マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Android.DownLoader.1939

Added to the Dr.Web virus database: 2017-04-01

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Loki.15.origin
  • Android.SmsSend.15976
  • Android.Backdoor.336.origin
  • Android.Loki.10.origin
Downloads the following detected threats from the Web:
  • Android.Backdoor.336.origin
Network activity:
Connecting to:
  • and####.####.com
  • p####.####.com
  • faceboo####.link
  • a####.####.plus
  • we####.com
  • aurora-####.####.com
  • i####.####.com
  • woo####.com:7077
  • ip####.io
  • sm-camp####.####.com
  • quede####.com
  • m####.####.com
  • statist####.com
  • md-41####.####.org
  • p####.####.com:3090
  • a####.####.com
  • t####.####.com
  • we####.com:8081
  • g####.####.com
  • c####.####.net
  • l####.####.net
  • c####.####.com
  • d####.####.com
  • e####.####.com
HTTP GET requests:
  • c####.####.com/landings/76902/1483451033/images/frl1.jpg
  • md-41####.####.org/logo/bf6daadda269968787bcbe0e15a0820e92226003.png
  • a####.####.com/c/d
  • md-41####.####.org/logo/4c70d14756c1c0891c24a3027867d98aa24caa5f.png
  • faceboo####.link/c/da57dc555e50572d?s1=####&s2=####&s3=####&click_id=####
  • e####.####.com/thinking/group/test4
  • quede####.com/99Q12/OjkYdA/Ljpd/KjdMJ2k/eHIafDNiK1N-ulas0aXWWjGkEszX8e0Bi1iEcqOBRBoJJVfUXE-L/fGdNIjpnMgQs6wby0_XIDxaypLy4U5M?jch=####
  • a####.####.com/pull/top_offer?gaid=####&id=####
  • md-41####.####.org/logo/4500e93798c40e8349d742cdfbbbe5b929f29f6e.png
  • sm-camp####.####.com/resource/icons/source_1_prod_21_source_17_prod_22_1DgHNL48SN1x5Y6E0jMnGIbnLhYpnCTXIKL_qMzzClwPwq7Vsyc_ZIykj9n4PNW5HQ%253Dw300
  • c####.####.net/games/icons/000/002/832/dimension_150x150.jpg?2017033####
  • c####.####.com/landings/76902/1483451033/css/style.css?148345####
  • i####.####.com/tracking/adBulkImpression?d=####
  • aurora-####.####.com/resource/icons/source_1_prod_62_source_2_prod_63_1464860481_931305.jpg
  • a####.####.plus/api/getADConfig?app_key=####&duid=####&sdk_version=####&gaid=####&sub=####&vs=####
  • sm-camp####.####.com/resource/icons/source_3_prod_1638_1df6ee29deeb4dd6872a0496e9032cdc.png
  • c####.####.net/games/icons/001/016/649/dimension_150x150.jpg?2017033####
  • c####.####.net/games/icons/001/009/820/dimension_150x150.jpg?2016120####
  • sm-camp####.####.com/resource/icons/source_1_prod_1807_source_17_prod_2419_CGCtfuS-ISG9UVy0EKYq9Ikon2dKS-0uXwtdldpe8LR39J7QVbRtVry5-KCQ7M4Ao1FP%253Dw3...
  • c####.####.net/games/icons/001/007/140/dimension_150x150.jpg?2017033####
  • c####.####.com/landings/76902/1483451033/js/function.js?148345####
  • c####.####.net/games/icons/001/011/142/dimension_150x150.jpg?2017032####
  • c####.####.net/games/icons/001/015/455/dimension_150x150.jpg?2017033####
  • ip####.io/json
  • c####.####.net/games/icons/001/014/980/dimension_150x150.jpg?2016120####
  • aurora-####.####.com/resource/icons/source_1_prod_3_source_2_prod_3_1ffbc6b9ade514f3975dabb118c896b1.png
  • e####.####.com/thinking/group/exp
  • c####.####.net/games/icons/001/007/263/dimension_150x150.jpg?2017032####
  • faceboo####.link/c/679efeecdc3b4d07?&ijykJHsadL5=####&click_id=####&s1=####&s2=####&s3=####&s5=####
  • c####.####.com/landings/76902/1483451033/images/frl3.jpg
  • c####.####.net/games/icons/001/010/375/dimension_150x150.jpg?2016120####
  • sm-camp####.####.com/resource/icons/source_1_prod_220_source_17_prod_222_K9czCJMDj3G4AUonnuDi6yYgbQ37vgIcRygRzzF36r79nfitFFBIrYdMxia-LvXJxKE%253Dw300
  • aurora-####.####.com/resource/icons/source_1_prod_10_source_2_prod_10_17f84c08a394b36e6949770fd6129ede.png
  • d####.####.com/thinking/group/rtt0319_662.apk
  • quede####.com/99Q12/Ljpd/ID5N/eHIafDNiK1N-ulas0aXWWjGkEszX8e0Bi1iEcqOBRBoJJVfUXE-L?KjM=####
  • e####.####.com/thinking/group/ym32
  • c####.####.net/games/icons/001/019/037/dimension_150x150.jpg?2017033####
  • c####.####.net/games/icons/001/011/249/dimension_150x150.jpg?2017033####
  • c####.####.com/landings/76902/1483451033/images/frl2.jpg
  • c####.####.net/games/icons/001/010/375/dimension_150x150.jpg?2017033####
  • sm-camp####.####.com/resource/icons/source_1_prod_20_source_17_prod_21_cvBWFUQavWhjNRJPthHH7uH8OGuoMnF15HktNjrbEj6VA56phkdYCdBSLIgpSVa8Fw%253Dw300
  • c####.####.net/games/icons/001/008/673/dimension_150x150.jpg?2017032####
  • e####.####.com/thinking/group/onemain/mainp.apk
  • c####.####.com/landings/76902/1483451033/js/avsc2.js?148345####
  • a####.####.com/v3/api/nativeads?&publisherid=####&slotid=####&lang=####&timestamp=####&platform=####&osv=####&dpi=####&tzone=####&aid=####&orientation...
