abc
  • /data/data/####/anNfc29hXzI%3D%0A
  • /data/data/####/anNfc29hXzI%3D%0A.abc
  • /data/data/####/anNfd3Bu%0A
  • /data/data/####/anNfd3Bu%0A.abc
  • /data/data/####/anNfdGVzdHBvY2E%3D%0A
  • /data/data/####/anNfdGVzdHBvY2E%3D%0A.abc
  • /data/data/####/anNfdGVzdHBvY2E%3D%0A.dex
  • /data/data/####/anNfdGVzdHBvY2E%3D%0A.dex.flock (deleted)
  • /data/data/####/anNfdGVzdHBvY2E%3D%0A.jar
  • /data/data/####/anNfeXk%3D%0A
  • /data/data/####/anNfeXk%3D%0A.abc
  • /data/data/####/anNfeXluZXdzXzI%3D%0A.abc
  • /data/data/####/androidxcorebac5z.
  • /data/data/####/androidxcorebac5z.dex
  • /data/data/####/androidxcorebac5z.dex.flock (deleted)
  • /data/data/####/base.apk
  • /data/data/####/base.dex
  • /data/data/####/base.dex.flock (deleted)
  • /data/data/####/c34a4c3h54e6_TYUYRTTYT
  • /data/data/####/ccddef.dex
  • /data/data/####/ccddef.dex.flock (deleted)
  • /data/data/####/ccddef.jar
  • /data/data/####/cda426fce2ac4c9f937f93a5f18af342
  • /data/data/####/com.db.tool.lausetting_ct_default.xml
  • /data/data/####/com.db.tool.lausetting_preferences.xml
  • /data/data/####/curtain_sp.xml
  • /data/data/####/curtain_sp.xml.bak
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e01e954cc6-57ff-4...289e9a
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e01e954cc6-57ff-4...9a.dex
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e01e954cc6-57ff-4...leted)
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e038e17b0e57b6ecc...6cache
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e07d8ad6e7195b848...4cache
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e07d8ad6e7195b848...949da4
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0b6cb96745f47e9c...65f071
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0b6cb96745f47e9c...leted)
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0b97a8e46-50f6-4...276891
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0b97a8e46-50f6-4...91.dex
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0b97a8e46-50f6-4...leted)
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0d6ff0db6-d776-4...0699fb
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0d6ff0db6-d776-4...fb.dex
  • /data/data/####/d0b06e32c35311eb8cdbb8599f4fd9e0d6ff0db6-d776-4...leted)
  • /data/data/####/data.dex
  • /data/data/####/data.dex.flock (deleted)
  • /data/data/####/data.jar
  • /data/data/####/df4essr.xml
  • /data/data/####/df4essr.xml.bak
  • /data/data/####/du
  • /data/data/####/e3f4r3ed.data-journal
  • /data/data/####/e3wg5rd.data-journal
  • /data/data/####/e77daa8583c8ff9d_0
  • /data/data/####/eea46c481d795204_0 (deleted)
  • /data/data/####/fb9dd01690a0d1ddbce9e527fb32207f.xml
  • /data/data/####/gameid
  • /data/data/####/gameid.zip
  • /data/data/####/gczt.png
  • /data/data/####/gjbq.png
  • /data/data/####/index
  • /data/data/####/jctr
  • /data/data/####/kdid
  • /data/data/####/ktwp
  • /data/data/####/libkezc.so
  • /data/data/####/libkezc.so-32
  • /data/data/####/libkezc.so-64
  • /data/data/####/libmytz.so
  • /data/data/####/libmytz.so-32
  • /data/data/####/libmytz.so-64
  • /data/data/####/libsszf.so
  • /data/data/####/libsszf.so-32
  • /data/data/####/libsszf.so-64
  • /data/data/####/life_record_config.xml
  • /data/data/####/link.db
  • /data/data/####/link.db-journal
  • /data/data/####/metrics_guid
  • /data/data/####/mq.xml
  • /data/data/####/ofew.png
  • /data/data/####/ofew.png (deleted)
  • /data/data/####/pakge_caches.xml
  • /data/data/####/readzibaoliang.xml
  • /data/data/####/s1s1k1_c2o3n23f2i3g2.xml
  • /data/data/####/s3p43_OIUTIUYT.xml
  • /data/data/####/settingsLog.xml
  • /data/data/####/settingsLog.xml.bak
  • /data/data/####/settingsLog.xml.bak (deleted)
  • /data/data/####/sp_dojz.xml
  • /data/data/####/sp_dojz.xml.bak
  • /data/data/####/sp_dqzanr.xml
  • /data/data/####/sp_dqzanr.xml.bak
  • /data/data/####/sp_tgee.xml
  • /data/data/####/sp_tgee.xml.bak
  • /data/data/####/sp_uenzy.xml
  • /data/data/####/sp_uenzy.xml.bak
  • /data/data/####/sytk.xml
  • /data/data/####/the-real-index
  • /data/data/####/uhen.xml
  • /data/data/####/ulanda.xml
  • /data/data/####/uma.xml
  • /data/data/####/v71.xml
  • /data/data/####/v71.xml.bak
  • /data/data/####/xfksgku
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • app_process /system/bin com.android.commands.pm.Pm list package -3
  • cat /proc/version
  • cat /sys/class/net/wlan0/address
  • getprop ro.yunos.build.version
  • sh
Loads the following dynamic libraries:
  • xfksgku
Uses the following algorithms to encrypt data:
  • AES
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-ECB-PKCS5Padding
  • DES-CBC-PKCS5Padding
  • RSA-None-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES
  • AES-CBC-NoPadding
  • AES-CBC-PKCS5Padding
  • AES-ECB-PKCS5Padding
  • DES-CBC-PKCS5Padding
  • RSA-None-PKCS1Padding
  • desede-CBC-PKCS5Padding
Accesses the ITelephony private interface.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.
Requests the system alert window permission.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android