マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Android.SmsSend.17039

Added to the Dr.Web virus database: 2017-03-19

Virus description added:

Technical information

Malicious functions:
Sends SMS messages:
  • 12114: HZSY#####
Downloads the following detected threats from the Web:
  • Android.Packed.19209
Sends data on received text messages to remote host.
Network activity:
Connecting to:
  • d####.####.net:8080
  • mo####.####.com
  • omujr####.####.com
  • dynami####.####.com
  • d####.####.net:6677
  • a####.####.com:8700
  • d####.####.net
  • mmy####.####.com
  • b####.####.net:5050
  • vide####.####.cn
  • a####.####.com
  • priceru####.####.com
HTTP GET requests:
  • vide####.####.cn/TOUXIANGS239.png
  • vide####.####.cn/20170317/aeee849e-596a-4bf9-9fb7-74e49d8bbbe4-ipz00809jp-3.jpg
  • vide####.####.cn/20170317/1119b04b-e01d-418b-b845-7e4ced3cd148-%E7%8C%A5%E8%A4%BB%E3%81%AA%E6%80%A7%E6%AC%B2.mp4
  • vide####.####.cn/TOUXIANGS217.png
  • mmy####.####.com/mmys-cps/styleTopChlVideo.service?pageNo=####&pageSize=####&showStyle=####&rv=####&deviceId=####&uuid=####&imei=####&imsi=####&manufa...
  • vide####.####.cn/TOUXIANGS232.png
  • vide####.####.cn/20170317/62911c63-a7b8-4c15-bbae-908df8f834a6-%E7%8C%A5%E8%A4%BB%E3%81%AA%E6%80%A7%E6%AC%B21.jpg
  • vide####.####.cn/TOUXIANGS230.png
  • vide####.####.cn/20170318/d1fa2cfc-0670-4b02-960a-7d825daacd0d-QQ%E5%9B%BE%E7%89%8720170318114723.jpg
  • vide####.####.cn/20170304/68b02df9-6a80-447e-a917-5b3ebbc05b08-snis00856jp-9.jpg
  • mmy####.####.com/mmys-cps/rdContent.service?deviceId=####&uuid=####&imei=####&imsi=####&manufacturer=####&model=####&versionCode=####&ditchNo=####&app...
  • vide####.####.cn/tou2084.jpg
  • vide####.####.cn/TOUXIANGS212.png
  • vide####.####.cn/TOUXIANGS257.png
  • vide####.####.cn/tou2036.jpg
  • vide####.####.cn/TOUXIANGS228.png
  • vide####.####.cn/20170318/e4888508-a8c7-47ae-8d9b-beabdfd47fa7-banner.jpg
  • d####.####.net:8080/appstore/pri/5403ddd6ecda4977b0ac92526095b12a.apk
  • mmy####.####.com/mmys-cps/runConfig.service?deviceId=####&uuid=####&imei=####&imsi=####&manufacturer=####&model=####&versionCode=####&ditchNo=####&app...
  • vide####.####.cn/20170317/bf739e2a-c8dc-42ca-b101-b019fd57f9fe-%E4%B8%80%E8%BC%AA%E8%BB%8A%E3%80%81%E5%A9%A6%E8%AD%A6%E3%81%95%E3%82%93.jpg
  • vide####.####.cn/20170317/aa6c2a95-ee12-4034-aa98-5378c30213ce-109cm%E3%81%AEAV%E7%9B%A3%E7%9D%A3%E3%81%AB%E3%81%97%E3%81%8F%E3%82%93%E3%81%A7%E3%81%9...
  • vide####.####.cn/tou2002.jpg
  • vide####.####.cn/tou2083.jpg
  • vide####.####.cn/20170318/7ee36c90-1797-4475-8354-7f0870307597-timg.jpg
  • vide####.####.cn/20170317/9f638fff-74b3-41f7-8230-b9b4ef514e6c-%E5%B1%88%E8%BE%B1%E3%81%AE%E5%A4%B1%E7%A6%81.jpg
  • mmy####.####.com/mmys-cps/appUpgrade.service?deviceId=####&uuid=####&imei=####&imsi=####&manufacturer=####&model=####&versionCode=####&ditchNo=####&ap...
  • mmy####.####.com/mmys-cps/vdtRmdVideoList.service?showStyle=####&id=####&itemCount=####&rv=####&deviceId=####&uuid=####&imei=####&imsi=####&manufactur...
