Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Android.Packed.38402

Added to the Dr.Web virus database: 2018-06-10

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.DownLoader.683.origin
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.0) 4####.92.62.1:80
  • TCP(HTTP/1.0) pis.al####.com:80
  • TCP(HTTP/1.1) h####.a####.com:80
  • TCP(HTTP/1.1) cs107-####.a####.com:80
  • TCP(HTTP/1.1) kvt####.m####.a####.com:80
  • TCP(HTTP/1.1) t####.dmp.y####.net:80
  • TCP(HTTP/1.1) www.a####.com.####.com:80
  • TCP(HTTP/1.1) res.we####.cn.####.com:80
  • TCP(HTTP/1.1) cs228-####.a####.com:80
  • TCP(HTTP/1.1) ip.ta####.com:80
  • TCP(HTTP/1.1) cs251-####.a####.com:80
  • TCP(HTTP/1.1) cs210-####.a####.com:80
  • TCP(HTTP/1.1) cs227-####.a####.com:80
  • TCP(HTTP/1.1) qs.lago####.com:8982
  • TCP(HTTP/1.1) cs223-####.a####.com:80
  • TCP(HTTP/1.1) cs112-####.a####.com:80
  • TCP(HTTP/1.1) pss.al####.com:80
  • TCP(HTTP/1.1) cs245-####.a####.com:80
  • TCP(HTTP/1.1) a####.m.ta####.com:80
  • TCP(HTTP/1.1) a####.u####.com:80
  • TCP(HTTP/1.1) g####.a####.com.####.com:80
  • TCP(HTTP/1.1) pus.al####.com:80
  • TCP(HTTP/1.1) a####.a####.com:80
  • TCP(HTTP/1.1) cdn.app.h####.####.com:80
  • TCP(HTTP/1.1) cs220-####.a####.com:80
  • TCP(HTTP/1.1) 1####.76.224.67:80
  • TCP(HTTP/1.1) cs246-####.a####.com:80
  • TCP(HTTP/1.1) l####.c####.q####.####.com:80
  • TCP(HTTP/1.1) cs110-####.a####.com:80
  • TCP(HTTP/1.1) fu1.a####.com:80
  • TCP(HTTP/1.1) cs221-####.a####.com:80
  • TCP(HTTP/1.1) policyc####.a####.com.####.com:80
  • TCP(HTTP/1.1) cs215-####.a####.com:80
  • TCP(HTTP/1.1) cs194-####.a####.com:80
  • TCP(HTTP/1.1) au.y####.net:80
  • TCP(HTTP/1.1) cs207-####.a####.com:80
  • TCP(HTTP/1.1) app.w####.cn:80
  • TCP(HTTP/1.1) c50.a####.com:80
  • TCP(HTTP/1.1) s.y####.net:80
  • TCP(HTTP/1.1) cdn.game####.org:80
  • TCP(TLS/1.0) pns.al####.com:443
  • TCP(TLS/1.0) c####.im.ta####.com:443
  • TCP(TLS/1.0) l####.4####.top:443
  • UDP 2####.0.0.1:9998
  • UDP 1####.168.59.254:4466
DNS requests:
  • 3####.nd####.y####.com
  • a####.a####.com
  • a####.m.ta####.com
  • a####.u####.com
  • aos.w####.y####.net
  • app.w####.cn
  • au.y####.net
  • c####.im.ta####.com
  • c50.a####.com
  • cdn.app.h####.top
  • cdn.game####.org
  • cs107-####.a####.com
  • cs110-####.a####.com
  • cs112-####.a####.com
  • cs194-####.a####.com
  • cs207-####.a####.com
  • cs207-####.a####.com
  • cs210-####.a####.com
  • cs215-####.a####.com
  • cs220-####.a####.com
  • cs221-####.a####.com
  • cs221-####.a####.com
  • cs223-####.a####.com
  • cs227-####.a####.com
  • cs228-####.a####.com
  • cs245-####.a####.com
  • cs246-####.a####.com
  • cs251-####.a####.com
  • cs251-####.a####.com
  • cs251-####.a####.com
  • fu1.a####.com
  • g####.a####.com
  • g####.a####.com
  • h####.a####.com
  • h####.a####.com
  • h####.a####.com
  • i####.ww.ta####.com
  • ip.ta####.com
  • j####.a####.com
  • j####.a####.com
  • j####.a####.com
  • kvt####.m####.a####.com
  • l####.4####.top
  • m####.a####.com
  • m.a####.com
  • pis.al####.com
  • pns.al####.com
  • policyc####.a####.com
  • pss.al####.com
  • pus.al####.com
  • qs.lago####.com
  • res.we####.cn
  • s####.gw.y####.net
  • s.y####.net
  • sdk.st####.y####.com
  • so.a####.com
  • t####.dmp.y####.net
  • www.a####.com
  • x####.a####.com
HTTP GET requests:
  • a####.a####.com/atiws/atiapp?category=####&platform=####&appver=####&gam...
