Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Android.Triada.5202

Added to the Dr.Web virus database: 2022-01-22

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Triada.573.origin
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) d1####.2usrq####.com:80
  • TCP(HTTP/1.1) gat####.funbl####.io:80
  • TCP(HTTP/1.1) api.applove####.com:80
  • TCP(HTTP/1.1) ip####.com:80
  • TCP(TLS/1.0) s.openmed####.com:443
  • TCP(TLS/1.0) analy####.ray####.com:443
  • TCP(TLS/1.0) d2####.2usrq####.com:443
  • TCP(TLS/1.0) net.ray####.com:443
  • TCP(TLS/1.0) wcf.seven####.com:443
  • TCP(TLS/1.0) fk-set####.ray####.com:443
  • TCP(TLS/1.0) st####.doublec####.net:443
  • TCP(TLS/1.0) firebas####.google####.com:443
  • TCP(TLS/1.0) ads.m####.com:443
  • TCP(TLS/1.0) wild####.moa####.com.####.net:443
  • TCP(TLS/1.0) adc3-la####.adco####.com:443
  • TCP(TLS/1.0) www.you####.com:443
  • TCP(TLS/1.0) cdn.app####.com:443
  • TCP(TLS/1.0) unit####.edges####.net:443
  • TCP(TLS/1.0) gd.a.s####.com:443
  • TCP(TLS/1.0) d1####.2usrq####.com:443
  • TCP(TLS/1.0) api.applove####.com:443
  • TCP(TLS/1.0) d####.fl####.com:443
  • TCP(TLS/1.0) adc-ad-####.ad####.com:443
  • TCP(TLS/1.0) api-acc####.edges####.net:443
  • TCP(TLS/1.0) googl####.g.doublec####.net:443
  • TCP(TLS/1.0) mt####.ray####.com:443
  • TCP(TLS/1.0) connect####.gst####.com:443
  • TCP(TLS/1.0) ssl.gst####.com:443
  • TCP(TLS/1.0) acco####.go####.com:443
  • TCP(TLS/1.0) res.z####.com:443
  • TCP(TLS/1.0) tls.vu####.edges####.net:443
  • TCP(TLS/1.2) 2####.58.215.74:443
  • TCP(TLS/1.2) www.you####.com:443
  • TCP(TLS/1.2) 1####.250.203.202:443
  • TCP d2####.2usrq####.com:443
  • TCP analy####.ray####.com:443
DNS requests:
  • a####.go####.com
  • acco####.go####.com
  • adc-ad-####.ad####.com
  • adc3-la####.adco####.com
  • ads.api.vu####.com
  • ads.m####.com
  • analy####.ray####.com
  • api.applove####.com
  • api.vu####.com
  • app-mea####.com
  • cd####.vu####.com
  • cdn.app####.com
  • co####.unit####.uni####.com
  • confi####.ray####.com
  • connect####.gst####.com
  • d####.fl####.com
  • d1####.2usrq####.com
  • d1####.2usrq####.com
  • d2####.2usrq####.com
  • firebas####.google####.com
  • gat####.funbl####.io
  • googl####.g.doublec####.net
  • ip####.com
  • m####.go####.com
  • mt####.ray####.com
  • net.ray####.com
  • pv.s####.com
  • res.z####.com
  • s.openmed####.com
  • ssl.gst####.com
  • st####.doublec####.net
  • wcf.seven####.com
  • web####.unit####.uni####.com
  • www.you####.com
  • z.moa####.com
HTTP GET requests:
  • adc-ad-####.ad####.com:443/launch/__controllers__/4.0.0/3.2.0.8/controll...
  • api-acc####.edges####.net:443/api/v5/new?ifa=####&app_id=####
  • api.applove####.com/api/v3/template/get?slot_id=####&update_time=####&us...
  • api.applove####.com:443/api/v3/pagead/get?osv=####&srnc=####&token=####&...
  • api.applove####.com:443/tools/sdk/confign/nativeads_new/2.5.9/native_ads...
  • api.applove####.com:443/tools/sdk/confign/rewarded/2.5.9/rewarded_config...
