マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Android.DownLoader.2098

Added to the Dr.Web virus database: 2017-04-28

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Xiny.20
Downloads the following detected threats from the Web:
  • Android.Xiny.20
Network activity:
Connecting to:
  • s####.####.com
  • mo####.####.com
  • h####.####.com
  • i####.####.com
  • j####.####.com
  • d####.####.cn
  • q####.####.com
  • c####.####.com
  • b####.####.cn
  • zj####.com
  • w####.####.com
  • mobads-####.####.com
  • m####.####.com
  • n####.####.com
  • 5####.com
  • a####.####.com
HTTP GET requests:
  • 5####.com/uploads/allimg/160527/117-16052G33K60-L.jpg
  • 5####.com/uploads/allimg/160527/124_160527203031_2.jpg
  • 5####.com/uploads/allimg/160909/117-160Z91035530-L.jpg
  • n####.####.com/ngame/icon/gg01.png
  • 5####.com/uploads/allimg/170427/140-1F42GJI20-L.jpg
  • 5####.com/uploads/allimg/160911/117-1609111049380-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G423440-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G334060-L.jpg
  • m####.####.com/images/grel.png
  • 5####.com/uploads/allimg/160527/117-16052G402220-L.jpg
  • 5####.com/uploads/allimg/170125/106-1F1251139380-L.jpg
  • 5####.com/uploads/allimg/160909/117-160Z91031100-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G50H50-L.jpg
  • 5####.com/uploads/allimg/170427/140-1F42G556010-L.jpg
  • 5####.com/uploads/allimg/170428/140-1F42QH3000-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G520420-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G510460-L.jpg
  • 5####.com/uploads/allimg/170303/139-1F3031531270-L.jpg
  • 5####.com/uploads/allimg/170311/106-1F3111126390-L.jpg
  • 5####.com/uploads/allimg/170311/106-1F3111135350-L.jpg
  • 5####.com/uploads/allimg/160911/117-1609111100390-L.jpg
  • 5####.com/uploads/allimg/170302/106-1F3021352220-L.jpg
  • m####.####.com/img/loading.gif
  • 5####.com/uploads/allimg/160911/117-160911111I10-L.jpg
  • 5####.com/uploads/allimg/170308/129-1F30Q514470-L.jpg
  • 5####.com/uploads/allimg/160527/124-16052G34Q1.jpg
  • 5####.com/uploads/allimg/160909/117-160Z91005540-L.jpg
  • 5####.com/uploads/170310/106-1F310142032591.jpg
  • mo####.####.com/cpro/ui/mads.php?code2=####
  • 5####.com/uploads/allimg/170428/106-1F42Q614550-L.jpg
  • 5####.com/uploads/allimg/170311/129-1F3111439180-L.jpg
  • m####.####.com/images/img15.png
  • 5####.com/uploads/allimg/160603/117-160603101U00-L.jpg
  • 5####.com/uploads/allimg/160909/117-160Z91023330-L.jpg
  • 5####.com/uploads/170310/106-1F310134I4141.jpg
  • 5####.com/uploads/allimg/170427/140-1F42G506380-L.jpg
  • mo####.####.com/ads/ads.appcache
  • 5####.com/uploads/allimg/170311/106-1F3111119340-L.jpg
  • mo####.####.com/ads/pa/8/__pasys_remote_banner.php?bdr=####&os=####&v=##...
  • 5####.com/uploads/allimg/170427/140-1F42G545280-L.jpg
  • 5####.com/uploads/allimg/170309/106-1F3091341330-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G153550-L.jpg
  • 5####.com/uploads/allimg/170428/140-1F42Q64J10-L.jpg
  • zj####.com/blog/pv6608?blog_id=####&pid=####&uid=####&tc_id=####&tpl_id=...