  • a####.a####.com/atiws/atiappcommon?platform=####&appver=####&gameid=####...
  • a####.m.ta####.com/rest/abtest?logid=####&ak=####&av=####&c=####&v=####&...
  • app.w####.cn/action/connect/active?app_id=####&udid=####&imsi=####&net=#...
  • au.y####.net/offer/dist/aos/pkg/2.9.2/offers_2.9.2.zip
  • c50.a####.com/user/460/58437460/1006/card/48143202/48143202_400.jpg
  • c50.a####.com/user/767/54361767/1006/card/48167922/48167922_400.jpg
  • cdn.app.h####.####.com/swenjian/321
  • cdn.app.h####.####.com/swenjian/321m
  • cdn.game####.org/strategy/UnknownDev
  • cdn.game####.org/strategy/base
  • cdn.game####.org/strategy/dev_root
  • cdn.game####.org/strategy/dev_root2
  • cdn.game####.org/strategy/larger4.3
  • cdn.game####.org/strategy/loss_4.3
  • cdn.game####.org/strategy/sul18
  • cdn.game####.org/strategy/symlink-adbd
  • cs107-####.a####.com/user/460/58437460/1006/card/48171116/info.xml
  • cs110-####.a####.com/user/813/11246813/1006/card/48178141/48178141_800.jpg
  • cs112-####.a####.com/user/825/9538825/1005/card/48156666/48156666_800.jpg
  • cs194-####.a####.com/user/460/58437460/1006/card/48171116/48171116_400.jpg
  • cs207-####.a####.com/user/103/2367103/1005/card/48163464/card.mp4?l=####...
  • cs207-####.a####.com/user/103/2367103/1005/card/48163464/info.xml
  • cs207-####.a####.com/user/405/6271405/1005/card/48172562/48172562_800.jpg
  • cs207-####.a####.com/user/825/9538825/1005/card/48193101/48193101_800.jpg
  • cs210-####.a####.com/user/813/11246813/1006/card/48178141/48178141_800.jpg
  • cs215-####.a####.com/user/813/11246813/1006/card/48178141/48178141_400.jpg
  • cs220-####.a####.com/user/103/2367103/1005/card/48163464/48163464_800.jpg
  • cs220-####.a####.com/user/103/2367103/1005/card/48163464/info.xml
  • cs221-####.a####.com/user/103/2367103/1005/card/48163464/48163464_800.jpg
  • cs221-####.a####.com/user/813/11246813/1006/card/48178141/48178141_800.jpg
  • cs223-####.a####.com/user/460/58437460/1006/card/48171116/48171116_800.jpg
  • cs227-####.a####.com/user/460/58437460/1006/card/48143202/48143202_400.jpg
  • cs228-####.a####.com/user/767/54361767/1006/card/48167922/48167922_400.jpg
  • cs245-####.a####.com/user/549/63072549/1006/card/48176671/48176671_400.jpg
  • cs246-####.a####.com/user/680/55476680/1006/card/48177036/48177036_400.jpg
  • cs251-####.a####.com/user/103/2367103/1005/card/48163464/card.mp4?l=####...
  • cs251-####.a####.com/user/767/54361767/1006/card/48167922/48167922_800.jpg
  • cs251-####.a####.com/user/825/9538825/1005/card/48193101/info.xml
  • fu1.a####.com/account/103/2367103/account/2367103_normal.jpg
  • fu1.a####.com/account/405/6271405/account/6271405_normal.jpg
  • fu1.a####.com/account/460/58437460/account/58437460_normal.jpg
  • fu1.a####.com/account/825/9538825/account/9538825_normal.jpg
  • fu1.a####.com/account/969/56279969/account/56279969_normal.jpg
  • g####.a####.com.####.com/user/460/58437460/1006/card/48171116/card.mp4?l...
