Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Android.Locker.17979

Added to the Dr.Web virus database: 2024-03-22

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Locker.1475.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.0) sun####.use####.com:443
  • TCP(TLS/1.0) gmscomp####.google####.com:443
  • TCP(TLS/1.0) cdn1d-s####.ph####.com:443
  • TCP(TLS/1.0) u####.com:443
  • TCP(TLS/1.0) s####.g.doublec####.net:443
  • TCP(TLS/1.0) www.por####.com:443
  • TCP(TLS/1.0) o####.vk.com:443
  • TCP(TLS/1.0) connect####.gst####.com:443
  • TCP(TLS/1.0) st####.ho####.com:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) h####.por####.com:443
  • TCP(TLS/1.0) cdn1-sm####.ph####.com:443
  • TCP(TLS/1.0) sc####.ho####.com:443
  • TCP(TLS/1.0) sto####.google####.com:443
  • TCP(TLS/1.0) i####.vk.com:443
  • TCP(TLS/1.0) rr9---s####.g####.com:443
  • TCP(TLS/1.0) analy####.go####.com:443
  • TCP(TLS/1.0) a####.vk.com:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) www.go####.ru:443
  • TCP(TLS/1.2) p####.google####.com:443
  • TCP(TLS/1.2) and####.cli####.go####.com:443
  • TCP(TLS/1.2) 74.1####.131.94:443
  • TCP(TLS/1.2) 74.1####.131.101:443
  • TCP(TLS/1.2) rr9---s####.g####.com:443
  • TCP(TLS/1.2) 64.2####.161.138:443
  • UDP gmscomp####.google####.com:443
  • UDP rr2---s####.g####.com:443
DNS requests:
  • a####.vk.com
  • analy####.go####.com
  • and####.cli####.go####.com
  • cdn1-sm####.ph####.com
  • cdn1d-s####.ph####.com
  • connect####.gst####.com
  • digital####.google####.com
  • ei.ph####.com
  • gmscomp####.google####.com
  • h####.por####.com
  • i####.vk.com
  • l####.vk.com
  • m####.traffic####.net
  • o####.vk.com
  • p####.google####.com
  • pla####.googleu####.com
  • rr2---s####.g####.com
  • rr9---s####.g####.com
  • s####.g.doublec####.net
  • sc####.ho####.com
  • ss.ph####.com
  • st####.ho####.com
  • st####.vk.com
  • sto####.google####.com
  • sun####.use####.com
  • u####.com
  • www.go####.com
  • www.go####.ru
  • www.google####.com
  • www.google-####.com
  • www.googlet####.com
  • www.por####.com
File system changes:
Creates the following files:
  • /data/data/####/00b8f7dd06b5077f_0
  • /data/data/####/0288f145269a1d9f_0
  • /data/data/####/07487728143176b3_0
  • /data/data/####/0788931a1a455b0b_0
  • /data/data/####/091770d4d798b659_0
  • /data/data/####/091770d4d798b659_0 (deleted)
  • /data/data/####/0986648ba8488d62_0
  • /data/data/####/0a364fb28e1eff70_0
  • /data/data/####/0baea7948606e3b1_0
  • /data/data/####/0baea7948606e3b1_0 (deleted)
  • /data/data/####/0ce153fe0c38db33_0
  • /data/data/####/0f83bf3ecb91dcc4_0
  • /data/data/####/11d75f4536d7ed49_0
  • /data/data/####/11e6d0c100ef6553_0
  • /data/data/####/11e6d0c100ef6553_1
  • /data/data/####/138ce075d033537d_0
  • /data/data/####/15f8932287d876e2_0
  • /data/data/####/16f51878287575a3_0
  • /data/data/####/1789f426c57381ee_0
  • /data/data/####/18b971898f62199a_0
  • /data/data/####/19a3a076856b51e4_0
  • /data/data/####/19a3a076856b51e4_0 (deleted)
  • /data/data/####/1b397839ddfc5955_0
  • /data/data/####/1b57e9a0e92112a8_0
  • /data/data/####/1bbce5d45ed5fe5a_0
  • /data/data/####/1c51e192d205be56_0