  • api.applove####.com:443/tools/sdk/langs/2.4.4/langs.json
  • api.applove####.com:443/tools/services/4.7.3/config.json
  • api.applove####.com:443/video/v4/ad/get?osv=####&srnc=####&token=####&ds...
  • api.applove####.com:443/video/v4/creative/get?osv=####&ispre=####&srnc=#...
  • cdn.app####.com:443/tools/sdk/confign/rewarded/2.5.9/rewarded_config.txt
  • d1####.2usrq####.com:443/static/media/coin.50f2d229.mp3
  • fk-set####.ray####.com:443/rewardsetting?app_id=####&sign=####&open=####...
  • fk-set####.ray####.com:443/rewardsetting?app_id=####&sign=####&unit_ids=...
  • fk-set####.ray####.com:443/setting?app_id=####&sign=####&open=####&chann...
  • fk-set####.ray####.com:443/setting?unit_ids=####&app_id=####&sign=####&o...
  • gat####.funbl####.io/config/client?cc=####&appType=####&osType=####&grou...
  • gd.a.s####.com:443/cityjson
  • ip####.com/json/?lang=####
  • mt####.ray####.com:443/2021/0629/confirmDialog-2b9fddb88412e09a244a9bb41...
  • res.z####.com:443/1576833642421_5566250.mp4
  • res.z####.com:443/1579245869408_竖屏1.mp4
  • res.z####.com:443/1588922659811_1579245843203_640x640.jpg
  • tls.vu####.edges####.net:443/creative/design-framework/assets/vungle-pri...
  • tls.vu####.edges####.net:443/templates/custom_creative_bundles/61e0a4047...
  • tls.vu####.edges####.net:443/zen/4c73024c90c68980344f1df38ca8384a.mp4-27...
  • tls.vu####.edges####.net:443/zen/7f89fbbd3b49cc529b38d008134ccbe9.mp4-27...
  • unit####.edges####.net:443/webview/3.4.6/release/config.json?ts=####&sdk...
  • unit####.edges####.net:443/webview/3.4.6/release/index.html
  • wild####.moa####.com.####.net:443/VNG/android/fe5b19d/status.json?ts=###...
HTTP POST requests:
  • adc3-la####.adco####.com:443/v4/launch
  • ads.m####.com:443/m/gdpr_sync
  • ads.m####.com:443/m/open
  • api-acc####.edges####.net:443/api/v5/ads
  • api-acc####.edges####.net:443/config
  • d1####.2usrq####.com:443/report/log
  • firebas####.google####.com:443/v1/projects/vnow-831a7/installations
  • net.ray####.com:443/openapi/ad/v5?app_id=####&unit_id=####&placement_id=...
  • s.openmed####.com:443/init?v=####&plat=####&sdkv=####&k=####
  • s.openmed####.com:443/om/wf?v=####&plat=####&sdkv=####
  • wcf.seven####.com:443/FBService.svc/GetPGCSetting
File system changes:
Creates the following files:
  • /data/data/####/.YFlurrySenderIndex.info.AnalyticsData_PW4WPX7H...Q8_311
  • /data/data/####/.YFlurrySenderIndex.info.StreamingMain
  • /data/data/####/.old_file_converted
  • /data/data/####/.yflurrydatasenderblock.c6df41d3-3b1d-40a3-bcee...79772e
  • /data/data/####/0.f1cc21b6.png
  • /data/data/####/026ae9c9824b3e483fa6c71fa88f57ae27816141
  • /data/data/####/058efb1d25df97b0_0
  • /data/data/####/058efb1d25df97b0_1
  • /data/data/####/0f88c08ea611aef3_0
  • /data/data/####/0f88c08ea611aef3_1
  • /data/data/####/10.2bb9f35b.png
  • /data/data/####/11a131a7a9685d498a244bd8e56f773b.0.tmp
  • /data/data/####/11a131a7a9685d498a244bd8e56f773b.1.tmp