  • c####.####.net/games/icons/001/004/767/dimension_150x150.jpg?2017033####
  • statist####.com/adv_pxl?pid=####&id=####
  • a####.####.com/mediation/config?&publisher_id=####&slot_id=####&app_id=####&platform=####&aid=####&language=####&version_code=####&osv=####&app_name=#...
HTTP POST requests:
  • a####.####.com/app_logs
  • a####.####.com/oversea_adjust_and_download_write_redis/notify/download/app
  • we####.com:8081/sm/sr/rt/ry
  • and####.####.com/rqd/async
  • p####.####.com/PlutoServer/app/getplugin/
  • we####.com/sm/sr/rt/ry
  • woo####.com:7077/sdk/nsd.action?b=####
  • t####.####.com/ggview/rsddateindex
  • g####.####.com/pilot/api/300102
  • a####.####.com/subscribe/api/1997
  • l####.####.net/gkview/info/600
  • p####.####.com:3090/PlutoServer/app/getplugin/
  • m####.####.com/errorview/api/601
  • a####.####.com/offerview/info/920
  • p####.####.com/PlutoServer/app/appinit/
Modified file system:
Creates the following files:
  • /data/data/####/databases/cc.db-journal
  • /data/data/####/shared_prefs/SSPPrefe.xml
  • /data/data/####/files/eopcmjt/libLXtzwvqtrxRlyavpdynamicloader.so
  • /data/data/####/shared_prefs/Alvin2.xml
  • /data/data/####/databases/cc.db
  • /sdcard/test
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/39ad2d3eff75116299bf808f9d2ddc9b
  • /data/data/####/shared_prefs/20160121.xml.bak
  • /data/data/####/cache/webviewCacheChromium/data_3
  • /data/data/####/cache/webviewCacheChromium/data_2
  • /data/data/####/cache/webviewCacheChromium/data_1
  • /data/data/####/cache/webviewCacheChromium/data_0
  • /data/data/####/files/eopcmjt/libnYlYSMWbGsbTavdZlala.so
  • /data/data/####/databases/webviewCookiesChromium.db-journal
  • /data/data/####/app_armeabi/libBugly.so
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/20109c903374e438c15be82a435c5a3e
  • /data/data/####/shared_prefs/umeng_general_config.xml
  • /data/data/####/files/.umeng/exchangeIdentity.json
  • /sdcard/.windy/65288c96bb8cefd3d531a278a6ac5862.tmp
  • /data/data/####/files/log/agent_log
  • /data/data/####/app_armeabi/libdaemon_api20.so
  • /data/data/####/tx_shell/libshella-2.10.1.so
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/af67e19de0453db776a027c359e96076
  • /data/data/####/files/.snow/.client
  • /sdcard/.DataStorage/ContextData.xml
  • /data/data/####/files/.snow/.zip/rt8
  • /data/data/####/files/exid.dat
  • /data/data/####/databases/webview.db-journal
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/09511ed323727fd02b9c6eb6d7fcd6e1
  • /data/data/####/shared_prefs/META_INFO.xml.bak
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/client.id
  • /data/data/####/shared_prefs/ar.xml.bak
  • /data/data/####/shared_prefs/IMDPREF.xml
  • /data/data/####/shared_prefs/share_data.xml
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/378f5f81d548fb3cef5a5b108f4e813b
  • /data/data/####/cache/webviewCacheChromium/index
  • /data/data/####/app_armeabi/liblegudb.x86.so
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/2e4c45d30fdff01358145d9da2568098
  • /data/data/####/app_bugly/rqd_record.eup
  • /sdcard/.windy/d2c2edbfd23c0e2279a83417a7e3c0db.tmp
  • /data/data/####/files/eopcmjt/libqNiSBgujjBxAEiyqzxc.so
  • /data/data/####/app_armeabi/libjni-comsysremindR002.so
  • /data/data/####/files/83bf46f2b4e35a0f9c967cd01d154a8.data
  • /data/data/####/files/.snow/.service
  • /sdcard/.windy/508e8558f784e3a21d3368e4763e2693.dat
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/f0cea11db3e2b1c5e163b9acd36e42a6
  • /data/data/####/files/.snow/.ir
  • /data/data/####/files/.snow/checkFile9
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/8007a3f4887723df20451e65a48a202e
  • /data/data/####/files/.snow/checkFile7
