Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Android.SmsSend.18743

Added to the Dr.Web virus database: 2017-05-14

Virus description added:

Technical information

Malicious functions:
Sends SMS messages:
  • 10658000: mmbb
  • 106904006189121: myqxt####
Executes code of the following detected threats:
  • Android.Triada.178
  • Android.SmsSend.18687
  • Android.Spy.205.origin
  • Android.SmsSend.18307
  • Android.SmsSend.18306
  • Android.Backdoor.285.origin
  • Android.SmsSend.17022
  • Android.DownLoader.441.origin
  • Android.Triada.155.origin
  • Android.SmsSend.18744
Downloads the following detected threats from the Web:
  • Android.Backdoor.285.origin
Sends data on received text messages to remote host.
Network activity:
Connecting to:
  • s####.####.com
  • a####.####.com:8088
  • 1####.####.95:18181
  • p####.####.com
  • p####.####.com:7820
  • pass####.####.cn
  • d####.####.com
  • d####.####.com:8080
  • do####.####.info:8010
  • 2####.####.31
  • greenxs####.net
  • do####.####.info
  • a####.####.com
HTTP GET requests:
  • p####.####.com/?igtcmd=####&nativePayCmd=####
  • p####.####.com/?igtcmd=####&nativePayCmd=####&imsi=####
  • d####.####.com/upload/plugin/net.tt.plugin.taiku_p20170510173018
  • pass####.####.cn/client/authRequest
  • d####.####.com/upload/plugin/net.tt.plugin.utadv_p20170503143958
  • s####.####.com/versioncheck.aspx?
  • s####.####.com/GetFeeData.aspx?iswifi=####
  • 2####.####.31/dl01.toucht.net/update/plugin-release-v4.9.3.zip?wsiphost=...
  • d####.####.com/upload/plugin/net.tt.plugin.yufeng_p20170510172955
  • greenxs####.net/doking/smsd!hiGo.action?t=####&dexId=####&dexVer=####&ap...
  • a####.####.com:8088/earth/enable?deviceid=####&version=####&imsi=####
  • s####.####.com/getconfig.aspx?
  • p####.####.com/?igtcmd%####
  • p####.####.com/openplg?appid=####&channelid=####
  • d####.####.com:8080/upload/plugin/net.tt.plugin.mysdk_p20170512171050
  • d####.####.com/update/plugin-release-v4.9.3.zip
  • 1####.####.95:18181/sdk/v1/GetFeePoint.aspx?appid=####&money=####&sdkver...
  • d####.####.com/upload/plugin/net.tt.plugin.shangan_p20170401110757
  • p####.####.com/?igtcmd=####&nativePayCmd=####&iccid=####&price=####&imsi...
  • p####.####.com/openicon?appid=####&channelid=####
  • p####.####.com/?igtcmd=####&order=####&state=####&paymsg=####&fingerprin...
  • d####.####.com/upload/plugin/net.tt.plugin.zhongzhi_p20170510172902
  • d####.####.com/upload/plugin/net.tt.plugin.myadv_p20170309134229
  • p####.####.com/?igtcmd=####&iccid=####&imsi=####&imei=####&order=####&um...