  • /data/data/####/19eb70bf26778999_0
  • /data/data/####/2.4cd3348d.png
  • /data/data/####/20.384794c3.png
  • /data/data/####/21.c4eb42f3.png
  • /data/data/####/212dc9bf918f8c04_0 (deleted)
  • /data/data/####/3.573fbdd2.png
  • /data/data/####/30.2f9b85ba.png
  • /data/data/####/31.bd0c9b93.png
  • /data/data/####/32.b87222f1.png
  • /data/data/####/34.3e058ec1.png
  • /data/data/####/3488befd0faf0157_0
  • /data/data/####/3488befd0faf0157_1
  • /data/data/####/35.c6ebd6d5.png
  • /data/data/####/36.8f6e0baa.png
  • /data/data/####/37.3b529239.png
  • /data/data/####/38.4ed29b65.png
  • /data/data/####/3Pm8UNiV1NNgk88APIEBBDt4W6AcF9ebe16rNK_m3g0=.vng_meta
  • /data/data/####/4.ed8132d6.png
  • /data/data/####/40.21b86cf6.png
  • /data/data/####/42.acd7421f.png
  • /data/data/####/43.084356dc.png
  • /data/data/####/44.52f0a3a1.png
  • /data/data/####/45.f2af0356.png
  • /data/data/####/46.b0ef0c0c.png
  • /data/data/####/47.8747dce2.png
  • /data/data/####/5843126701258470536
  • /data/data/####/59e9afefe28c6c37a9d58112ee473024.0
  • /data/data/####/59e9afefe28c6c37a9d58112ee473024.1
  • /data/data/####/7.c1140a9a.png
  • /data/data/####/78945c9af78806e2_0
  • /data/data/####/78945c9af78806e2_1
  • /data/data/####/7b87995873aede0e_0 (deleted)
  • /data/data/####/7bf3a1e7bbd31e612eda3310c2cdb8075c43c6b5
  • /data/data/####/7ce8bd006fe5b524_0
  • /data/data/####/7ce8bd006fe5b524_1
  • /data/data/####/8.7753f926.png
  • /data/data/####/9.b8c9cb29.png
  • /data/data/####/901ddc3bbe5ae563_0 (deleted)
  • /data/data/####/AdConfig.xml
  • /data/data/####/AdTimingCrashSP.xml
  • /data/data/####/AppInfo
  • /data/data/####/AppVersion
  • /data/data/####/BlSQteKik6tRaeG_tWjba4Bl_H2VENHH1VJ7kBTD3co=
  • /data/data/####/BlSQteKik6tRaeG_tWjba4Bl_H2VENHH1VJ7kBTD3co=.vng_meta
  • /data/data/####/Cookies-journal
  • /data/data/####/DT_Event.xml
  • /data/data/####/DT_Event.xml.bak
  • /data/data/####/FLURRY_SHARED_PREFERENCES.xml
  • /data/data/####/FLURRY_SHARED_PREFERENCES.xml.bak
  • /data/data/####/FirebaseAppHeartBeat.xml
  • /data/data/####/PersistedInstallation.W0RFRkFVTFRd+MToxMDg3ODU4...Q.json
  • /data/data/####/PersistedInstallation234108400tmp
  • /data/data/####/PersistedInstallation461544585tmp
  • /data/data/####/RewardedVideo.db
  • /data/data/####/RewardedVideo.db-journal
  • /data/data/####/UnityAdsStorage-private-data.json
  • /data/data/####/UnityAdsStorage-public-data.json
  • /data/data/####/UnityAdsTest.txt (deleted)
  • /data/data/####/UnityAdsWebApp.html
  • /data/data/####/WXovo7QJD8CKQM0WRto-3LheHVvCNx9s-qRfzKuel_k=
  • /data/data/####/WXovo7QJD8CKQM0WRto-3LheHVvCNx9s-qRfzKuel_k=.vng_meta
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a88382ac6d6ba3d9_0 (deleted)
  • /data/data/####/aa_config
  • /data/data/####/afd1707ad76c449f9c1ce4de75dac80e.zip
  • /data/data/####/androidx.work.workdb-journal (deleted)
  • /data/data/####/androidxu3dqqnc0z.
