Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Android.Packed.43484

Added to the Dr.Web virus database: 2019-03-18

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.DownLoader.363.origin
  • Android.DownLoader.691.origin
Accesses the ITelephony private interface.
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) m####.g####.com.####.com:80
  • TCP(HTTP/1.1) 1####.159.180.48:8090
  • TCP(HTTP/1.1) 47.97.2####.31:660
  • TCP(HTTP/1.1) 1####.159.103.205:8090
  • TCP(HTTP/1.1) i####.g####.com.####.net:80
  • TCP(HTTP/1.1) sm####.qy####.cn:80
  • TCP(HTTP/1.1) s####.tc.qq.com:80
  • TCP(HTTP/1.1) 1####.78.31.198:8030
  • TCP(HTTP/1.1) gdv.a.s####.com:80
  • TCP(HTTP/1.1) p####.tc.qq.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) qos.re####.qq.com:80
  • TCP(HTTP/1.1) s####.e.qq.com:80
  • TCP(HTTP/1.1) v.g####.qq.com:80
  • TCP(HTTP/1.1) bt####.qq.com:80
  • TCP(HTTP/1.1) q####.a####.com:80
  • TCP(HTTP/1.1) aexcep####.b####.qq.com:8011
  • TCP(HTTP/1.1) aexcep####.b####.qq.com:8012
  • TCP(HTTP/1.1) ot.prs.qin####.com:80
  • TCP(HTTP/1.1) z####.heyc####.net:80
  • TCP(HTTP/1.1) ji####.jieme####.com:8152
  • TCP(HTTP/1.1) 1####.159.152.136:8090
  • TCP(HTTP/1.1) www.palmfun####.cn:80
  • TCP(HTTP/1.1) ot.grb.qin####.com:80
  • TCP(HTTP/1.1) xc.g####.qq.com:80
  • TCP(HTTP/1.1) a####.on####.club:80
  • TCP(HTTP/1.1) mi.g####.qq.com:80
  • TCP(HTTP/1.1) yuey####.ld####.com:80
  • TCP(TLS/1.0) analy####.map.qq.com:443
  • TCP(TLS/1.0) kua####.qq.com:443
  • TCP(TLS/1.0) m####.g####.com.####.com:443
  • TCP(TLS/1.0) s####.e.qq.com:443
  • TCP(TLS/1.0) et2-na6####.wagbr####.ali####.####.com:443
DNS requests:
  • a####.b####.qq.com
  • a####.on####.club
  • aexcep####.b####.qq.com
  • analy####.map.qq.com
  • and####.b####.qq.com
  • bt####.qq.com
  • i####.g####.com
  • imgc####.qq.com
  • ji####.dl####.com
  • ji####.jieme####.com
  • kua####.qq.com
  • m####.g####.com
  • mi.g####.qq.com
  • ot.cor.qin####.com
  • ot.grb.qin####.com
  • ot.m.qin####.com
  • ot.prs.qin####.com
  • p####.ugd####.com
  • plb####.u####.com
  • pv.s####.com
  • qos.re####.qq.com
  • qzones####.g####.cn
  • s####.e.qq.com
  • sm####.qy####.cn
  • t.g####.qq.com
  • u####.u####.com
  • v.g####.qq.com
  • www.palmfun####.cn
  • xc.g####.qq.com
  • yuey####.ld####.com
  • z####.heyc####.net
HTTP GET requests:
  • a####.on####.club/fileupload/806e62abe7aae788.jar
  • bt####.qq.com/kvcollect?BossId=####&Pwd=####&sIp=####&iQQ=####&sBiz=####...