  • vide####.####.cn/tou1019.gif
  • vide####.####.cn/20160808/04ecdcac-7438-4e3b-ab8a-8a93f604f613-15_%E5%89%AF%E6%9C%AC.png
  • vide####.####.cn/TOUXIANGS254.png
  • vide####.####.cn/20170317/1dc44d36-634e-4e7f-8523-d035a6db86fa-%E6%AF%8D%E3%81%AE%E5%8F%8B%E4%BA%BA.jpg
  • vide####.####.cn/TOUXIANGS20.png
  • omujr####.####.com/parkedmmys?deviceId=####&uuid=####&imei=####&imsi=####&manufacturer=####&model=####&versionCode=####&ditchNo=####&appId=####&dcVers...
  • vide####.####.cn/TOUXIANGS23.png
  • vide####.####.cn/hao26.jpg
  • vide####.####.cn/TOUXIANGS200.png
  • vide####.####.cn/tou2037.jpg
  • vide####.####.cn/TOUXIANGS17.png
  • mmy####.####.com/mmys-cps/videoDtl.service?id=####&rv=####&deviceId=####&uuid=####&imei=####&imsi=####&manufacturer=####&model=####&versionCode=####&d...
  • d####.####.net/edt_r
  • vide####.####.cn/20170317/e836e14d-fc85-4bb9-a840-ada3bd3c2bc6-%E7%8C%A5%E8%A4%BB%E3%81%AA%E6%80%A7%E6%AC%B2.jpg
  • vide####.####.cn/20160808/166770aa-880e-4309-8204-b97955e6cb58-10.png
  • vide####.####.cn/tou2077.jpg
  • vide####.####.cn/tou2051.jpg
  • mmy####.####.com/mmys-cps/barrage3.service?videoId=####&deviceId=####&uuid=####&imei=####&imsi=####&manufacturer=####&model=####&versionCode=####&ditc...
  • vide####.####.cn/TOUXIANGS259.png
  • vide####.####.cn/TOUXIANGS187.png
  • vide####.####.cn/20170318/60535d10-c921-40ad-a75e-1709acb9a8eb-QQ%E5%9B%BE%E7%89%8720170318114418.jpg
  • vide####.####.cn/tou2023.jpg
  • mmy####.####.com/mmys-cps/runConfig.service?deviceId=####&imei=####&imsi=####&manufacturer=####&model=####&versionCode=####&ditchNo=####&appId=####&dc...
  • vide####.####.cn/TOUXIANGS262.png
  • mmy####.####.com/mmys-cps/bannerInfo.service?showStyle=####&deviceId=####&uuid=####&imei=####&imsi=####&manufacturer=####&model=####&versionCode=####&...
  • priceru####.####.com/price-rule-cmp/rule/matchRule?version=####&deviceId=####&uuid=####&imei=####&imsi=####&manufacturer=####&model=####&versionCode=#...
  • vide####.####.cn/tou2076.jpg
  • vide####.####.cn/20170317/71e2b21e-c2ee-4afc-ac44-b84552f14d0d-%E5%83%95%E3%81%A0%E3%81%91%E3%81%AE%E5%A5%B3%E6%95%99%E5%B8%AB.jpg
  • vide####.####.cn/TOUXIANGS237.png
  • mmy####.####.com/mmys-cps/videoComment2.service?videoId=####&deviceId=####&uuid=####&imei=####&imsi=####&manufacturer=####&model=####&versionCode=####...
  • vide####.####.cn/20170318/06c74910-1128-4575-9672-3ab8ea9bf53f-oba00312jp-9.jpg
  • vide####.####.cn/TOUXIANGS186.png
  • vide####.####.cn/TOUXIANGS246.png
  • vide####.####.cn/TOUXIANGS261.png
  • vide####.####.cn/tou2032.jpg
HTTP POST requests:
  • mmy####.####.com/mmys-cps/lookVideoStat.service?videoId=####&isRmd=####&deviceId=####&uuid=####&imei=####&imsi=####&manufacturer=####&model=####&versi...
  • mmy####.####.com/mmys-cps/userVisit.service?deviceId=####&uuid=####&imei=####&imsi=####&manufacturer=####&model=####&versionCode=####&ditchNo=####&app...