  • /data/data/####/androidxu3dqqnc0z.dex
  • /data/data/####/androidxu3dqqnc0z.dex.flock (deleted)
  • /data/data/####/appnext_dbs472
  • /data/data/####/appnext_dbs472-journal
  • /data/data/####/asset_package.zip
  • /data/data/####/b2282b5722084345ec092f29813ef92e.0.tmp
  • /data/data/####/b2282b5722084345ec092f29813ef92e.1.tmp
  • /data/data/####/b49874ea86ce6e4af7e43b1c80e8cf5f.0.tmp
  • /data/data/####/b49874ea86ce6e4af7e43b1c80e8cf5f.1.tmp
  • /data/data/####/b667ee494323487a_0
  • /data/data/####/b667ee494323487a_1
  • /data/data/####/bg2.png.a557bee1.webp
  • /data/data/####/bg3.png.4e900c08.webp
  • /data/data/####/bg_bonus.a2c28610.png.webp
  • /data/data/####/bg_checkin.1797ce97.png.webp
  • /data/data/####/bg_game.df720637.png.webp
  • /data/data/####/btn-refernow-en.fd0fc6ee.png.webp
  • /data/data/####/btn-refernow-hi.f199a4f6.png.webp
  • /data/data/####/btn-refernow-id.9a9fe68e.png.webp
  • /data/data/####/cache_policy_journal
  • /data/data/####/cache_touch_timestamp
  • /data/data/####/cache_touch_timestamp (deleted)
  • /data/data/####/cd_wefewf
  • /data/data/####/challenge-redeemcard-bg.ce234050.png.webp
  • /data/data/####/checkintip.9aab093f.png.webp
  • /data/data/####/chunk-09e5b021.8b4b78e2.css
  • /data/data/####/chunk-09e5b021.a4f44b61.js
  • /data/data/####/chunk-112935b8.468e75b8.js
  • /data/data/####/chunk-112935b8.6d2e0ca8.css
  • /data/data/####/chunk-1581edc4.823d5f59.css
  • /data/data/####/chunk-1581edc4.84b638d8.js
  • /data/data/####/chunk-198d38fe.12ecb430.js
  • /data/data/####/chunk-198d38fe.68a1c342.css
  • /data/data/####/chunk-1d0417fe.5b6361b4.css
  • /data/data/####/chunk-1d0417fe.a1e991a1.js
  • /data/data/####/chunk-20d6afd0.4685f41b.js
  • /data/data/####/chunk-20d6afd0.d5d7bf07.css
  • /data/data/####/chunk-2a4c20b0.656aebe3.js
  • /data/data/####/chunk-2a4c20b0.b0d394bd.css
  • /data/data/####/chunk-2d0c0846.e511a780.js
  • /data/data/####/chunk-2d0e5e97.f5c070f7.js
  • /data/data/####/chunk-2d208c0c.e29149ed.js
  • /data/data/####/chunk-2d213786.6b800e50.js
  • /data/data/####/chunk-2e8a2bec.8578221f.css
  • /data/data/####/chunk-2e8a2bec.a6bafacc.js
  • /data/data/####/chunk-3053d40c.91a0beb0.js
  • /data/data/####/chunk-3290b65c.561e87a6.js
  • /data/data/####/chunk-3290b65c.b333fc7f.css
  • /data/data/####/chunk-382dc3ed.3107b276.css
  • /data/data/####/chunk-382dc3ed.31bc4874.js
  • /data/data/####/chunk-396ade4a.7dcf18c4.js
  • /data/data/####/chunk-396ade4a.9e9c215c.css
  • /data/data/####/chunk-3c958150.40115834.js
  • /data/data/####/chunk-3c958150.e65e338d.css
  • /data/data/####/chunk-3e70bf22.9f051c1a.js
  • /data/data/####/chunk-3e70bf22.c6eb95ec.css
  • /data/data/####/chunk-43e48476.6b32b697.css
  • /data/data/####/chunk-43e48476.78f7a040.js
  • /data/data/####/chunk-441c5675.416833a1.css
  • /data/data/####/chunk-441c5675.f4b070e9.js
  • /data/data/####/chunk-487479c7.e6194745.js
  • /data/data/####/chunk-487479c7.f31231df.css
  • /data/data/####/chunk-4cc25658.884d4045.js
  • /data/data/####/chunk-4cc25658.9c634c20.css