  • /data/data/####/shared_prefs/com.monetiseguys.adsdk.preference.xml
  • /data/data/####/files/.snow/checkFile0
  • /data/data/####/shared_prefs/Q2hhbm5lbElES2V5MjAxNjEyMjcxODU3.xml
  • /data/data/####/app_bugly/tomb_1485418453762.txt
  • /data/data/####/cache/tomb.zip
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/19cfa0b7c315c36f48ff8bd80410894c
  • /sdcard/.UTSystemConfig/Global/Alvin2.xml
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/409d9061ef061d4270c9a4cb8b5852f0
  • /data/data/####/files/nYlYSMWbGsbTavdZlala.jar
  • /data/data/####/databases/webviewCookiesChromium.db.mirror
  • /data/data/####/app_bugly/tomb_1485418424179.txt
  • /data/data/####/app_armeabi/liblegudb.so
  • /data/data/####/files/.snow/.center.tapk
  • /data/data/####/files/.snow/exp
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/f6ea94b44a78665c5b364210f198eda7
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/7c6a32a46f8cf8802e156b1bd68bf21f
  • /data/data/####/files/LXtzwvqtrxRlyavpdynamicloader.jar
  • /data/data/####/files/.snow/.dlme.apk
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/521e342cf85eb122fd3aa52891d406be
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/13210bff4393669431dd9f50007e3412
  • /data/data/####/files/umeng_it.cache
  • /data/data/####/files/security_info
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/334e612a821e874b7a39e4647eaaa63e
  • /data/data/####/databases/bugly_db_legu.mirror
  • /data/data/####/app_armeabi/libdaemon_api21.so
  • /data/data/####/files/local_crash_lock
  • /data/data/####/files/log/crash_log
  • /data/data/####/files/native_record_lock
  • /sdcard/.windy/508e8558f784e3a21d3368e4763e2693.tmp
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/841dc7c3e0897e459b744320ec642430
  • /data/data/####/shared_prefs/META_INFO.xml
  • /data/data/####/shared_prefs/20160121.xml
  • /data/data/####/app_armeabi/libshella-2.10.1.so
  • /data/data/####/databases/ua.db
  • /data/data/####/files/AyuSnsgpJNCmGCZwdaemon.so
  • /data/data/####/files/.snow/.zip/ym
  • /data/data/####/files/.pluto_lib/c58507babbe4e02168755ae955472a77/pluto.apk
  • /data/data/####/files/eopcmjt/libHkvFXwaLTSDvKsFFbt.so
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/7dbde55dabdfd9d696b970cd71993c9f
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/c992b414fc27f5b0cb20c4b64c51da2d
  • /data/data/####/files/qNiSBgujjBxAEiyqzxc.jar
  • /data/data/####/app_bugly/tomb_1485418431926.txt
  • /sdcard/.windy/d2c2edbfd23c0e2279a83417a7e3c0db.dat
  • /data/data/####/databases/swith1014.db.mirror
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/339f1c7eab804b53d4366dff8cc50bea
  • /data/data/####/app_armeabi/mix.dex
  • /data/data/####/databases/ua.db.mirror
  • /data/data/####/app_armeabi/libcore.so
  • /data/data/####/mix.dex
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/125a97a3c9710f8c5ad4fec054d5c362.tmp
  • /data/data/####/files/.snow/.zip/rsh
  • /sdcard/.windy/49f19b1b089f018a1792a4c581f93d58.tmp
  • /data/data/####/databases/webview.db.mirror
  • /data/data/####/databases/ReminderDatabase-journal
  • /data/data/####/files/.default/83bf46f2b4e35a0f9c967cd01d154a8.data.temp
  • /data/data/####/app_indicators/indicator_p
  • /data/data/####/files/libcqqVdNbNsWngeIrdbootstrap.so
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/75767d94c2c49ccb0eb983b932bb1daf
  • /data/data/####/files/.snow/supolicy
  • /data/data/####/files/.snow/.zip/post.sh
  • /data/data/####/app_indicators/indicator_d
  • /data/data/####/tx_shell/libufix.so
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/3e4c73fa708f9dee6b9ef5e4a8d36731
  • /data/data/####/files/.snow/.zip/boy
  • /data/data/####/databases/ReminderDatabase.mirror
  • /data/data/####/files/HkvFXwaLTSDvKsFFbt.jar