  • a####.####.com:8700/
  • d####.####.net/
  • mmy####.####.com/mmys-cps/userActivation.service?deviceId=####&uuid=####&imei=####&imsi=####&manufacturer=####&model=####&versionCode=####&ditchNo=###...
  • mo####.####.com/mobile-service/getImsiMobilePhone.json
  • a####.####.com/
  • d####.####.net:6677/
  • b####.####.net:5050/
  • mmy####.####.com/sdk-update/sdkUpdateCdnUpload.json
  • dynami####.####.com/dynamicpay//getSyFormalChannels.json?
Modified file system:
Creates the following files:
  • /data/data/####/cache/picasso-cache/42a5a445d089d2572ca14cc3c3d029e2.1.tmp
  • /sdcard/.s_d_p/.im
  • /data/data/####/cache/picasso-cache/5f9e4bdd09cf1eccbb9b35fbdcade056.1.tmp
  • /data/data/####/cache/picasso-cache/a6213fd5faccb13b505167ad47ba38c4.0.tmp
  • /data/data/####/files/f6.c
  • /data/data/####/cache/picasso-cache/40f6fc703f5dc085970faf33cbe6384b.1.tmp
  • /data/data/####/shared_prefs/uuid.xml
  • /data/data/####/cache/picasso-cache/7ee7397be279789853854fefa9c455c7.0.tmp
  • /data/data/####/cache/picasso-cache/c92a26012d42102a1accd7e8bdb9ddc7.0.tmp
  • /data/data/####/cache/picasso-cache/1ebc7023e8cae9e5e8aea1caf9804bec.0.tmp
  • /data/data/####/files/da9e6f7ed6a2bfac/75dd2ede-69fc-4a07-b676-54deebc36161.zip
  • /data/data/####/cache/picasso-cache/de3172af728070c838650da3d45090dc.1.tmp
  • /data/data/####/cache/picasso-cache/e000601d6a1d333db781c99f86fa002b.0.tmp
  • /data/data/####/databases/webview.db-journal
  • /data/data/####/cache/picasso-cache/40f6fc703f5dc085970faf33cbe6384b.0.tmp
  • /data/data/####/shared_prefs/p_config.xml
  • /data/data/####/files/gaClientId
  • /data/data/####/databases/sy_video_data_cache-journal
  • /data/data/####/cache/picasso-cache/journal.tmp
  • /data/data/####/cache/picasso-cache/5768cb430a7152c65ba9d2c97a851560.0.tmp
  • /data/data/####/cache/picasso-cache/56d9c76fb6ba6598d681d73378aef47c.1.tmp
  • /data/data/####/databases/statistics_db
  • /data/data/####/cache/picasso-cache/cfae695c216d38426f0ccb12ecc8146f.1.tmp
  • /data/data/####/cache/picasso-cache/648b7a2566ac9300131ddd4fd6818fed.1.tmp
  • /data/data/####/cache/picasso-cache/7ee7397be279789853854fefa9c455c7.1.tmp
  • /data/data/####/cache/picasso-cache/c8f6800f50b1513f4b2385de2b451af0.1.tmp
  • /data/data/####/cache/picasso-cache/935b2ac7769b387ff3c5d33cbf49f15b.1.tmp
  • /data/data/####/cache/picasso-cache/166c423b94d00074b09fa73ccd0da559.0.tmp
  • /data/data/####/cache/picasso-cache/c9eb68de1727d15631f08137c0ad965b.0.tmp
  • /data/data/####/cache/picasso-cache/a2cd96244f1be2e425784a29b25cb896.0.tmp
  • /data/data/####/cache/picasso-cache/e688cabc15e1bc608eaae664cada2f2e.0.tmp
  • /data/data/####/shared_prefs/ds_configer.xml
  • /data/data/####/cache/picasso-cache/3988b3148105b6cf8349ca0f946253b8.0.tmp
  • /data/data/####/cache/picasso-cache/a74f360db680904f1ed3c96d5a210c63.0.tmp
  • /data/data/####/cache/picasso-cache/cfae695c216d38426f0ccb12ecc8146f.0.tmp
  • /data/data/####/files/arte
  • /data/data/####/cache/picasso-cache/5768cb430a7152c65ba9d2c97a851560.1.tmp
  • /data/data/####/cache/picasso-cache/04031b061d59dd6b595c32d90205f136.0.tmp