  • /data/data/####/1c51e192d205be56_0 (deleted)
  • /data/data/####/1ecf4e4d63dfe6af_0
  • /data/data/####/1ecf4e4d63dfe6af_0 (deleted)
  • /data/data/####/1f4083e14aaf2f8b_0
  • /data/data/####/1f5386163e1d3505_0
  • /data/data/####/1fda99d0c2eaf8cb_0
  • /data/data/####/1fda99d0c2eaf8cb_1
  • /data/data/####/1fe2a1c3956b0293_0
  • /data/data/####/20228e4c5f180e22_0
  • /data/data/####/209ca5920ca6490c_0
  • /data/data/####/20e140c7275d4a36_0
  • /data/data/####/21bdf2d67bb9c4a9_0 (deleted)
  • /data/data/####/2322703455c315e6_0 (deleted)
  • /data/data/####/2940195bd9870d6e_0
  • /data/data/####/2940195bd9870d6e_1
  • /data/data/####/2a1ac2855cb07f3c_0
  • /data/data/####/2b50071db951b078_0
  • /data/data/####/2cc80dabc69f58b6_0
  • /data/data/####/2d692dc02629ecc1_0
  • /data/data/####/2de80fe66af549a1_0
  • /data/data/####/2e4fdf2369489403_0
  • /data/data/####/2e7b9d78d88a1409_0
  • /data/data/####/2fc06c91053754df_0
  • /data/data/####/2fc06c91053754df_0 (deleted)
  • /data/data/####/2fd39fa451651e9f_0
  • /data/data/####/302fbdf32d767003_0
  • /data/data/####/302fbdf32d767003_0 (deleted)
  • /data/data/####/31827a3183f99724_0
  • /data/data/####/325f5c919b678838_0
  • /data/data/####/325f5c919b678838_0 (deleted)
  • /data/data/####/33722cf88a938c86_0
  • /data/data/####/33b47afb1195617a_0
  • /data/data/####/354e063309954807_0
  • /data/data/####/354e063309954807_1
  • /data/data/####/3696f68521dc36bb_0
  • /data/data/####/3696f68521dc36bb_0 (deleted)
  • /data/data/####/369b0771fb9365a2_0
  • /data/data/####/38a4582924540585_0
  • /data/data/####/39362e6494ed19cc_0
  • /data/data/####/39362e6494ed19cc_1
  • /data/data/####/3a31d6041484cb8a_0
  • /data/data/####/3a31d6041484cb8a_1
  • /data/data/####/3b585071f7fa0da1_0
  • /data/data/####/3b585071f7fa0da1_0 (deleted)
  • /data/data/####/3ea4d78ea985ea67_0
  • /data/data/####/3ebf402d69629be6_0
  • /data/data/####/3fe887253b741b15_0
  • /data/data/####/3ff34dc9d2ab4b3d_0
  • /data/data/####/40beb0ad5d29023c_0
  • /data/data/####/4304d8e949fc40b1_0
  • /data/data/####/430a48aaddf9e67b_0
  • /data/data/####/44a8721f73bca5d9_0
  • /data/data/####/454a11e8855b60b1_0
  • /data/data/####/461b605a9f07e4d2_0
  • /data/data/####/461b605a9f07e4d2_0 (deleted)
  • /data/data/####/46618695e86f2d0a_0
  • /data/data/####/48272cc2a8051d34_0
  • /data/data/####/482f58354005718a_0
  • /data/data/####/482f58354005718a_1
  • /data/data/####/488fc84fd245f3fb_0
  • /data/data/####/488fc84fd245f3fb_0 (deleted)
  • /data/data/####/4964f155836b7037_0
  • /data/data/####/49a60a6ddd4c26d7_0
  • /data/data/####/4a3fa22bf20a3a23_0
  • /data/data/####/4a729048aa73aca3_0
  • /data/data/####/4aa9d38a8de5430a_0 (deleted)
  • /data/data/####/4bcd0c66adc69813_0
  • /data/data/####/4bcd0c66adc69813_1
  • /data/data/####/4c623feaf48dbd64_0
  • /data/data/####/4cb013792b196a35_0
  • /data/data/####/4cb013792b196a35_1
  • /data/data/####/4e22d17b34b8f30d_0
  • /data/data/####/4ecb39dc65e13f11_0
  • /data/data/####/4ed0070704a56e97_0
  • /data/data/####/4ed7c7240bfdfef8_0
  • /data/data/####/4eecd32344c4fe35_0
  • /data/data/####/5026cef840ebe16c_0
  • /data/data/####/51601d3d55b76398_0