  • g####.a####.com.####.com/user/825/9538825/1005/card/48193101/card.mp4?l=...
  • h####.a####.com/user/103/2367103/1005/card/48163464/48163464_800.jpg
  • h####.a####.com/user/103/2367103/1005/card/48163464/card.mp4?l=####
  • h####.a####.com/user/103/2367103/1005/card/48163464/info.xml
  • h####.a####.com/user/405/6271405/1005/card/48172562/48172562_800.jpg
  • h####.a####.com/user/460/58437460/1006/card/48143202/48143202_400.jpg
  • h####.a####.com/user/460/58437460/1006/card/48171116/48171116_400.jpg
  • h####.a####.com/user/460/58437460/1006/card/48171116/48171116_800.jpg
  • h####.a####.com/user/460/58437460/1006/card/48171116/card.mp4?l=####
  • h####.a####.com/user/460/58437460/1006/card/48171116/info.xml
  • h####.a####.com/user/549/63072549/1006/card/48176671/48176671_400.jpg
  • h####.a####.com/user/680/55476680/1006/card/48177036/48177036_400.jpg
  • h####.a####.com/user/767/54361767/1006/card/48167922/48167922_400.jpg
  • h####.a####.com/user/767/54361767/1006/card/48167922/48167922_800.jpg
  • h####.a####.com/user/813/11246813/1006/card/48178141/48178141_400.jpg
  • h####.a####.com/user/813/11246813/1006/card/48178141/48178141_800.jpg
  • h####.a####.com/user/825/9538825/1005/card/48156666/48156666_800.jpg
  • h####.a####.com/user/825/9538825/1005/card/48193101/48193101_800.jpg
  • h####.a####.com/user/825/9538825/1005/card/48193101/card.mp4?l=####
  • h####.a####.com/user/825/9538825/1005/card/48193101/info.xml
  • ip.ta####.com/service/getIpInfo2.php?ip=####
  • kvt####.m####.a####.com/kvinfo.php
  • l####.c####.q####.####.com/core/aos-dex/1701/7011/6f830529.jar
  • l####.c####.q####.####.com/core/aos-so/1611/7000/ad389c56.so
  • policyc####.a####.com.####.com/api/aipaiApp_action-getCommentNew_mobile-...
  • policyc####.a####.com.####.com/app/www/templates/cdn_policy_telecom.txt?...
  • policyc####.a####.com.####.com/common/img/upload/xifen/1482832745_450.png
  • policyc####.a####.com.####.com/common/img/upload/xifen/1487160851_428.jpg
  • policyc####.a####.com.####.com/common/img/upload/xifen/1488615019_899.jpg
  • policyc####.a####.com.####.com/mobile/apps/apps.php?module=####&func=###...
  • policyc####.a####.com.####.com/pc/operator
  • pus.al####.com/kernal/sdkcontrol/vod_android-mobile_x86_9.1.1.1220.jpg
  • qs.lago####.com:8982/loadtime.shtml?clientIp=113.107.58.60&st=android&lt...
  • qs.lago####.com:8982/notify.shtml?saddr=aipai-android560000&definition=4...
  • qs.lago####.com:8982/notify.shtml?saddr=jhc-android560000&definition=480...
  • res.we####.cn.####.com/common/img/upload/xifen/1482832667_46.png
  • res.we####.cn.####.com/common/img/upload/xifen/1483942737_196.png
  • s.y####.net/aos/v3/initf?s=####
  • s.y####.net/stat/aos/v3/pkc?s=####
  • s.y####.net/stat/aos/v3/pku?s=####
  • s.y####.net/stat/v3/udt2?appid=####&s=####
  • s.y####.net/v3/zip_upd?s=####
  • www.a####.com.####.com/api/aipaiApp_action-getCommentNew_mobile-1_type-2...
  • www.a####.com.####.com/api/framework/adConf/33?platform=####&appver=####...
  • www.a####.com.####.com/api/framework/jifen/enter/33?platform=####&appver...