  • /data/data/####/cache/picasso-cache/aff85b1b3a0b313dd53d09b8e2f543f1.0.tmp
  • /data/data/####/cache/picasso-cache/89d131e10fbde990a077ac34602d6bc2.1.tmp
  • /data/data/####/cache/picasso-cache/c8f6800f50b1513f4b2385de2b451af0.0.tmp
  • /data/data/####/cache/picasso-cache/b37924bbcbedfaa918a6e74d3f240f13.1.tmp
  • /data/data/####/files/dio.d
  • /data/data/####/cache/picasso-cache/e78dbc631f4074fa055503fa0c9cd3ea.1.tmp
  • /data/data/####/cache/picasso-cache/c92a26012d42102a1accd7e8bdb9ddc7.1.tmp
  • /data/data/####/cache/picasso-cache/a2cd96244f1be2e425784a29b25cb896.1.tmp
  • /data/data/####/cache/picasso-cache/2933912231905691ba9ff5a9fd0a8bec.0.tmp
  • /data/data/####/cache/picasso-cache/d2e84ebb09cd828d09532b41686c5dad.0.tmp
  • /data/data/####/cache/picasso-cache/4ec25f373f5abf4c324de19dbea33621.1.tmp
  • /data/data/####/cache/picasso-cache/e688cabc15e1bc608eaae664cada2f2e.1.tmp
  • /data/data/####/cache/picasso-cache/e9559e0796771ca91597c295c9d3823a.1.tmp
  • /data/data/####/cache/picasso-cache/6134d992660c09eb1c9586ad7a410737.0.tmp
  • /data/data/####/cache/picasso-cache/a890585c6533cb0a9e5b04fa4a7966ea.0.tmp
  • /data/data/####/cache/picasso-cache/4ec25f373f5abf4c324de19dbea33621.0.tmp
  • /data/data/####/cache/picasso-cache/1d7da624928a8eafc6816a5ca05adfd2.0.tmp
  • /data/data/####/cache/picasso-cache/dc496ffa762995da177d990c57b5870f.1.tmp
  • /data/data/####/cache/picasso-cache/dea469ac979e3a0d130b9d2a49604667.1.tmp
  • /data/data/####/cache/picasso-cache/b14bdb08771cf1e42c13a6a3f8acdb16.1.tmp
  • /data/data/####/cache/picasso-cache/aff85b1b3a0b313dd53d09b8e2f543f1.1.tmp
  • /data/data/####/cache/picasso-cache/e2f34b060eef5729d1ed79691d6af3da.1.tmp
  • /data/data/####/files/dlook
  • /data/data/####/cache/picasso-cache/c17180a8e710816f09ba393c8dda6ec7.0.tmp
  • /data/data/####/cache/picasso-cache/5f6f1375befbd75e10f754e83948d889.0.tmp
  • /data/data/####/cache/picasso-cache/6134d992660c09eb1c9586ad7a410737.1.tmp
  • /data/data/####/cache/picasso-cache/d2e84ebb09cd828d09532b41686c5dad.1.tmp
  • /data/data/####/cache/picasso-cache/35077f1da20fa256b30ce694c7069331.0.tmp
  • /data/data/####/cache/picasso-cache/dea469ac979e3a0d130b9d2a49604667.0.tmp
  • /data/data/####/cache/picasso-cache/8ccafbe5250d2c9b7e72ad57543bbef7.0.tmp
  • /data/data/####/cache/picasso-cache/a74f360db680904f1ed3c96d5a210c63.1.tmp
  • /data/data/####/cache/picasso-cache/3167fb0acc0458f3783d23c66f90af8d.0.tmp
  • /data/data/####/cache/picasso-cache/f643264bc61b36c478200be432626022.1.tmp
  • /data/data/####/cache/picasso-cache/dc496ffa762995da177d990c57b5870f.0.tmp
  • /data/data/####/databases/upgrade_app-journal
  • /data/data/####/cache/picasso-cache/648b7a2566ac9300131ddd4fd6818fed.0.tmp
  • /data/data/####/databases/statistics_db-journal
  • /data/data/####/cache/picasso-cache/3988b3148105b6cf8349ca0f946253b8.1.tmp
  • /data/data/####/cache/picasso-cache/89d131e10fbde990a077ac34602d6bc2.0.tmp
  • /data/data/####/shared_prefs/free_click_count.xml
  • /data/data/####/cache/picasso-cache/e78dbc631f4074fa055503fa0c9cd3ea.0.tmp