  • /data/data/####/518fac0b5057aba6_0
  • /data/data/####/518fac0b5057aba6_1
  • /data/data/####/554fc100bf62286d_0
  • /data/data/####/554fc100bf62286d_0 (deleted)
  • /data/data/####/5675426d887a623d_0
  • /data/data/####/56c5d77ae254a86f_0
  • /data/data/####/56c5d77ae254a86f_0 (deleted)
  • /data/data/####/578e3b30163dab41_0
  • /data/data/####/5816d2625538cec3_0
  • /data/data/####/5816d2625538cec3_1
  • /data/data/####/58246537f2bb0f4e_0
  • /data/data/####/58246537f2bb0f4e_0 (deleted)
  • /data/data/####/5b3c9faadf07966b_0
  • /data/data/####/5b3c9faadf07966b_1
  • /data/data/####/5d5f5dac1beceadc_0
  • /data/data/####/5f871d301a72e2cc_0
  • /data/data/####/5fa35c56c4f1ca2d_0
  • /data/data/####/5fa35c56c4f1ca2d_0 (deleted)
  • /data/data/####/5fa51d2a581e6c14_0
  • /data/data/####/601f98d205444d2f_0
  • /data/data/####/61a537e0025801b5_0
  • /data/data/####/62c7a4b13f61aac3_0
  • /data/data/####/6361971b6eff071b_0
  • /data/data/####/64c9cbb28868be6a_0
  • /data/data/####/667a27c0a9e90a1f_0
  • /data/data/####/66f53875ef135f74_0
  • /data/data/####/677c6fca3a7d6465_0
  • /data/data/####/68c4dad70735f4e7_0
  • /data/data/####/6a183740cfc79df8_0
  • /data/data/####/6a183740cfc79df8_0 (deleted)
  • /data/data/####/6aa22650b47092a6_0
  • /data/data/####/6d2b1920660b91a3_0
  • /data/data/####/6d395b4260819868_0
  • /data/data/####/6d6381b1d0fd4f41_0
  • /data/data/####/6d6381b1d0fd4f41_1
  • /data/data/####/6e0e18b6803538da_0
  • /data/data/####/7075c7014ce5d516_0
  • /data/data/####/70fc6d057ae6906b_0
  • /data/data/####/70fc6d057ae6906b_0 (deleted)
  • /data/data/####/71f58dd2db28bab0_0
  • /data/data/####/72a80c29e7e4b304_0
  • /data/data/####/72a80c29e7e4b304_0 (deleted)
  • /data/data/####/731aaea9660fa841_0
  • /data/data/####/733604b1f706e994_0
  • /data/data/####/73719fc6d66b82df_0
  • /data/data/####/7417c269a3ff921c_0
  • /data/data/####/74317f94aa15fca0_0
  • /data/data/####/74e952e675561c87_0
  • /data/data/####/75b55804c44ec152_0
  • /data/data/####/75b55804c44ec152_1
  • /data/data/####/77617333d7b2b7d4_0
  • /data/data/####/79047a0613c08b22_0
  • /data/data/####/794f1c82b5139bad_0
  • /data/data/####/79fbda025aa6fb4c_0
  • /data/data/####/79fcd7885f65b56f_0
  • /data/data/####/7a4407eae2a435a1_0
  • /data/data/####/7aab4d1e49f73e87_0
  • /data/data/####/7e48091a74668621_0
  • /data/data/####/7e48091a74668621_0 (deleted)
  • /data/data/####/7f67230712f25f00_0
  • /data/data/####/7f67230712f25f00_0 (deleted)
  • /data/data/####/8145993ceeceaa21_0 (deleted)
  • /data/data/####/82691b748d9f9bf0_0
  • /data/data/####/82691b748d9f9bf0_0 (deleted)
  • /data/data/####/82c72f3dca473120_0
  • /data/data/####/83e26ea99c347781_0
  • /data/data/####/84e90743bae8d018_0
  • /data/data/####/8534d70a1f65cd9c_0
  • /data/data/####/8888bac454c36fa6_0
  • /data/data/####/8888bac454c36fa6_1
  • /data/data/####/8888bac454c36fa6_1 (deleted)
  • /data/data/####/8999481908a47166_0
  • /data/data/####/89faca86f37c5f9c_0
  • /data/data/####/8af2a919f5675156_0
  • /data/data/####/902f3d2bd23e797d_0
  • /data/data/####/92dda78f19b4482c_0
  • /data/data/####/92dda78f19b4482c_0 (deleted)