  • gdv.a.s####.com/cityjson?ie=####
  • i####.g####.com.####.net/newsapp_bt/0/8023082129/640
  • i####.g####.com.####.net/newsapp_bt/0/8023083232/640
  • i####.g####.com.####.net/newsapp_bt/0/8023092901/640
  • i####.g####.com.####.net/newsapp_bt/0/8040386411/641
  • i####.g####.com.####.net/newsapp_bt/0/8040388007/641
  • i####.g####.com.####.net/newsapp_bt/0/8040388983/641
  • i####.g####.com.####.net/newsapp_bt/0/8040395322/641
  • i####.g####.com.####.net/newsapp_bt/0/8040610594/640
  • i####.g####.com.####.net/newsapp_bt/0/8040622986/640
  • i####.g####.com.####.net/newsapp_bt/0/8040632739/640
  • i####.g####.com.####.net/newsapp_bt/0/8087692675/640
  • i####.g####.com.####.net/newsapp_bt/0/8087692808/640
  • i####.g####.com.####.net/newsapp_bt/0/8087692858/640
  • i####.g####.com.####.net/newsapp_bt/0/8103825617/640
  • i####.g####.com.####.net/newsapp_bt/0/8103827479/640
  • i####.g####.com.####.net/newsapp_bt/0/8103829179/640
  • i####.g####.com.####.net/newsapp_ls/0/1189879430_200200/0
  • i####.g####.com.####.net/newsapp_ls/0/7f0caeeda0ab71707af3e660534625c7/0
  • i####.g####.com.####.net/newsapp_ls/0/8082194982_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8082194989_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8082195001_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8097065755_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8097065756_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8097065758_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8097308618_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8097308619_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8097308624_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8099071025_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8099071026_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8099071030_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8107480694_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8107480701_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8107482898_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8108461104_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8108742506_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8108746518_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8108749254_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8116147698_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8116147904_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8116148101_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8125200044_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8125203190_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8125205503_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8133339226_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8133341124_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8133347323_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8133759103_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8133759104_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8133759106_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8134126722_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8134126723_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8134126784_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8135702091_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8135880664_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8135882623_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8136358487_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8136358490_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8136363829_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8136922142_240180/0
  • i####.g####.com.####.net/newsapp_ls/0/8140389842_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8141881583_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8141888534_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8141890073_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8149506048_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8149515059_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8149517111_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8149570525_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8149570527_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8149573601_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8150041620_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8150041621_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8150041622_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8153996520_150120/0
  • i####.g####.com.####.net/newsapp_ls/0/8155015216_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8155015221_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8155015223_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8156525745_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8156525754_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8156525757_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8156637574_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8156637576_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8156637580_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8156722878_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8156722883_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8156722885_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8165349934_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8165349935_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8165349940_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8165395457_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8165880376_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8165880378_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8165880380_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8166526367_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8166526375_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8166526377_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8166682296_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8166939401_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8166939412_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8166960509_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8168922961_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8168922976_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8168922980_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8171287505_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8171333097_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8171333100_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8171333101_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8171402698_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8171402702_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8171402707_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8171435610_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8171435612_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8171435613_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8172408527_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8172408531_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8172408537_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8172679761_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8173041706_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8173041707_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8173041710_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8174496153_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8174497299_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8174504723_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8177163606_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8177751462_240180/0
  • i####.g####.com.####.net/newsapp_ls/0/8179197007_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8179197011_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8179197012_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8180057539_640480/0
  • i####.g####.com.####.net/newsapp_ls/0/8180890713_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8180890714_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8180890721_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8181062403_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8181062405_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8181062408_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8182093810_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8182095381_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8182096645_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8182609345_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8182611405_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8182612490_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8183458245_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8183458250_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8183458252_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8185127428_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8185127430_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8185127432_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8185548507_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8185548510_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8185548511_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8186171345_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8186171347_196130/0
  • i####.g####.com.####.net/newsapp_ls/0/8186171353_196130/0
  • m####.g####.com.####.com/www/images/kuaibao/bonus/fuliyouhuoyong_logo_20...
  • m####.g####.com.####.com/www/images/kuaibao/bonus/kuaibaohongbao_gongxif...
  • m####.g####.com.####.com/www/images/kuaibao/bonus/tips_pic_envelope_clos...
  • m####.g####.com.####.com/www/images/kuaibao/kuaibao_h5_nopic.png
  • m####.g####.com.####.com/www/images/kuaibao/logo_titlebar_20171023.png
  • m####.g####.com.####.com/www/images/newsapp/mqq/kb_logo_rad_20171014.png
  • m####.g####.com.####.com/www/images/newsapp/wechat/kuaibao_h5_nopic.png
  • mi.g####.qq.com/gdt_mview.fcg?posw=####&posh=####&count=####&r=####&data...