HTTP POST requests:
  • p####.####.com/
  • a####.####.com/app_logs
  • p####.####.com:7820/
  • do####.####.info:8010/
  • do####.####.info/
Modified file system:
Creates the following files:
  • /data/anr/traces.txt
  • /sdcard/.d080d3a37b0be7bc7c15c0a5ac76bc64/.config
  • /data/data/####/Plugin/net.tt.plugin.zhongzhi/apk/base-1.apk
  • /data/data/####/files/net.tt.plugin.mysdk.apk
  • /data/data/####/Plugin/net.tt.plugin.mysdk/dalvik-cache/base-1.dex
  • /data/data/####/Plugin/net.tt.plugin.myadv/Signature/Signature_0.key
  • /data/data/####/shared_prefs/ShareFiles.xml
  • /sdcard/.twservice/qshp_3003_2247/tw
  • /data/data/####/Plugin/net.tt.plugin.taiku/lib/tmp.rj2136
  • /data/data/####/files/net.tt.plugin.shangan.apk
  • /data/data/####/Plugin/net.tt.plugin.shangan/Signature/Signature_0.key
  • /data/data/####/files/net.tt.plugin.taiku.apk
  • /data/data/####/files/splash.dat
  • /data/data/####/Plugin/net.tt.plugin.zhongzhi/dalvik-cache/base-1.dex
  • /data/data/####/Plugin/net.tt.plugin.utadv/apk/base-1.apk
  • /data/data/####/Plugin/net.tt.plugin.utadv/dalvik-cache/base-1.dex
  • /data/data/####/files/mobclick_agent_cached_####
  • /data/data/####/files/net.tt.plugin.utadv
  • /data/data/####/files/net.tt.plugin.myadv
  • /data/data/####/files/net.tt.plugin.yufeng
  • /data/data/####/Plugin/net.tt.plugin.utadv/Signature/Signature_0.key
  • /data/data/####/shared_prefs/mobclick_agent_state_####.xml
  • /data/data/####/Plugin/net.tt.plugin.shangan/dalvik-cache/base-1.dex
  • /data/data/####/Plugin/net.tt.plugin.myadv/apk/base-1.apk
  • /data/data/####/files/net.tt.plugin.mysdk
  • /data/data/####/shared_prefs/game_state_file.xml
  • /data/data/####/Plugin/net.tt.plugin.taiku/apk/base-1.apk
  • /data/data/####/files/net.tt.plugin.shangan
  • /data/data/####/Plugin/net.tt.plugin.taiku/dalvik-cache/base-1.dex
  • /data/data/####/files/net.tt.plugin.zhongzhi
  • /data/data/####/Plugin/net.tt.plugin.yufeng/apk/base-1.apk
  • /sdcard/com.zckj.files/u.apk
  • /data/data/####/Plugin/net.tt.plugin.mysdk/Signature/Signature_0.key
  • /data/data/####/files/net.tt.plugin.utadv.apk
  • /sdcard/.armsd/tjfblFPob85GtAQw/I7HE1pd26tdvkjhloLWlx5UBeDOAmh6M.lk
  • /data/data/####/Plugin/net.tt.plugin.yufeng/dalvik-cache/base-1.dex
  • /data/data/####/Plugin/net.tt.plugin.myadv/dalvik-cache/base-1.dex
  • /data/data/####/shared_prefs/third_info.xml
  • /data/data/####/files/net.tt.plugin.yufeng.apk
  • /sdcard/.twservice/qshp_3003_2247.zip
  • /data/data/####/files/net.tt.plugin.myadv.apk
  • /sdcard/.armsd/tjfblFPob85GtAQw/I7HE1pd26tdvkjhloLWlx5UBeDOAmh6M
  • /sdcard/.d080d3a37b0be7bc7c15c0a5ac76bc64/zip/163037a5-53be-4395-8c97-781ba5d4fd7f.zip
  • /data/data/####/Plugin/net.tt.plugin.taiku/Signature/Signature_0.key
  • /data/data/####/files/2cb45657bda5decf6216a404438f0066.apk
  • /data/data/####/files/net.tt.plugin.zhongzhi.apk
  • /data/data/####/Plugin/net.tt.plugin.yufeng/Signature/Signature_0.key
  • /data/data/####/Plugin/net.tt.plugin.mysdk/apk/base-1.apk
  • /data/data/####/shared_prefs/userinfo_file.xml
  • /data/data/####/shared_prefs/mobclick_agent_header_####.xml
  • /sdcard/.tpservice/net.tt.plugin.taiku/download/jar/qsha_80001_5094.jar
  • /data/data/####/Plugin/net.tt.plugin.zhongzhi/Signature/Signature_0.key
  • /data/data/####/Plugin/net.tt.plugin.shangan/apk/base-1.apk
  • /data/data/####/files/net.tt.plugin.taiku
Miscellaneous:
Executes next shell scripts:
  • /system/bin/dexopt --dex 27 63 40 112932 /data/data/####/Plugin/net.tt.plugin.zhongzhi/apk/base-1.apk 0 -689701806 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /sys