  • 5####.com/uploads/allimg/170125/106-1F1251049100-L.jpg
  • m####.####.com/images/img13.png
  • m####.####.com/images/img12.png
  • 5####.com/uploads/allimg/160603/117-1606031129320-L.jpg
  • m####.####.com/images/img17.png
  • 5####.com/uploads/allimg/160527/117-16052G352080-L.jpg
  • 5####.com/uploads/allimg/160527/124_160527181746_2.jpg
  • mo####.####.com/ads/js/c.js
  • m####.####.com/scb/sbscb/
  • 5####.com/uploads/allimg/170210/139-1F2101G4540-L.jpg
  • 5####.com/uploads/allimg/170120/106-1F1201431000-L.jpg
  • m####.####.com/images/img21.png
  • 5####.com/uploads/allimg/170428/140-1F42QF3220-L.jpg
  • 5####.com/uploads/allimg/170427/140-1F42G645260-L.jpg
  • 5####.com/uploads/allimg/170428/140-1F42QFG00-L.jpg
  • 5####.com/uploads/allimg/170309/106-1F3091349230-L.jpg
  • 5####.com/uploads/allimg/160601/117-160601102Q10-L.jpg
  • m####.####.com/images/img18.png
  • 5####.com/uploads/allimg/170428/140-1F42QA6140-L.jpg
  • m####.####.com/images/img10.png
  • 5####.com/uploads/allimg/160527/117-16052G513570-L.jpg
  • 5####.com/uploads/allimg/170117/106-1F11G142210-L.jpg
  • m####.####.com/images/img14.png
  • 5####.com/uploads/allimg/160527/117-16052G416050-L.jpg
  • j####.####.com/m/fm.js
  • 5####.com/uploads/allimg/160601/117-1606011030520-L.jpg
  • 5####.com/uploads/allimg/170123/106-1F1231513010-L.jpg
  • mo####.####.com/ads/css/min/main.css
  • m####.####.com/scb/zqjscb/
  • m####.####.com/scb/zsjscb/
  • 5####.com/uploads/allimg/170308/129-1F30Q401190-L.jpg
  • 5####.com/uploads/170426/140-1F4261G33RC.jpg
  • 5####.com/uploads/allimg/170308/106-1F30Q01Q20-L.jpg
  • 5####.com/uploads/allimg/170308/129-1F30Q43I50-L.jpg
  • 5####.com/uploads/allimg/160601/117-1606011122520-L.jpg
  • 5####.com/uploads/allimg/170308/106-1F30Q040010-L.jpg
  • 5####.com/uploads/allimg/160527/124_160527181746_4.jpg
  • 5####.com/uploads/allimg/170309/129-1F3091519200-L.jpg
  • 5####.com/uploads/allimg/170428/140-1F42Q641520-L.jpg
  • 5####.com/uploads/170118/106-1F11Q4232DT.jpg
  • m####.####.com/scb/xnscb/
  • zj####.com/blog/c6608?blogid=####&siteurl=####&siteid=####&uid=####&pid=...
  • 5####.com/uploads/allimg/160527/117-16052G253400-L.jpg
  • m####.####.com/images/hua2.jpg
  • 5####.com/uploads/allimg/160602/117-1606020944590-L.jpg
  • j####.####.com/www/jquery1.11.3.js
  • 5####.com/uploads/allimg/170303/106-1F3031415040-L.jpg
  • 5####.com/uploads/allimg/170311/129-1F3111522340-L.jpg
  • m####.####.com/images/logoimg.png
  • 5####.com/uploads/allimg/160912/117-1609121500490-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G509150-L.jpg
  • 5####.com/uploads/allimg/170427/140-1F42G456060-L.jpg
  • m####.####.com/images/img8.png
  • 5####.com/uploads/allimg/170303/139-1F303150U80-L.jpg
  • j####.####.com/js/swiper.min.js
  • 5####.com/uploads/allimg/160527/117-16052G313240-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G30K10-L.jpg
  • m####.####.com/scb/etjscb/
  • 5####.com/uploads/allimg/170427/140-1F42GH6130-L.jpg
  • 5####.com/uploads/allimg/160527/124_160527181746_3.jpg
  • 5####.com/uploads/allimg/170428/106-1F42Q543110-L.jpg
  • 5####.com/uploads/allimg/160527/124-16052G34Q1-52.jpg
  • 5####.com/uploads/allimg/160602/117-160602105R40-L.jpg
  • 5####.com/uploads/allimg/170428/140-1F42QG2300-L.jpg
  • mo####.####.com/ads/pa/8/__xadsdk__remote__8.53.jar
  • 5####.com/uploads/allimg/160602/117-1606021006110-L.jpg
  • 5####.com/uploads/allimg/160602/117-1606021100020-L.jpg
  • 5####.com/uploads/allimg/170428/140-1F42Q513190-L.jpg
  • 5####.com/uploads/allimg/160601/117-160601101S20-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G250560-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G310560-L.jpg
  • m####.####.com/images/img1.png
  • 5####.com/uploads/allimg/160918/117-16091Q025350-L.jpg
  • m####.####.com/images/ckgd.jpg
  • j####.####.com/m/fps.js
  • 5####.com/uploads/allimg/160628/117-16062Q131010-L.jpg
  • 5####.com/uploads/allimg/170427/140-1F42GAT30-L.jpg
  • 5####.com/uploads/allimg/170303/106-1F3031424450-L.jpg
  • 5####.com/uploads/allimg/170303/139-1F303145P40-L.jpg
  • 5####.com/uploads/allimg/160912/117-1609120950470-L.jpg
  • m####.####.com/scb/ldjscb/