  • mi.g####.qq.com/gdt_mview.fcg?posw=####&spsa=####&posh=####&count=####&r...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/icon-ad.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/icon-close.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/inter_close_lo...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/popup_ad_car_b...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/score.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/tsa_ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/images/tsa_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/interstitial.appcache
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/interstitial.html
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/js-release/20170821/i...
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android01/js/lib/require.js
  • p####.tc.qq.com/qzone/biz/gdt/mob/sdk/v2/android02/images/tsa_ad_logo.png
  • p####.tc.qq.com/qzone/biz/gdt/mod/android/AndroidAllInOne/proguard/his/r...
  • q####.a####.com/jieplginf/djmdeta29
  • qos.re####.qq.com/collect?type=####&name=####&1=####&2=####&3=####&4=###...
  • s####.tc.qq.com/gdt/0/2ca5b72e3362073e2e35fe984e3b49de.JPG/0?ck=####
  • s####.tc.qq.com/gdt/0/DAADyLpAKAAPAAAiBci35WAp81WO6z.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAGTJ3AKAAPAABdBcg-RpCqTHtMgD.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAGTJ3AKAAPAABgBceSOcBgEQaK2U.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAGTJ3AKAAPAABjBcd5uXBhL2HyM7.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAfs1OAKAAPAAV2BcT8aMAadRF9yQ.gif/0?ck=####
  • s####.tc.qq.com/gdt/0/DAAiiAjAKAAPAABhBb5j0VBAX4KKWt.jpg/0?ck=####
  • s####.tc.qq.com/gdt/0/d2410203104a581bea06fc8e26f2ed96.JPG/0?ck=####
  • s####.tc.qq.com/gdt/0/ff4b46c94e749743228bbc516b7c4c4a.JPG/0?ck=####
  • v.g####.qq.com/gdt_stats.fcg?viewid=####&i=####&os=####&xp=####&gap=####
  • xc.g####.qq.com/adx_click.fcg?viewid=####&jtype=####&bid=####&i=####&os=...
HTTP POST requests:
  • aexcep####.b####.qq.com:8011/rqd/async
  • aexcep####.b####.qq.com:8012/rqd/async
  • and####.b####.qq.com/rqd/async
  • and####.b####.qq.com/rqd/async?aid=####
  • ji####.jieme####.com:8152/ryf_webserver/payment/checkupdate.html
  • ot.grb.qin####.com/JBVZVr/niyaei
  • ot.grb.qin####.com/ei6VRb/ZJnAba
  • ot.prs.qin####.com/7ziimi/QriUva
  • ot.prs.qin####.com/7ziimi/ieuYzm
  • ot.prs.qin####.com/JBVZVr/niyaei
  • ot.prs.qin####.com/ei6VRb/ZJnAba
  • ot.prs.qin####.com/zIFvYr/uaqmAn
  • s####.e.qq.com/activate
  • s####.e.qq.com/launch
  • s####.e.qq.com/msg
  • sm####.qy####.cn/code/reqXSCodeSDK
  • www.palmfun####.cn/fee/active
  • www.palmfun####.cn/fee/searchpc
  • www.palmfun####.cn/fee/searchpcNew
  • yuey####.ld####.com/channel/paymentHandle.action?requestId=####&v=####
  • z####.heyc####.net/getlist
  • z####.heyc####.net/xlogin
File system changes:
Creates the following files:
  • /data/data/####/.dex
  • /data/data/####/.imprint
  • /data/data/####/.jar
  • /data/data/####/0206f97398da1e3fafdde7d3680eba30.temp
  • /data/data/####/1004
  • /data/data/####/1552876701398
  • /data/data/####/1552876703290
  • /data/data/####/1552876705817
  • /data/data/####/1552876706325
  • /data/data/####/1552876707323
  • /data/data/####/1552876707690
  • /data/data/####/1552876709332
  • /data/data/####/1552876709780
  • /data/data/####/1552876714467
  • /data/data/####/1552876714678
  • /data/data/####/1552876716755
  • /data/data/####/1552876717643
  • /data/data/####/1552876718090