  • www.a####.com.####.com/api/hot/bannerItem/625?platform=####&appver=####&...
  • www.a####.com.####.com/api/hot/titleItem/626?platform=####&appver=####&o...
  • www.a####.com.####.com/api/hot/videos/2367?appId=####&xifenId=####&platf...
  • www.a####.com.####.com/api/jifen/firstInstallInit?platform=####&appver=#...
  • www.a####.com.####.com/api/specialTopic/itemList/628?platform=####&appve...
  • www.a####.com.####.com/mobile/apps/apps.php?module=####&func=####&app=##...
  • www.a####.com.####.com/mobile/apps/apps_module-badDomain.html
HTTP POST requests:
  • a####.m.ta####.com/rest/gc?dd=####&nsgs=####&ak=####&av=####&c=####&v=##...
  • a####.m.ta####.com/rest/sur?ak=####&av=####&c=####&v=####&s=####&d=####&...
  • a####.u####.com/app_logs
  • app.w####.cn/action/user_info
  • kvt####.m####.a####.com/i.gif
  • pis.al####.com/p/pcdn/i.php?v=####
  • pss.al####.com/iku/log/acc
  • pss.al####.com/iku/log/acc?ver=####&flag=####&t=####&mytype=####
  • t####.dmp.y####.net/v1/android/packages?rt=####&sign=####
  • t####.dmp.y####.net/v2/android/pkgtime?rt=####&sign=####
Modified file system:
Creates the following files:
  • /data/data/####/.imprint
  • /data/data/####/.jg.ic
  • /data/data/####/0406c892fe829f82a61face9b4739f8d.0.tmp
  • /data/data/####/0406c892fe829f82a61face9b4739f8d.1.tmp
  • /data/data/####/0671d775123a154925cc78b85520b81b4a3a6bcee5ac036....0.tmp
  • /data/data/####/0a29463f8fc406f80dcacac9a0890ff5.0.tmp
  • /data/data/####/0a29463f8fc406f80dcacac9a0890ff5.1.tmp
  • /data/data/####/0ccf73827510fff25c9bfab9e639e447.0.tmp
  • /data/data/####/0ccf73827510fff25c9bfab9e639e447.1.tmp
  • /data/data/####/0e9e78bdf6748b184e7c70d78c4ac21d3afe2549b6fffc9....0.tmp
  • /data/data/####/1740c449fc10be62df60ba0f18696c9f
  • /data/data/####/1d8661ea6a83cc3e5f8ac122ef427f3a.0.tmp
  • /data/data/####/1d8661ea6a83cc3e5f8ac122ef427f3a.1.tmp
  • /data/data/####/225badcae247c67bc8ab8c0b42a25295.0.tmp
  • /data/data/####/225badcae247c67bc8ab8c0b42a25295.1.tmp
  • /data/data/####/28ecc45b83b2965f01c7a176afe5808a31d1c3185770745....0.tmp
  • /data/data/####/2fbf5f05a73c07dbd20052520494aeaffacbedcd7be0d57....0.tmp
  • /data/data/####/2ff87966-5bb0-4db6-a4c6-c04178b44567
  • /data/data/####/32edd79a240b5f1e461d069caab1ec3e
  • /data/data/####/3334272fc82e756b77a6e251a33c28ae.0.tmp
  • /data/data/####/3334272fc82e756b77a6e251a33c28ae.1.tmp
  • /data/data/####/393b3583-d0c6-47cd-ad89-144847cfe3b2.jar
  • /data/data/####/3e92c90106cc1456b33c08b96947216ec71458d120a50a5....0.tmp
  • /data/data/####/44ad2a3e9b2ae742bc53ba539ed2853d4fa390381a04eaf....0.tmp
  • /data/data/####/53e3a44dac6f372f30ba936b94b07c16178fe7aa1c80ca8....0.tmp
  • /data/data/####/58f08a37cda11013b5981a72d12309996e808f05d4f4107....0.tmp
  • /data/data/####/591d9521-296c-4c60-b538-2e2c8fd3f79b
  • /data/data/####/5c851564d14103aad01f63f898f627d1.0.tmp
  • /data/data/####/5c851564d14103aad01f63f898f627d1.1.tmp
  • /data/data/####/6065c471fa488187d6c0cb191ffbe531ab760d69409e92f....0.tmp
  • /data/data/####/747116e7a861bce83d8783d887a2768b63f9caf2955f825....0.tmp