  • 5####.com/uploads/allimg/170119/106-1F1191156060-L.jpg
  • 5####.com/uploads/allimg/160909/117-160Z91010280-L.jpg
  • j####.####.com/m/hd.js
  • m####.####.com/scb/jsjscb/
  • 5####.com/uploads/allimg/160527/117-16052G330480-L.jpg
  • 5####.com/uploads/allimg/160909/117-160Z91020320-L.jpg
  • 5####.com/uploads/allimg/170124/106-1F1241023270-L.jpg
  • d####.####.cn/jarFile/SDKAutoUpdate/giantt.jar
  • 5####.com/uploads/allimg/170308/106-1F30Q113230-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G204480-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052GH4330-L.jpg
  • 5####.com/uploads/allimg/160601/117-1606011026440-L.jpg
  • 5####.com/uploads/allimg/160909/117-160Z91026090-L.jpg
  • 5####.com/uploads/allimg/170310/106-1F3101355280-L.jpg
  • mo####.####.com/ads/js/ads.trunk.js
  • 5####.com/uploads/allimg/160911/117-1609111042260-L.jpg
  • 5####.com/uploads/allimg/160912/117-1609120952230-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G159130-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G440210-L.jpg
  • 5####.com/uploads/allimg/170308/129-1F30Q621140-L.jpg
  • mo####.####.com/ads/index.htm
  • m####.####.com/images/img6.png
  • 5####.com/uploads/allimg/170118/106-1F11Q403130-L.jpg
  • 5####.com/uploads/allimg/160527/124_160527203031_1.jpg
  • m####.####.com/scb/
  • 5####.com/uploads/allimg/170303/139-1F303151R40-L.jpg
  • 5####.com/uploads/allimg/170426/140-1F4261H2020-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G515000-L.jpg
  • h####.####.com/hm.js?28aa780####
  • 5####.com/uploads/allimg/160527/124_160527203031_4.jpg
  • n####.####.com/ngame/thf2/513303.jpg
  • 5####.com/uploads/allimg/170308/106-1F30Q04Q40-L.jpg
  • 5####.com/uploads/allimg/170307/139-1F30G60Q90-L.jpg
  • 5####.com/uploads/allimg/170303/139-1F3031504280-L.jpg
  • 5####.com/uploads/allimg/170428/106-1F42Q512020-L.jpg
  • m####.####.com/images/img11.png
  • 5####.com/uploads/allimg/160527/117-16052G34Q90-L.jpg
  • j####.####.com/mgg203.js
  • 5####.com/uploads/allimg/160911/117-1609111051310-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G446050-L.jpg
  • j####.####.com/gg.js
  • 5####.com/uploads/allimg/160527/124-16052G924330-L.jpg
  • 5####.com/uploads/allimg/160909/117-160ZZ95K90-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G512160-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G322290-L.jpg
  • m####.####.com/scb/sbscb/378524.html
  • 5####.com/uploads/allimg/170117/106-1F11G120510-L.jpg
  • 5####.com/uploads/allimg/160912/117-1609121A2550-L.jpg
  • m####.####.com/images/img16.png
  • 5####.com/uploads/allimg/160909/117-160Z9101Q10-L.jpg
  • s####.####.com/1648/1113.js
  • 5####.com/uploads/allimg/160601/117-1606011025160-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G335460-L.jpg
  • 5####.com/uploads/allimg/160527/124-16052G34Q1-51.jpg
  • n####.####.com/ngame/thf2/513304.jpg
  • 5####.com/uploads/allimg/160527/117-16052G51S00-L.jpg
  • m####.####.com/images/img20.png
  • 5####.com/uploads/allimg/160527/117-16052G404230-L.jpg
  • 5####.com/uploads/allimg/160805/117-160P51J3220-L.jpg
  • 5####.com/uploads/allimg/170307/139-1F30G612470-L.jpg
  • 5####.com/uploads/allimg/160909/117-160Z91014450-L.jpg
  • 5####.com/uploads/allimg/170308/1-1F30Q51428!3_600_600.png
  • 5####.com/uploads/allimg/160805/117-160P51J0420-L.jpg
  • m####.####.com/images/img19.png
  • 5####.com/uploads/170308/129-1F30Q5551W18.jpg
  • 5####.com/uploads/allimg/170427/140-1F42GJ0550-L.jpg
  • 5####.com/uploads/allimg/170119/106-1F119135Z30-L.jpg
  • 5####.com/uploads/allimg/170117/106-1F11G34K30-L.jpg
  • 5####.com/uploads/170311/129-1F311150611D8.jpg
  • 5####.com/uploads/allimg/170303/139-1F3031543240-L.jpg
  • 5####.com/uploads/allimg/170311/106-1F3111141140-L.jpg
  • 5####.com/uploads/allimg/160913/117-1609131544070-L.jpg
  • 5####.com/uploads/allimg/160527/124-16052G141120-L.jpg
  • 5####.com/uploads/allimg/160911/117-1609111033060-L.jpg
  • 5####.com/uploads/allimg/170309/106-1F3091050490-L.jpg
  • 5####.com/uploads/allimg/160603/117-1606031021270-L.jpg
  • 5####.com/uploads/allimg/170427/140-1F42GI3060-L.jpg
  • h####.####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&et=####&ja=####&ln...