  • /data/data/####/1552876719111
  • /data/data/####/1552876720738
  • /data/data/####/1552876721249
  • /data/data/####/1552876721998
  • /data/data/####/1552876722610
  • /data/data/####/1552876724452
  • /data/data/####/1552876728314
  • /data/data/####/1552876728441
  • /data/data/####/1552876730369
  • /data/data/####/1552876731613
  • /data/data/####/1552876732075
  • /data/data/####/1552876732852
  • /data/data/####/1552876734682
  • /data/data/####/1552876735492
  • /data/data/####/1552876736254
  • /data/data/####/1552876736673
  • /data/data/####/1552876740963
  • /data/data/####/1552876741084
  • /data/data/####/1552876742631
  • /data/data/####/1552876744952
  • /data/data/####/1552876745477
  • /data/data/####/1552876745996
  • /data/data/####/1552876746850
  • /data/data/####/1552876746987
  • /data/data/####/1552876749692
  • /data/data/####/1552876749777
  • /data/data/####/1552876750762
  • /data/data/####/1552876753138
  • /data/data/####/1552876753224
  • /data/data/####/1552876755004
  • /data/data/####/1552876755398
  • /data/data/####/1552876755784
  • /data/data/####/1552876757180
  • /data/data/####/1552876757398
  • /data/data/####/1552876759543
  • /data/data/####/1552876759560
  • /data/data/####/1552876761037
  • /data/data/####/1552876763013
  • /data/data/####/1552876766147
  • /data/data/####/1552876766385
  • /data/data/####/1552876768150
  • /data/data/####/1552876771562
  • /data/data/####/1552876772235
  • /data/data/####/1552876774098
  • /data/data/####/2295.yaqcookie
  • /data/data/####/2659.yaqcookie
  • /data/data/####/3036.yaqcookie
  • /data/data/####/3405.yaqcookie
  • /data/data/####/3786.yaqcookie
  • /data/data/####/3f83d65a9a8cdc5cf1f21371b6eb5a94.temp
  • /data/data/####/55bad9d54fdb1b42c03df9d96cbb94a5.temp
  • /data/data/####/5ead7c1916e321af3ee0d7d6aa595238.temp
  • /data/data/####/71a91cc876127818fd1f76122732f509.temp
  • /data/data/####/7d2519f0f21ee1ee1fb2f1c0ac2e3a65.temp
  • /data/data/####/825587e649e1b2cead8ac2ee0b8d818f.temp
  • /data/data/####/ApplicationCache.db
  • /data/data/####/ApplicationCache.db-journal
  • /data/data/####/BrowserPreference.xml
  • /data/data/####/BuglySdkInfos.xml
  • /data/data/####/GDTSDK.db
  • /data/data/####/GDTSDK.db-journal
  • /data/data/####/JiePay.xml
  • /data/data/####/XinZF.xml
  • /data/data/####/XinZF_conf.xml
  • /data/data/####/XinZFsmspay.db
  • /data/data/####/XinZFsmspay.db-journal
  • /data/data/####/a==7.5.3&&2.0_1552876706894_envelope.log
  • /data/data/####/a_tmp
  • /data/data/####/b747f831e5fa0915e85f2f296a2a39eb.temp
  • /data/data/####/bb88459d446ae855319385330e7174f8.temp
  • /data/data/####/bugly_db_
  • /data/data/####/bugly_db_-journal
  • /data/data/####/bugly_db_legu
  • /data/data/####/bugly_db_legu-journal
  • /data/data/####/c8ef51bca7c6ca597d96a5924f5daec5.xml
  • /data/data/####/crashrecord.xml
  • /data/data/####/dW1weF9pbnRlcm5hbF8xNTUyODc2NzA2NzU1;
  • /data/data/####/dW1weF9pbnRlcm5hbF8xNTUyODc2NzE4OTA1;
  • /data/data/####/dW1weF9pbnRlcm5hbF8xNTUyODc2NzMyODI3;
  • /data/data/####/dW1weF9pbnRlcm5hbF8xNTUyODc2NzQ2MDM4;
  • /data/data/####/dW1weF9pbnRlcm5hbF8xNTUyODc2NzU1NzIz;
  • /data/data/####/data_0
  • /data/data/####/data_1
  • /data/data/####/data_2
  • /data/data/####/data_3
  • /data/data/####/devCloudSetting.cfg
  • /data/data/####/devCloudSetting.sig
  • /data/data/####/dexMethod.36117467.dat
  • /data/data/####/dexMethod.91475202.dat
  • /data/data/####/dpi