  • /data/data/####/93573d65da76104d_0
  • /data/data/####/9402ef73a016ffbb_0
  • /data/data/####/949d0cb185d4e4b1_0
  • /data/data/####/95b1e05494e4cff7_0
  • /data/data/####/95cae56d052c205b_0
  • /data/data/####/982b1891059858a9_0
  • /data/data/####/9afc16a6650352e0_0
  • /data/data/####/9afc16a6650352e0_1
  • /data/data/####/9e61552832a50985_0
  • /data/data/####/9fa18ca32fbecddb_0
  • /data/data/####/CURRENT
  • /data/data/####/Cookies-journal
  • /data/data/####/Databases.db-journal
  • /data/data/####/MANIFEST-000001
  • /data/data/####/OCbBHJwqTBDXoh.dex
  • /data/data/####/OMauueEDwYp.dex
  • /data/data/####/OMauueEDwYp.dex.flock (deleted)
  • /data/data/####/QuotaManager-journal
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/XAgVyDhZWDJyF.dex
  • /data/data/####/XAgVyDhZWDJyF.dex.flock (deleted)
  • /data/data/####/a062df3131afc54e_0
  • /data/data/####/a1a0eb390b604316_0
  • /data/data/####/a1a0eb390b604316_1
  • /data/data/####/a317d8b09bea59df_0
  • /data/data/####/a317d8b09bea59df_0 (deleted)
  • /data/data/####/a46130d10cbbd6d1_0
  • /data/data/####/a50f08eac5f28fcf_0
  • /data/data/####/a903a9b6a7699fa9_0 (deleted)
  • /data/data/####/a97da596e5214df1_0
  • /data/data/####/a9fb05ac05a9f2cb_0
  • /data/data/####/ad582fdd06fb34fd_0
  • /data/data/####/ad582fdd06fb34fd_0 (deleted)
  • /data/data/####/ad5f0ab47419c954_0
  • /data/data/####/ae97ee15aa894569_0
  • /data/data/####/ae97ee15aa894569_1
  • /data/data/####/aeafe34adc808330_0
  • /data/data/####/aeafe34adc808330_1
  • /data/data/####/b0ab10a1e5c17ceb_0
  • /data/data/####/b0ab10a1e5c17ceb_1
  • /data/data/####/b1995a046364a8a8_0
  • /data/data/####/b1995a046364a8a8_1
  • /data/data/####/b232c7b8c61fc373_0 (deleted)
  • /data/data/####/b35ec17b7804f676_0
  • /data/data/####/b372591c1d4992a7_0
  • /data/data/####/b6005ed34a8f2253_0
  • /data/data/####/b6543e6523502985_0
  • /data/data/####/b7bda711931af62b_0
  • /data/data/####/b7bda711931af62b_0 (deleted)
  • /data/data/####/b847531a252dd22e_0
  • /data/data/####/b847531a252dd22e_1
  • /data/data/####/b97521682eb94942_0
  • /data/data/####/b97521682eb94942_0 (deleted)
  • /data/data/####/b9fa3f927c775ca3_0
  • /data/data/####/b9fa3f927c775ca3_0 (deleted)
  • /data/data/####/bc17e336c4e353f0_0
  • /data/data/####/be97427b03d8575a_0
  • /data/data/####/c07d78cdfd2fcace_0
  • /data/data/####/c07d78cdfd2fcace_1
  • /data/data/####/c0b3a98a37384442_0
  • /data/data/####/c17a399374af1f2b_0
  • /data/data/####/c1eb451e8463a640_0
  • /data/data/####/c24a544b58357c9f_0
  • /data/data/####/c24a544b58357c9f_1
  • /data/data/####/c261c09d2747368a_0
  • /data/data/####/c261c09d2747368a_0 (deleted)
  • /data/data/####/c30477915f41e1d4_0
  • /data/data/####/c30477915f41e1d4_0 (deleted)
  • /data/data/####/c3ad037f6aa07275_0
  • /data/data/####/c3ad037f6aa07275_0 (deleted)
  • /data/data/####/c41f142177a71782_0
  • /data/data/####/c41f142177a71782_1
  • /data/data/####/c42ced0c58dfae8b_0
  • /data/data/####/c65dae96f96cc834_0
  • /data/data/####/c65dae96f96cc834_0 (deleted)
  • /data/data/####/c6b6afacd9490517_0
  • /data/data/####/c72d6fba44b6df57_0
  • /data/data/####/c77a5b8856003648_0
  • /data/data/####/c7da7fc1fd72af35_0