  • /data/data/####/chunk-4d350800.e5233f98.js
  • /data/data/####/chunk-59ddcdcc.5ba5f962.css
  • /data/data/####/chunk-59ddcdcc.d1bace08.js
  • /data/data/####/chunk-5a4bda97.1784be4b.js
  • /data/data/####/chunk-5a4bda97.1ecbad2c.css
  • /data/data/####/chunk-60a9c2de.5f1e1b48.js
  • /data/data/####/chunk-60a9c2de.7ba062d2.css
  • /data/data/####/chunk-636090c4.64faab60.js
  • /data/data/####/chunk-636090c4.c97e86c3.css
  • /data/data/####/chunk-6c756b73.c48c7d69.js
  • /data/data/####/chunk-6c756b73.d2e68206.css
  • /data/data/####/chunk-6e2d27ac.7230eb1d.js
  • /data/data/####/chunk-6e2d27ac.bf26bb9a.css
  • /data/data/####/chunk-79b8fb84.9523e0b1.css
  • /data/data/####/chunk-79b8fb84.af51573e.js
  • /data/data/####/chunk-7dd5a9a0.6971f087.css
  • /data/data/####/chunk-7dd5a9a0.8da8e7ff.js
  • /data/data/####/chunk-b22852b8.d2dd825d.js
  • /data/data/####/chunk-b22852b8.f04cc715.css
  • /data/data/####/chunk-c3c738b8.3d74f96e.css
  • /data/data/####/chunk-c3c738b8.637e388f.js
  • /data/data/####/chunk-cc99e368.76c40e66.css
  • /data/data/####/chunk-cc99e368.9e243819.js
  • /data/data/####/chunk-cedf0df0.00218859.css
  • /data/data/####/chunk-cedf0df0.fadb4f62.js
  • /data/data/####/chunk-common.4eb7ae15.js
  • /data/data/####/chunk-common.fea91aeb.css
  • /data/data/####/chunk-dcf33c96.1fd00f5e.js
  • /data/data/####/chunk-dcf33c96.8e97d91b.css
  • /data/data/####/chunk-ddbc83cc.9cdb0e08.css
  • /data/data/####/chunk-ddbc83cc.d89d6c97.js
  • /data/data/####/chunk-ea26b7ac.abebd5a7.js
  • /data/data/####/chunk-ea26b7ac.c2ef2c52.css
  • /data/data/####/chunk-eca31988.5f1d9e6e.js
  • /data/data/####/chunk-vendors.205624ff.css
  • /data/data/####/chunk-vendors.b2457925.js
  • /data/data/####/cocos2d-js-min.5ac6a.js
  • /data/data/####/coin-rp.ccf51795.png
  • /data/data/####/coin.50f2d229.mp3
  • /data/data/####/com.google.android.datatransport.events-journal
  • /data/data/####/com.google.android.gms.appid-no-backup
  • /data/data/####/com.google.android.gms.appid.xml
  • /data/data/####/com.google.android.gms.measurement.prefs.xml
  • /data/data/####/com.google.android.gms.measurement.prefs.xml.bak
  • /data/data/####/com.mopub.privacy.xml
  • /data/data/####/com.mopub.privacy.xml.bak
  • /data/data/####/com.mopub.settings.identifier.xml
  • /data/data/####/com.vd.vidnow_ct_default.xml
  • /data/data/####/com.vd.vidnow_preferences.xml
  • /data/data/####/com.vungle.sdk.xml
  • /data/data/####/com.vungle.sdk.xml.bak
  • /data/data/####/common-empty.06c31d82.png.webp
  • /data/data/####/completed-1642879168181
  • /data/data/####/config_ad
  • /data/data/####/config_banner
  • /data/data/####/config_common_en
  • /data/data/####/config_hotword
  • /data/data/####/config_i18n
  • /data/data/####/config_movie
  • /data/data/####/config_native_ad_config
  • /data/data/####/config_share
  • /data/data/####/config_spider
  • /data/data/####/config_website
  • /data/data/####/config_youtube
  • /data/data/####/confirmDialog.html
  • /data/data/####/confirmDialog.js
  • /data/data/####/confirm_dlg_icon.b3e9c568.png.webp