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/8352fd113125b1f8d5c4052d12ac0032
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/d07e53406981e6a58311440a63b7cd76
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/634cd6783e3a759f8f480738a2b639ba
  • /data/data/####/shared_prefs/####_preferences.xml
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/9cf061bccceade79458fe8d5e2c5f5b3
  • /data/data/####/files/c201704011350.apk
  • /data/data/####/files/.snow/.zip/r4
  • /data/data/####/files/.snow/.zip/r1
  • /data/data/####/files/.snow/.zip/r3
  • /data/data/####/files/.snow/.zip/r2
  • /data/data/####/shared_prefs/SSPPrefe.xml.bak
  • /data/data/####/databases/ua.db-journal
  • /data/data/####/tx_shell/libnfix.so
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/163881f3e8fe796f182b68ddea55e106
  • /data/data/####/files/.work/postroot.sh
  • /data/data/####/app_armeabi/libcqqVdNbNsWngeIrdbootstrap.so
  • /data/data/####/app_armeabi/libXUSqbOmGAtoCLrCTdaemon.so
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/af8a4b87d7175e499d813e6190c57c81
  • /data/data/####/app_armeabi/mixz.dex
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/2e4f22fed4837b10b1c1a3e38b9479eb
  • /data/data/####/files/.snow/busybox
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/f5c51fb8096b0f473d9ae6da8437855c
  • /data/data/####/files/.imprint
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/6080e95505124975e564e6e0650a5b83
  • /data/data/####/databases/bdownloaders.db.mirror
  • /data/data/####/shared_prefs/ContextData.xml
  • /data/data/####/databases/bdownloaders.db-journal
  • /data/data/####/files/.snow/checkFile13
  • /data/data/####/files/201704011350.apk
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/f3113fc4a940c1a02193ce92b56fcccd
  • /data/data/####/databases/swith1014.db-journal
  • /data/data/####/shared_prefs/duspf6030945.xml
  • /data/data/####/shared_prefs/####_preferences.xml.bak
  • /data/data/####/shared_prefs/umeng_general_config.xml.bak
  • /data/data/####/databases/bugly_db_legu-journal
  • /data/data/####/files/.snow/.uok
  • /data/data/####/shared_prefs/com.monetiseguys.adsdk.preference.xml.bak
  • /data/data/####/files/.default/.p.apk
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/dd32ad9afaba078fbb9279bcb49efa4e
  • /data/data/####/files/.snow/.zip/mkdevsh
  • /data/data/####/shared_prefs/ar.xml
  • /data/data/####/databases/cc.db.mirror
  • /sdcard/.pluto_data/c58507babbe4e02168755ae955472a77/images/280fef2cea71df13c73804fc0ff98117
Sets the 'executable' attribute to the following files:
  • /data/data/####/tx_shell/libufix.so
  • /data/data/####/files/.snow/.zip/r2
  • /data/data/####/files/c201704011350.apk
  • /data/data/####/files/.snow/.zip/r4
  • /data/data/####/files/.snow/.zip/r1
  • /data/data/####/files/.snow/.service
  • /data/data/####/files/.snow/.zip/r3
  • /data/data/####/files/.snow/busybox
  • /data/data/####/tx_shell/libnfix.so
  • /data/data/####/files/.work/postroot.sh
  • /data/data/####/files/.snow/.ir
  • /data/data/####/app_bugly/tomb_1485418431926.txt
  • /data/data/####/app_bugly/tomb_1485418453762.txt
  • /data/data/####/tx_shell/libshella-2.10.1.so
  • /data/data/####/files/.snow/.client
  • /data/data/####/files/.snow/.zip/rt8
  • /data/data/####/app_bugly/tomb_1485418424179.txt
  • /data/data/####/files/.snow/.zip/rsh
  • /data/data/####/files/.snow/exp
  • /data/data/####/files/.snow/.uok
  • /data/data/####/files/.snow/.zip/mkdevsh
  • /data/data/####/files/.snow/supolicy
  • /data/data/####/files/.snow/.zip/post.sh
Miscellaneous:
Uses special library to hide executable bytecode.
Contains functionality to send SMS messages automatically.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android