  • m####.####.com/images/gre.png
  • 5####.com/uploads/170311/129-1F31114545E05.jpg
  • 5####.com/uploads/allimg/160527/117-16052G400550-L.jpg
  • 5####.com/uploads/allimg/170311/129-1F3111535450-L.jpg
  • m####.####.com/images/img4.png
  • 5####.com/uploads/allimg/170308/129-1F30Q536360-L.jpg
  • 5####.com/uploads/allimg/170428/140-1F42Q635260-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G31T60-L.jpg
  • 5####.com/uploads/allimg/170309/129-1F309150T50-L.jpg
  • 5####.com/uploads/allimg/170428/140-1F42Q544100-L.jpg
  • q####.####.com/stat.htm?id=####&r=####&lg=####&ntime=####&cnzz_eid=####&...
  • 5####.com/uploads/allimg/160912/117-1609121501300-L.jpg
  • 5####.com/uploads/allimg/160601/117-1606011120420-L.jpg
  • w####.####.com/core.php?web_id=####&l=####&t=####
  • n####.####.com/ngame/thf2/513305.jpg
  • 5####.com/plus/count.php?view=####&aid=####&mid=####
  • 5####.com/uploads/allimg/170310/106-1F310142Z50-L.jpg
  • 5####.com/uploads/allimg/170309/106-1F309145Q90-L.jpg
  • 5####.com/uploads/allimg/160603/117-160603101G90-L.jpg
  • j####.####.com/m/vp.js
  • 5####.com/uploads/allimg/160602/117-1606020956180-L.jpg
  • zj####.com/title/6608
  • 5####.com/uploads/allimg/160527/117-16052G25U70-L.jpg
  • 5####.com/uploads/allimg/170311/106-1F3111112160-L.jpg
  • m####.####.com/images/img7.png
  • m####.####.com/images/img2.png
  • m####.####.com/images/img3.png
  • 5####.com/uploads/allimg/160527/117-16052G155480-L.jpg
  • 5####.com/uploads/allimg/170308/106-1F30Q154080-L.jpg
  • w####.####.com/q_stat.php?id=####&l=####
  • 5####.com/uploads/allimg/160527/117-16052G256400-L.jpg
  • m####.####.com/images/hua1.jpg
  • m####.####.com/images/img9.png
  • 5####.com/uploads/allimg/160527/117-16052G350430-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G32I20-L.jpg
  • 5####.com/uploads/allimg/170428/140-1F42Q53J10-L.jpg
  • 5####.com/uploads/allimg/170303/139-1F303153K20-L.jpg
  • 5####.com/uploads/allimg/160527/124_160527203031_3.jpg
  • c####.####.com/cpro/ui/cm.js
  • m####.####.com/images/img5.png
  • 5####.com/uploads/allimg/160527/117-16052G201350-L.jpg
  • 5####.com/uploads/allimg/170308/106-1F30Q026360-L.jpg
  • i####.####.com/img/sangshizhizhan/noc/22/640x100_4.png
  • 5####.com/uploads/allimg/170308/106-1F30Q33R50-L.jpg
  • m####.####.com/css/index.css
  • j####.####.com/mgg_bottom_sys.js?248####
  • 5####.com/uploads/allimg/170118/106-1F11Q11S30-L.jpg
  • 5####.com/uploads/allimg/160912/117-1609121A5570-L.jpg
  • 5####.com/uploads/allimg/170311/129-1F3111416450-L.jpg
  • 5####.com/uploads/allimg/160602/117-1606021003110-L.jpg
  • 5####.com/uploads/allimg/160527/117-16052G325360-L.jpg
  • n####.####.com/ngame/thf2/513308.jpg
  • 5####.com/uploads/allimg/170303/106-1F3031431030-L.jpg
  • 5####.com/uploads/allimg/170303/106-1F303135K40-L.jpg
  • 5####.com/uploads/allimg/170303/139-1F3031523230-L.jpg
  • 5####.com/uploads/allimg/160527/124-16052G34Q1-50.jpg
  • 5####.com/uploads/allimg/160601/117-160601112T10-L.jpg
  • 5####.com/uploads/allimg/170303/139-1F3031514200-L.jpg
  • h####.####.com/hm.gif?cc=####&ck=####&cl=####&ds=####&ep=####&et=####&ja...