  • /data/data/####/7586cc94d852bd089fda195509d5227a.0.tmp
  • /data/data/####/7586cc94d852bd089fda195509d5227a.1.tmp
  • /data/data/####/7ac6f9620b705f09e8fbb222c91d6f7fee3ec2cbdd764a7....0.tmp
  • /data/data/####/7e05a80f-0505-4130-b6e6-75f133debaa3
  • /data/data/####/82bb521e-a87c-422a-9b83-fac9525f4a41
  • /data/data/####/86225ecf8d82be8312d2ae6c92363f82.0.tmp
  • /data/data/####/86225ecf8d82be8312d2ae6c92363f82.1.tmp
  • /data/data/####/8b6f263391259b7a8e5f58ee71852ca8
  • /data/data/####/8c266095-f728-4c48-bf86-2abcb014cbb6
  • /data/data/####/8ffe047bec5f53815bd14cdb017a78d32f9dcdb9d7d6fc8....0.tmp
  • /data/data/####/9152e5e4df9e1ec6b7c484be6bfcbfed095e64b9b4ed120....0.tmp
  • /data/data/####/95d3ddcb204ebee6eb8ab3e6d7bd41998f107b40614b645....0.tmp
  • /data/data/####/98f40fc2916d72d5b3028c481f93300a34451b5662a7aab....0.tmp
  • /data/data/####/998abd6ac6831d8313ae52a884bde760.0.tmp
  • /data/data/####/998abd6ac6831d8313ae52a884bde760.1.tmp
  • /data/data/####/9ca7ec7c81cffe92500234fd0787e98f
  • /data/data/####/9ca7ec7c81cffe92500234fd0787e98f-journal
  • /data/data/####/Alvin2.xml
  • /data/data/####/AppSettings.xml
  • /data/data/####/C0XKJAO3JLZKJPDKJFXLINQCJIOAOD.xml
  • /data/data/####/CE94557724F842149D690D0E8CBB1CBD.xml
  • /data/data/####/CacheTime.dat
  • /data/data/####/ContextData.xml
  • /data/data/####/CookiePersistence.xml
  • /data/data/####/Ll.xml
  • /data/data/####/Matrix
  • /data/data/####/OFFERSCONFIG1.xml
  • /data/data/####/OxgHkj2lz09F
  • /data/data/####/OxgHkj2lz09F-journal
  • /data/data/####/P15pKIjsm64m
  • /data/data/####/P15pKIjsm64m-journal
  • /data/data/####/SUBOXLOG_
  • /data/data/####/ShowAdFlag.xml
  • /data/data/####/T1oX0rhhuXWt
  • /data/data/####/T1oX0rhhuXWt-journal
  • /data/data/####/UTCommon.xml
  • /data/data/####/UTMCConf799303286.xml
  • /data/data/####/UTMCLog799303286.xml
  • /data/data/####/XKwVoK0huy3R
  • /data/data/####/XKwVoK0huy3R-journal
  • /data/data/####/Xwii.jar
  • /data/data/####/Xwii.xml
  • /data/data/####/a7d859d8ce2ecda081bb5e92b6266ff12f559c34a9f6d20....0.tmp
  • /data/data/####/a95721442af30cac93cc3f55edeee0c6.0.tmp
  • /data/data/####/a95721442af30cac93cc3f55edeee0c6.1.tmp
  • /data/data/####/abf7be53e2a083a8132ea973568bb609a7269cc316da69d....0.tmp
  • /data/data/####/ad_system_config.xml
  • /data/data/####/aipai.btconfig
  • /data/data/####/aipai.db
  • /data/data/####/aipai.db-journal
  • /data/data/####/aipai.guid
  • /data/data/####/arrow-left.png
  • /data/data/####/arrow-right.png
  • /data/data/####/b0141e478b25af7c40a8cca8de6c4708
  • /data/data/####/b18a021d11a3004d25017230b681476b
  • /data/data/####/blank.gif
  • /data/data/####/bzwn.db-journal
  • /data/data/####/c61913b615fb6224701377a119081f36
  • /data/data/####/cc200d66-0e57-4434-bf72-d83afc72e5de
  • /data/data/####/cecce475d4a3e358b2cbd04efe9bad79f628676ca7050f8....0.tmp
  • /data/data/####/close-icon.png
  • /data/data/####/com.gdcs.wjscdgpjlzx_preferences.xml
  • /data/data/####/config.json
  • /data/data/####/d6016521-4aab-43f6-a6fc-18100a748239