  • /data/data/####/contribution1.9245b44f.png.webp
  • /data/data/####/crashFile
  • /data/data/####/ct_download.db-journal
  • /data/data/####/currentFile
  • /data/data/####/cv.xml
  • /data/data/####/d7711073613e8abb2f6115d497aa126b.0.tmp
  • /data/data/####/d7711073613e8abb2f6115d497aa126b.1.tmp
  • /data/data/####/default.0064ab3d.png.webp
  • /data/data/####/default.710f167c.png
  • /data/data/####/defaultavatar.db6c6fec.jpg
  • /data/data/####/detail_bg.2c59a754.png.webp
  • /data/data/####/dialog.50806a7b.js
  • /data/data/####/dialog.html
  • /data/data/####/dt_event.db-journal
  • /data/data/####/e49b73494151f26d_0
  • /data/data/####/e9015d1dd49199ed_0
  • /data/data/####/e9015d1dd49199ed_1
  • /data/data/####/f3329f06499ce4f8_0
  • /data/data/####/fLLorktUQPqZ6P7na949l243k_-pH3VfP2TGMOq1Zi8=
  • /data/data/####/fLLorktUQPqZ6P7na949l243k_-pH3VfP2TGMOq1Zi8=.vng_meta
  • /data/data/####/favicon.ico
  • /data/data/####/fe4d94827e1ccca64a9c4bc7449a3573.0.tmp
  • /data/data/####/fe4d94827e1ccca64a9c4bc7449a3573.1.tmp
  • /data/data/####/feedback.40c32947.js
  • /data/data/####/feedback.69b5ab05.css
  • /data/data/####/filedownloader.db-journal
  • /data/data/####/game-machine-buddle2.7c2aa443.png
  • /data/data/####/game_block.3c232200.png
  • /data/data/####/gbridge.js
  • /data/data/####/generatefid.lock
  • /data/data/####/godap_download.db-journal
  • /data/data/####/godap_pub_data.xml
  • /data/data/####/google_app_measurement_local.db
  • /data/data/####/google_app_measurement_local.db-journal
  • /data/data/####/hand.1da7be80.png
  • /data/data/####/head_bg.e318e326.png.webp
  • /data/data/####/head_bg.f67827e7.png.webp
  • /data/data/####/http_d1cth1.2usrqwl1z.com_0.localstorage-journal
  • /data/data/####/https_accounts.google.com_0.localstorage-journal
  • /data/data/####/icon-1.14fb6eec.png
  • /data/data/####/icon-2.e30e1cdb.png
  • /data/data/####/icon-3.c04675ce.png
  • /data/data/####/icon-4.0a0152ed.png
  • /data/data/####/icon-5.c0827820.png
  • /data/data/####/icon-coin-shadow.d76e001b.png.webp
  • /data/data/####/icon-coin.2bc2711f.png.webp
  • /data/data/####/icon_bonus.e92c1298.png
  • /data/data/####/icon_coin.84e4aef2.png
  • /data/data/####/icon_game.0e5e2bf5.png
  • /data/data/####/icon_gift.2cb96876.png
  • /data/data/####/icon_q.74725d4d.png
  • /data/data/####/icon_step1.dd330b6a.png.webp
  • /data/data/####/icon_step2.741e0511.png.webp
  • /data/data/####/icon_step3.091917e7.png.webp
  • /data/data/####/icon_step4.836b7749.png.webp
  • /data/data/####/icon_task.9146b71f.png
  • /data/data/####/icon_video.92fa2418.png
  • /data/data/####/iconfont.c02901ca.woff
  • /data/data/####/index
  • /data/data/####/index.6e5d2ace.js
  • /data/data/####/index.html
  • /data/data/####/index.json
  • /data/data/####/installationNum
  • /data/data/####/journal
  • /data/data/####/leaderboard-title-en.3ad0730c.png.webp
  • /data/data/####/leaderboard-title-hi.8b0bee22.png.webp
  • /data/data/####/leaderboard-title-id.dcf22970.png.webp
  • /data/data/####/lib_shared_preferences.xml