  • 5####.com/uploads/allimg/160527/124_160527181746_1.jpg
HTTP POST requests:
  • b####.####.cn/cw/interface!u2.action?protocol=####&version=####&cid=####
  • b####.####.cn/cw/cp.action?requestId=####&g=####
  • mobads-####.####.com/brwhis.log
  • a####.####.com/app_logs
Modified file system:
Creates the following files:
  • /data/data/####/databases/downloadswc-journal
  • /data/data/####/cache/webviewCacheChromium/f_00000a
  • /data/data/####/shared_prefs/com.baidu.mobads.loader.xml
  • /data/data/####/shared_prefs/__xadsdk_downloaded__version__.xml
  • /data/data/####/shared_prefs/####_preferences.xml
  • /data/data/####/app_baidu_ad_sdk/__xadsdk__remote__final__builtin__.jar
  • /data/data/####/app_baidu_ad_sdk/__xadsdk__remote__final__8a1a8af7-58a8-49ef-bcb2-79ba467789a1.jar
  • /sdcard/Download/hou/4.5_giantt.jar.tmp
  • /data/data/####/cache/webviewCacheChromium/data_3
  • /data/data/####/cache/webviewCacheChromium/data_2
  • /data/data/####/cache/webviewCacheChromium/data_1
  • /data/data/####/cache/webviewCacheChromium/data_0
  • /data/data/####/databases/webviewCookiesChromium.db-journal
  • /data/data/####/shared_prefs/####_preferences.xml.bak
  • /data/data/####/app_database/ApplicationCache.db-journal
  • /data/data/####/shared_prefs/umeng_general_config.xml
  • /sdcard/dt/restime.dat
  • /data/data/####/files/.umeng/exchangeIdentity.json
  • /data/data/####/shared_prefs/__x_adsdk_agent_header__.xml
  • /data/data/####/files/.imprint
  • /data/data/####/shared_prefs/a.xml
  • /data/data/####/shared_prefs/W_Key.xml
  • /data/data/####/app_baidu_ad_sdk/__xadsdk__remote__final__4c7d3ca4-63fe-4f8b-9ccd-d902fe4bab4b.jar
  • /data/data/####/cache/webviewCacheChromium/f_000009
  • /data/data/####/cache/webviewCacheChromium/f_000008
  • /data/data/####/shared_prefs/st.xml
  • /data/data/####/cache/webviewCacheChromium/f_000001
  • /data/data/####/cache/webviewCacheChromium/f_000003
  • /data/data/####/cache/webviewCacheChromium/f_000002
  • /data/data/####/cache/webviewCacheChromium/f_000005
  • /data/data/####/cache/webviewCacheChromium/f_000004
  • /data/data/####/cache/webviewCacheChromium/f_000007
  • /data/data/####/cache/webviewCacheChromium/f_000006
  • /data/data/####/databases/webview.db-journal
  • /data/data/####/files/umeng_it.cache
  • /data/data/####/shared_prefs/W_Key.xml.bak
  • /data/data/####/databases/webviewCookiesChromiumPrivate.db-journal
  • /data/data/####/databases/downloadswc
  • /data/data/####/cache/webviewCacheChromium/index
Miscellaneous:
Executes next shell scripts:
  • /system/bin/dexopt --dex 27 49 40 209724 /data/data/####/app_baidu_ad_sdk/__xadsdk__remote__final__builtin__.jar 1224893203 -1687546542 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.ja
  • /system/bin/dexopt --dex 27 86 40 108620 /storage/emulated/0/download/hou/4.5_giantt.jar 1244034170 1925108179 45 /system/framework/core.jar /system/framework/core-junit.jar /system/framework/bouncycastle.jar /system/framework/ext.jar /system/framework/fr
Contains functionality to send SMS messages automatically.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android