  • /data/data/####/cache/picasso-cache/5f9e4bdd09cf1eccbb9b35fbdcade056.0.tmp
  • /data/data/####/databases/google_analytics_v2.db-journal
  • /data/data/####/cache/picasso-cache/c9eb68de1727d15631f08137c0ad965b.1.tmp
  • /data/data/####/cache/picasso-cache/70c77d3d1c75aa75f4f296ffeb4fd3c4.1.tmp
  • /data/data/####/cache/picasso-cache/c17180a8e710816f09ba393c8dda6ec7.1.tmp
  • /data/data/####/cache/picasso-cache/de3172af728070c838650da3d45090dc.0.tmp
  • /data/data/####/cache/picasso-cache/f643264bc61b36c478200be432626022.0.tmp
  • /data/data/####/cache/picasso-cache/04031b061d59dd6b595c32d90205f136.1.tmp
  • /data/data/####/cache/picasso-cache/6ea8f9929a569b30b726ed8ac3016621.0.tmp
  • /data/data/####/cache/picasso-cache/2933912231905691ba9ff5a9fd0a8bec.1.tmp
  • /data/data/####/cache/picasso-cache/a890585c6533cb0a9e5b04fa4a7966ea.1.tmp
  • /data/data/####/cache/picasso-cache/8ccafbe5250d2c9b7e72ad57543bbef7.1.tmp
  • /data/data/####/cache/picasso-cache/f65cec726b4eb72d20c37663b3f68aca.0.tmp
  • /data/data/####/cache/picasso-cache/b37924bbcbedfaa918a6e74d3f240f13.0.tmp
  • /data/data/####/cache/picasso-cache/56d9c76fb6ba6598d681d73378aef47c.0.tmp
  • /data/data/####/cache/picasso-cache/1d7da624928a8eafc6816a5ca05adfd2.1.tmp
  • /data/data/####/cache/picasso-cache/e2f34b060eef5729d1ed79691d6af3da.0.tmp
  • /data/data/####/shared_prefs/time.xml
  • /data/data/####/databases/sy_pay_record-journal
  • /data/data/####/cache/picasso-cache/6ea8f9929a569b30b726ed8ac3016621.1.tmp
  • /data/data/####/cache/picasso-cache/f65cec726b4eb72d20c37663b3f68aca.1.tmp
  • /data/data/####/files/attd/loo/liblive.so
  • /data/data/####/cache/picasso-cache/a6213fd5faccb13b505167ad47ba38c4.1.tmp
  • /data/data/####/cache/picasso-cache/1ebc7023e8cae9e5e8aea1caf9804bec.1.tmp
  • /data/data/####/cache/picasso-cache/3167fb0acc0458f3783d23c66f90af8d.1.tmp
  • /data/data/####/cache/picasso-cache/b14bdb08771cf1e42c13a6a3f8acdb16.0.tmp
  • /data/data/####/shared_prefs/initdata_stats.xml
  • /data/data/####/cache/picasso-cache/e9559e0796771ca91597c295c9d3823a.0.tmp
  • /data/data/####/cache/picasso-cache/166c423b94d00074b09fa73ccd0da559.1.tmp
  • /data/data/####/cache/picasso-cache/5f6f1375befbd75e10f754e83948d889.1.tmp
  • /data/data/####/files/attd/loo/arte
  • /data/data/####/cache/picasso-cache/35077f1da20fa256b30ce694c7069331.1.tmp
  • /data/data/####/cache/picasso-cache/70c77d3d1c75aa75f4f296ffeb4fd3c4.0.tmp
  • /data/data/####/databases/recommend_app-journal
  • /data/data/####/databases/DATA_MF_CFG-journal
  • /data/data/####/cache/picasso-cache/42a5a445d089d2572ca14cc3c3d029e2.0.tmp
  • /data/data/####/cache/picasso-cache/935b2ac7769b387ff3c5d33cbf49f15b.0.tmp
  • /data/data/####/cache/picasso-cache/e000601d6a1d333db781c99f86fa002b.1.tmp
Sets the 'executable' attribute to the following files:
  • /data/data/####/files/dio.d
  • /data/data/####/files/f6.c
Miscellaneous:
Executes next shell scripts:
  • dumpsys meminfo
  • cat /data/anr/traces.txt
  • sh
  • procrank
Contains functionality to send SMS messages automatically.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android