  • /data/data/####/lib_shared_preferences.xml.bak
  • /data/data/####/loading.json
  • /data/data/####/lottie.min.js
  • /data/data/####/m.bundle.js
  • /data/data/####/mbridge.msdk.db-journal
  • /data/data/####/mbridge.xml
  • /data/data/####/metrics_guid
  • /data/data/####/mix.34f52de0.js
  • /data/data/####/mix.html
  • /data/data/####/mp4.c62d7fhadbvufgfssmdg
  • /data/data/####/mp4.c62d7fpadbvufgfssmo0
  • /data/data/####/mycrash.log
  • /data/data/####/notlogined.10e7ab83.png.webp
  • /data/data/####/omDB.db
  • /data/data/####/omDB.db-journal
  • /data/data/####/paytm-ico.f76928e1.png
  • /data/data/####/proc_auxv
  • /data/data/####/redeem-result.f4144f00.png.webp
  • /data/data/####/refer-top-bg.5c58d61e.png.webp
  • /data/data/####/refer2.279347f3.png
  • /data/data/####/remote.fe739fbc.js
  • /data/data/####/rise-line.213c6f83.png
  • /data/data/####/rules-steps.27bdbee6.png
  • /data/data/####/s1s1k1_c2o3n23f2i3g2.xml
  • /data/data/####/share_date.xml
  • /data/data/####/sp_wertwe.xml
  • /data/data/####/sp_wertwe.xml.bak
  • /data/data/####/splash.4fdde.png
  • /data/data/####/step1.37b5265f.png.webp
  • /data/data/####/step1_2.f7d32f64.png.webp
  • /data/data/####/step2.03747dc4.png.webp
  • /data/data/####/step3.21ce8d7d.png.webp
  • /data/data/####/step4.12671af1.png.webp
  • /data/data/####/steps.c500a65a.png.webp
  • /data/data/####/steps.eb2d52b2.png.webp
  • /data/data/####/style-mobile.css
  • /data/data/####/switch
  • /data/data/####/tUeWv3L_pKNO3b7VIsU3Iuf3YlVGgsXrYEdc464Q178=.vng_meta
  • /data/data/####/tasktip-img1.c47ea8fc.png.webp
  • /data/data/####/tasktip-img2.b4d79868.png.webp
  • /data/data/####/tasktip-img3_1.b664a55d.png.webp
  • /data/data/####/the-real-index
  • /data/data/####/top_bg.7d4b702b.png.webp
  • /data/data/####/unlogin-bg.365c686e.png.webp
  • /data/data/####/update.zip
  • /data/data/####/update1.d38dc913.png.webp
  • /data/data/####/updatepath.856eaebf.png.webp
  • /data/data/####/video_bg.4c2eb988.png.webp
  • /data/data/####/vungle-privacy.svg
  • /data/data/####/vungle_db-journal
  • /data/data/####/webviewjavascriptbridge.js
  • /data/media/####/.nomedia
  • /data/media/####/UnityAdsTest.txt (deleted)
  • /data/media/####/VDMaster.mmap3
  • /data/media/####/VDMaster_20220122.xlog
  • /data/media/####/afd1707ad76c449f9c1ce4de75dac80e.zip
  • /data/media/####/confirmDialog.html
  • /data/media/####/confirmDialog.js
  • /data/media/####/m.bundle.js
  • /data/media/####/mycrash.log
  • /data/media/####/rhea-atrace.gz
  • /data/media/####/z
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • app_process /system/bin com.android.commands.pm.Pm list package -3
  • ls -l /system/bin/su
  • sh
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS7PADDING
  • AES-CBC-PKCS7Padding
Uses the following algorithms to decrypt data:
  • desede-CBC-PKCS5Padding
Accesses the ITelephony private interface.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.
Requests the system alert window permission.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android