  • /system/bin/dexopt --dex 27 57 40 527884 /data/data/####/Plugin/net.tt.plugin.utadv/data/net.tt.plugin.utadv/files/wpUkvUNSBkRZldvKQ47ukOY1AcZUjcH9xA7Ljw==/HHka6VDE1KK1YJbeg5U37Q==/57CSXG4AkRf8mBYZ.zip 1229621871 -838
  • chmod -R 755 /data/data/####/Plugin
  • /system/bin/dexopt --dex 27 53 40 477372 /storage/emulated/0/com.zckj.files/u.apk 0 -1595531788 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framework/framework.jar /sy
  • /system/bin/dexopt --dex 27 61 40 88408 /data/data/####/Plugin/net.tt.plugin.taiku/apk/base-1.apk 0 -1021980421 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system
  • /system/bin/dexopt --dex 27 70 40 251536 /data/data/####/Plugin/net.tt.plugin.mysdk/apk/base-1.apk 0 75012433 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/f
  • /system/bin/dexopt --dex 27 53 40 723324 /data/data/####/Plugin/net.tt.plugin.myadv/data/net.tt.plugin.myadv/files/33224739b1ec8ca8f65e8f072d8d8b17/655b3f11-737b-43c2-84e5-7c48def750b7.zip 1226343268 1975700309 45 /sy
  • /system/bin/dexopt --dex 27 54 40 246200 /data/data/####/Plugin/net.tt.plugin.taiku/apk/base-1.apk 0 1326277547 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system
  • sh /data/data/####/Plugin/net.tt.plugin.utadv/data/net.tt.plugin.utadv/code-4706618/98yrN6pnyVgK_kW9 net.tt.plugin.utadv com.gmkerqw.fjskd.bgrfxa.a.a.c.b /storage/emulated/0/.armsd/tjfblFPob85GtAQw/I7HE1pd26tdvkjhloLW
  • /data/data/####/Plugin/net.tt.plugin.utadv/data/net.tt.plugin.utadv/code-4706618/98yrN6pnyVgK_kW9 net.tt.plugin.utadv com.gmkerqw.fjskd.bgrfxa.a.a.c.b /storage/emulated/0/.armsd/tjfblFPob85GtAQw/I7HE1pd26tdvkjhloLWlx5
  • /system/bin/dexopt --dex 27 53 40 213440 /storage/emulated/0/.tpservice/net.tt.plugin.taiku/download/jar/qsha_80001_5094.jar 1248298237 -1297833896 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/f
  • /system/bin/dexopt --dex 27 40 40 2951240 /data/data/####/files/2cb45657bda5decf6216a404438f0066.apk 2179072 199364825 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar
  • /system/bin/dexopt --dex 27 71 40 128600 /data/data/####/Plugin/net.tt.plugin.zhongzhi/apk/base-1.apk 0 -1607311582 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /sy
  • /system/bin/dexopt --dex 27 67 40 182804 /data/data/####/Plugin/net.tt.plugin.myadv/apk/base-1.apk 0 1705094576 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system
  • /system/bin/dexopt --dex 27 65 40 263520 /data/data/####/Plugin/net.tt.plugin.shangan/apk/base-1.apk 0 -276708096 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /syst
  • /system/bin/dexopt --dex 27 65 40 156368 /data/data/####/Plugin/net.tt.plugin.yufeng/apk/base-1.apk 0 1541322089 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /syste
  • /system/bin/dexopt --dex 27 69 40 58464 /data/data/####/Plugin/net.tt.plugin.utadv/apk/base-1.apk 0 -815522394 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/
  • /system/bin/dexopt --dex 27 69 40 172292 /data/data/####/Plugin/net.tt.plugin.yufeng/apk/base-1.apk 0 1974962180 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /syste
  • /system/bin/dexopt --dex 27 47 40 82816 /data/data/####/Plugin/net.tt.plugin.utadv/data/net.tt.plugin.utadv/files/hrfaxq_d/hrfaxq_f.zip 1230210551 449958743 45 /system/framework/core.jar /system/framework/core-junit.j
  • /system/bin/dexopt --dex 27 46 40 477372 /storage/emulated/0/com.zckj.files/u.apk 0 -1595531788 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framework/framework.jar /sy
Contains functionality to send SMS messages automatically.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android