  • /data/data/####/dcf5c8fd4b2fed609f543af0170c1328278d84defb65029....0.tmp
  • /data/data/####/ddexe
  • /data/data/####/debuggerd
  • /data/data/####/default.png
  • /data/data/####/detail-wx-miniprogram.html
  • /data/data/####/detail-wx-miniprogram.js
  • /data/data/####/detail-wx.html
  • /data/data/####/detail-wx.js
  • /data/data/####/detail.html
  • /data/data/####/detail.js
  • /data/data/####/device.db
  • /data/data/####/df9bf88d-79d4-41f9-ba59-c23775c1058e
  • /data/data/####/e0888850d29ef11a195e5b377efd4265.0.tmp
  • /data/data/####/e0888850d29ef11a195e5b377efd4265.1.tmp
  • /data/data/####/e1ace30880b1e461c1b7d6a7babe424a1cae96044c1d37c....0.tmp
  • /data/data/####/e4d5a925de217ba2d331a54234399e67.zip
  • /data/data/####/e610fa5e08b26b2dc34931ebda8f453f.0.tmp
  • /data/data/####/e610fa5e08b26b2dc34931ebda8f453f.1.tmp
  • /data/data/####/e8723b74f6941a3107a08bfbc85d06d2.0.tmp
  • /data/data/####/e8723b74f6941a3107a08bfbc85d06d2.1.tmp
  • /data/data/####/e8b4f32f8d2d1bddf395d4b3cda478e0-journal
  • /data/data/####/ebn.xml
  • /data/data/####/ecb8066ab461d27a519de0ea191adde1
  • /data/data/####/ecb8066ab461d27a519de0ea191adde1-journal
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/f0e5a7bb-b47e-4d68-ae69-bafed3d20e3e
  • /data/data/####/f198ae99e1dc41e0b534153895c35d54004dd7fd6dde94f....0.tmp
  • /data/data/####/f6d6795831b3dca3ddf325b178051401d45846fc46bf930....0.tmp
  • /data/data/####/fb8087b11c3491a245bb77fc1db9d6ef.0.tmp
  • /data/data/####/fb8087b11c3491a245bb77fc1db9d6ef.1.tmp
  • /data/data/####/fcea79a85c76c943110c48ea5316523d0848294d991f4d2....0.tmp
  • /data/data/####/feedback.html
  • /data/data/####/feedback.js
  • /data/data/####/fileWork
  • /data/data/####/form.css
  • /data/data/####/global.js
  • /data/data/####/install-recovery.sh
  • /data/data/####/jg_so_upgrade_setting.xml
  • /data/data/####/journal.tmp
  • /data/data/####/jqIqJYOT3JpT
  • /data/data/####/jqIqJYOT3JpT-journal
  • /data/data/####/libabcdefgh.so.new
  • /data/data/####/libjiagu.so
  • /data/data/####/libpcdn_acc.zip
  • /data/data/####/libpcdn_acc_new.so
  • /data/data/####/lists.css
  • /data/data/####/lists.html
  • /data/data/####/lists.js
  • /data/data/####/md5.js
  • /data/data/####/multidex.version.xml
  • /data/data/####/pcdnconfigs.xml
  • /data/data/####/pic_friend_step1.jpg
  • /data/data/####/pic_friend_step2.jpg
  • /data/data/####/pic_friend_step3.jpg
  • /data/data/####/pic_friend_step4.jpg
  • /data/data/####/pic_friend_step5.jpg
  • /data/data/####/pic_m.png
  • /data/data/####/pic_tips_01.png
  • /data/data/####/pic_tips_02.png
  • /data/data/####/pic_xiaochengxu_kefu_step1.png
  • /data/data/####/pic_xiaochengxu_kefu_step2.png
  • /data/data/####/pic_xiaochengxu_kefu_step3.png
  • /data/data/####/pic_xiaochengxu_kefu_step4.png
  • /data/data/####/pic_xiaochengxu_kefu_step5.png
  • /data/data/####/pic_xiaochengxu_kefu_step6.png
  • /data/data/####/pic_xiaochengxu_step1.png
  • /data/data/####/pic_xiaochengxu_step2.png
  • /data/data/####/pic_xiaochengxu_step3.png