  • /data/data/####/c7e77ecac7260d96_0
  • /data/data/####/c96d7944a0933d1f_0
  • /data/data/####/cLclWop.dex
  • /data/data/####/cLclWop.dex.flock (deleted)
  • /data/data/####/ca81abc6757c617e_0
  • /data/data/####/cc08e9a3c537a6a6_0
  • /data/data/####/ccb6ae163afebfc0_0
  • /data/data/####/ce99954b54aff87b_0
  • /data/data/####/ce99954b54aff87b_0 (deleted)
  • /data/data/####/cf92d750413a575d_0
  • /data/data/####/cfd1329b8c038b95_0
  • /data/data/####/com.nhq_preferences.xml
  • /data/data/####/d00edb6132ba214e_0
  • /data/data/####/d00edb6132ba214e_0 (deleted)
  • /data/data/####/d29498d32466c4a2_0
  • /data/data/####/d479f41ddbccc691_0
  • /data/data/####/d479f41ddbccc691_1
  • /data/data/####/d57c064cb162006e_0
  • /data/data/####/d5debb1bd642d91c_0
  • /data/data/####/d5debb1bd642d91c_0 (deleted)
  • /data/data/####/d646c4e5a2117ec8_0
  • /data/data/####/da656b5775b93a3c_0
  • /data/data/####/da656b5775b93a3c_0 (deleted)
  • /data/data/####/dac3805093812cfa_0
  • /data/data/####/dac9d998e0af9cbc_0
  • /data/data/####/dac9d998e0af9cbc_1
  • /data/data/####/dad378f1f69a5264_0
  • /data/data/####/e023261e66e20dd5_0
  • /data/data/####/e033319690e08440_0
  • /data/data/####/e04ecf0bca57320a_0
  • /data/data/####/e540394ad74844c3_0
  • /data/data/####/e642c89b0b5c1334_0
  • /data/data/####/ea3d8d50f8615d85_0
  • /data/data/####/ebcbdd115cf1772c_0
  • /data/data/####/ebef35fb2b0f0bf4_0
  • /data/data/####/ebef35fb2b0f0bf4_0 (deleted)
  • /data/data/####/ec7dbca9cf1791ff_0
  • /data/data/####/ee62a3850636e459_0
  • /data/data/####/ee62a3850636e459_1
  • /data/data/####/effd37cf07a9b470_0
  • /data/data/####/effd37cf07a9b470_0 (deleted)
  • /data/data/####/f1e26d66e6b1a1fb_0
  • /data/data/####/f3b9acb96c8e8ad4_0
  • /data/data/####/f3bc64089fc60292_0
  • /data/data/####/f3bc64089fc60292_1
  • /data/data/####/f59083fab2974a70_0
  • /data/data/####/f5eea42a87c2fb05_0 (deleted)
  • /data/data/####/f5fa9c6556e1c73b_0
  • /data/data/####/f5fa9c6556e1c73b_1
  • /data/data/####/f66190232104951a_0
  • /data/data/####/f66190232104951a_1
  • /data/data/####/f752dc463338e643_0
  • /data/data/####/f752dc463338e643_1
  • /data/data/####/f7885de88148296b_0
  • /data/data/####/f7885de88148296b_0 (deleted)
  • /data/data/####/f8095dc0e69b4992_0
  • /data/data/####/f82b6317d1ea8738_0
  • /data/data/####/f82b6317d1ea8738_0 (deleted)
  • /data/data/####/f8837464383b0097_0
  • /data/data/####/f8837464383b0097_0 (deleted)
  • /data/data/####/f9aedac89e038873_0
  • /data/data/####/f9d0e6498978d551_0
  • /data/data/####/f9d0e6498978d551_0 (deleted)
  • /data/data/####/fa4505d9207ea687_0
  • /data/data/####/fb22d47945ad80e1_0
  • /data/data/####/fbd3ba0341e0b989_0
  • /data/data/####/fcb7185336ff17e5_0
  • /data/data/####/fd29a675c89eb2db_0
  • /data/data/####/fd88f7dd532a57e9_0
  • /data/data/####/fe8b15318529dad9_0
  • /data/data/####/ff9690c93f6c91e2_0
  • /data/data/####/index
  • /data/data/####/metrics_guid
  • /data/data/####/temp-index
  • /data/data/####/the-real-index
  • /data/misc/####/primary.prof
Miscellaneous:
Gets information about network.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android