  • /data/data/####/e1e89e3f104bc40a46a21b8c76fdb30a
  • /data/data/####/e1e89e3f104bc40a46a21b8c76fdb30a.temp
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f_000001
  • /data/data/####/f_000002
  • /data/data/####/fplay_arthc
  • /data/data/####/gdt_config.cfg
  • /data/data/####/gdt_plugin.dex
  • /data/data/####/gdt_plugin.dex (deleted)
  • /data/data/####/gdt_plugin.jar
  • /data/data/####/gdt_plugin.jar.sig
  • /data/data/####/gdt_plugin.tmp
  • /data/data/####/gdt_plugin.tmp.sig
  • /data/data/####/gdt_stat.db
  • /data/data/####/gdt_stat.db-journal
  • /data/data/####/gdt_suid
  • /data/data/####/hid.db
  • /data/data/####/i==1.2.0&&2.0_1552876707769_envelope.log
  • /data/data/####/i==1.2.0&&2.0_1552876718425_envelope.log
  • /data/data/####/i==1.2.0&&2.0_1552876746068_envelope.log
  • /data/data/####/i==1.2.0&&2.0_1552876755876_envelope.log
  • /data/data/####/index
  • /data/data/####/info.xml
  • /data/data/####/jiepay_config.xml
  • /data/data/####/jiepayplugin.apk
  • /data/data/####/jiepayplugin.apkdata
  • /data/data/####/jiepayplugin.dex
  • /data/data/####/jiepayplugin.dex (deleted)
  • /data/data/####/jiepaysmspay.db
  • /data/data/####/jiepaysmspay.db-journal
  • /data/data/####/lhfreewildprism
  • /data/data/####/libnfix.so
  • /data/data/####/libshella-2.9.1.2.so
  • /data/data/####/libufix.so
  • /data/data/####/libyaqbasic.36117467.so
  • /data/data/####/libyaqbasic.91475202.so
  • /data/data/####/libyaqpro.36117467.so
  • /data/data/####/libyaqpro.91475202.so
  • /data/data/####/local_crash_lock
  • /data/data/####/mix.dex
  • /data/data/####/mix.so
  • /data/data/####/native_record_lock
  • /data/data/####/one.dex
  • /data/data/####/onePayV3.xml
  • /data/data/####/onePay_SP.xml
  • /data/data/####/org.blusteam.lhfree.wildprism.com.one.support.c...ournal
  • /data/data/####/pretw.xml
  • /data/data/####/qs_LcCache.xml
  • /data/data/####/sdkCloudSetting.cfg
  • /data/data/####/sdkCloudSetting.sig
  • /data/data/####/security_info
  • /data/data/####/security_info (deleted)
  • /data/data/####/sms_data.xml
  • /data/data/####/tw.dex
  • /data/data/####/twc.xml
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/um_pri.xml
  • /data/data/####/umdat.xml
  • /data/data/####/umeng_common_config.xml
  • /data/data/####/umeng_common_location.xml
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/update_lc
  • /data/data/####/userData.xml
  • /data/data/####/userDatas.xml
  • /data/data/####/webview.db
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/yaqsdkcookie
  • /data/data/####/ydutl.cf
  • /data/data/####/yy.dt
  • /data/data/####/yywda.apk
  • /data/data/####/yywda.dex
  • /data/media/####/.a.dat
  • /data/media/####/.adfwe.dat
  • /data/media/####/.cca.dat
  • /data/media/####/.nid
  • /data/media/####/.nomedia
  • /data/media/####/.umm.dat
  • /data/media/####/WyyyCrashLog_20190318023829_2295.log
  • /data/media/####/WyyyCrashLog_20190318023840_2659.log
  • /data/media/####/WyyyCrashLog_20190318023841_2659.log
  • /data/media/####/WyyyCrashLog_20190318023842_2659.log
  • /data/media/####/WyyyCrashLog_20190318023844_2659.log
  • /data/media/####/WyyyCrashLog_20190318023856_3036.log
  • /data/media/####/WyyyCrashLog_20190318023906_3405.log
  • /data/media/####/WyyyCrashLog_20190318023909_3405.log
  • /data/media/####/WyyyCrashLog_20190318023910_3405.log
  • /data/media/####/WyyyCrashLog_20190318023916_3786.log
  • /data/media/####/WyyyCrashLog_20190318023917_3786.log