  • /data/data/####/pic_xiaochengxu_step4.png
  • /data/data/####/pic_xiaochengxu_step5.png
  • /data/data/####/pidof
  • /data/data/####/result.png
  • /data/data/####/root3
  • /data/data/####/rule.html
  • /data/data/####/rx_sf_account.xml
  • /data/data/####/rx_sf_app.xml
  • /data/data/####/sdetail.html
  • /data/data/####/share.css
  • /data/data/####/share.html
  • /data/data/####/share.js
  • /data/data/####/sp.lock
  • /data/data/####/sprite-face.png
  • /data/data/####/sprite-icons.png
  • /data/data/####/sprite-icons2.png
  • /data/data/####/su
  • /data/data/####/supolicy
  • /data/data/####/toolbox
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/wIU6pTyUBYWX
  • /data/data/####/wIU6pTyUBYWX-journal
  • /data/data/####/webview.db-journal
  • /data/data/####/wsUL1uCdKvjD
  • /data/data/####/wsUL1uCdKvjD-journal
  • /data/data/####/wsroot.sh
  • /data/data/####/wx-qr-step1.jpg
  • /data/data/####/wx-qr-step2.jpg
  • /data/data/####/wx-qr-step3.jpg
  • /data/data/####/wx-qr-step4.jpg
  • /data/data/####/wx-qr-step5.jpg
  • /data/data/####/wx-step1.jpg
  • /data/data/####/wx-step2.jpg
  • /data/data/####/wx-step3.jpg
  • /data/data/####/wx-step4.jpg
  • /data/data/####/wx-step5.jpg
  • /data/data/####/ymdex.jar
  • /data/data/####/ymdex.jar.new
  • /data/data/####/ywPrefsTools.xml
  • /data/media/####/.nomedia
  • /data/media/####/018dfc7dbb6790c384d37dd71a010687
  • /data/media/####/018dfc7dbb6790c384d37dd71a010687.ymtf
  • /data/media/####/6c709c11d2d46a7b
  • /data/media/####/Alvin2.xml
  • /data/media/####/AppPackage.dat
  • /data/media/####/CacheTime.dat
  • /data/media/####/ContextData.xml
  • /data/media/####/DXTX902KJZX9JASLDJF
  • /data/media/####/DXTX902KJZX9JASLDJF.ymtf
  • /data/media/####/SOX90123JSOALK2098SD
  • /data/media/####/SOX90123JSOALK2098SD.ymtf
  • /data/media/####/UnPackage.dat
  • /data/media/####/android
  • /data/media/####/dd7893586a493dc3
  • /data/media/####/i42d45df023jnkdd93la483f9xGFKXI
  • /data/media/####/myself.dat
  • /data/media/####/s92TjjdfoP2n3o9dfji2l9s1olkjf0p
Miscellaneous:
Executes next shell scripts:
  • /system/bin/cat /sys/devices/system/cpu/kernel_max
  • cat /proc/cpuinfo | grep Serial
  • chmod 755 <Package Folder>/.jiagu/libjiagu.so
  • chmod 777 Matrix ddexe debuggerd device.db fileWork install-recovery.sh pidof root3 su supolicy toolbox wsroot.sh
  • chmod 777 Matrix ddexe debuggerd fileWork install-recovery.sh pidof su supolicy toolbox wsroot.sh
  • ls -l /system/xbin/su
  • sh
Loads the following dynamic libraries:
  • abcdefgh
  • libjiagu
  • libpcdn_acc
  • pcdn_acc
  • securitysdk-3.1
  • xifen
Uses the following algorithms to encrypt data:
  • AES
  • AES-CBC-PKCS5Padding
  • DES-CBC-PKCS5Padding
  • PBEWITHMD5andDES
Uses the following algorithms to decrypt data:
  • DES-CBC-PKCS5Padding
  • PBEWITHMD5andDES
Uses special library to hide executable bytecode.
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about installed applications.
Gains access to information about running applications.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android