  • /data/media/####/WyyyCrashLog_20190318023919_3786.log
  • /data/media/####/WyyyCrashLog_20190318023920_3786.log
  • /data/media/####/WyyyCrashLog_20190318023922_3786.log
  • /data/media/####/sysid.dat
  • /data/media/####/tw
  • /data/media/####/yydd_3009_2344.zip
Miscellaneous:
Executes the following shell scripts:
  • ./fplay_arthc
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
  • /system/bin/sh
  • /system/bin/sh -c getprop
  • /system/bin/sh -c getprop ro.aa.romver
  • /system/bin/sh -c getprop ro.board.platform
  • /system/bin/sh -c getprop ro.build.fingerprint
  • /system/bin/sh -c getprop ro.build.nubia.rom.name
  • /system/bin/sh -c getprop ro.build.rom.id
  • /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
  • /system/bin/sh -c getprop ro.build.version.emui
  • /system/bin/sh -c getprop ro.build.version.opporom
  • /system/bin/sh -c getprop ro.gn.gnromvernumber
  • /system/bin/sh -c getprop ro.lenovo.series
  • /system/bin/sh -c getprop ro.lewa.version
  • /system/bin/sh -c getprop ro.meizu.product.model
  • /system/bin/sh -c getprop ro.miui.ui.version.name
  • /system/bin/sh -c getprop ro.vivo.os.build.display.id
  • /system/bin/sh -c type su
  • cat /sys/block/mmcblk0/device/cid
  • cat /sys/class/android_usb/android0/idProduct
  • cat /sys/class/android_usb/android0/idVendor
  • chmod 700 <Package Folder>/tx_shell/libnfix.so
  • chmod 700 <Package Folder>/tx_shell/libshella-2.9.1.2.so
  • chmod 700 <Package Folder>/tx_shell/libufix.so
  • chmod 777 <Package Folder>/files/fplay_arthc
  • chmod 777 <Package Folder>/lhfreewildprism
  • dd if <Package Folder>/files/fplay_arthc of <Package Folder>/lhfreewildprism
  • dd if=<Package Folder>/files/fplay_arthc of=<Package Folder>/lhfreewildprism
  • getprop
  • getprop ro.aa.romver
  • getprop ro.board.platform
  • getprop ro.build.fingerprint
  • getprop ro.build.nubia.rom.name
  • getprop ro.build.rom.id
  • getprop ro.build.tyd.kbstyle_version
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.gn.gnromvernumber
  • getprop ro.lenovo.series
  • getprop ro.lewa.version
  • getprop ro.meizu.product.model
  • getprop ro.miui.ui.version.name
  • getprop ro.vivo.os.build.display.id
  • getprop ro.yunos.version
  • logcat -d -v threadtime
  • ls -l /dev
  • ls -l /dev/block
  • ls -l /dev/block/vold
  • ls -l /dev/bus
  • ls -l /dev/bus/usb
  • ls -l /dev/bus/usb/001
  • ls -l /dev/com.android.settings.daemon
  • ls -l /dev/cpuctl
  • ls -l /dev/cpuctl/apps
  • ls -l /dev/cpuctl/apps/bg_non_interactive
  • ls -l /dev/graphics
  • ls -l /dev/input
  • ls -l /dev/log
  • ls -l /dev/pts
  • ls -l /dev/snd
  • ls -l /dev/socket
  • ls /sys/class/thermal
  • ps
  • sh
  • sh ./fplay_arthc
Loads the following dynamic libraries:
  • Bugly
  • cocos2dcpp
  • engine
  • libnfix
  • libshella-2.9.1.2
  • libufix
  • libyaqbasic.36117467
  • libyaqbasic.91475202
  • libyaqpro.36117467
  • libyaqpro.91475202
  • n1300f
  • nfix
  • ufix
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • AES-GCM-NoPadding
  • DES-CBC-PKCS5Padding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • AES-GCM-NoPadding
  • DES
  • DES-CBC-PKCS5Padding
  • RSA-ECB-PKCS1Padding
Uses special library to hide executable bytecode.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Gets information about running apps.
Displays its own windows over windows of other apps.
Parses information from SMS.
Gets information about sent/received SMS.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android