マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Android.Siggen.8128

Added to the Dr.Web virus database: 2018-06-07

Virus description added:

Technical information

Malicious functions:
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) mo####.zhu####.s####.com:80
  • TCP(HTTP/1.1) www.a####.com:80
  • TCP(HTTP/1.1) get.s####.com:80
  • TCP(HTTP/1.1) down####.zhu####.s####.####.com:80
  • TCP(HTTP/1.1) qd.sogo####.com.####.com:80
  • TCP(HTTP/1.1) yap####.cdn.a####.####.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) de####.ping####.zhu####.####.com:80
  • TCP(HTTP/1.1) amdc####.m.ta####.com:80
  • TCP(HTTP/1.1) i####.a####.com.####.com:80
  • TCP(HTTP/1.1) dl.zhu####.s####.####.com:80
  • TCP(HTTP/1.1) i####.sogo####.com.####.com:80
  • TCP(TLS/1.0) ssl.gst####.com:443
  • TCP(TLS/1.0) lh3.googleu####.com:443
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.0) mo####.zhu####.s####.com:443
  • TCP(TLS/1.0) and####.cli####.go####.com:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) acco####.go####.com:443
  • TCP(TLS/1.0) www.gst####.com:443
  • TCP(TLS/1.0) s####.g.doublec####.net:443
  • TCP(TLS/1.0) f####.google####.com:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) a####.google####.com:443
  • TCP(TLS/1.0) msg.umengc####.com:443
  • TCP ope####.m.ta####.com:443
  • TCP umengj####.m.ta####.com:80
  • TCP(ff8 G4H%2FzlN9C2h0LR7xvlsaqhbTo5TOn5LP50sf97xlqbkRjRZnSf672PJAaDJES97i%2BAyBdU99vPjrzhvY5dheYIVgm7I9efkw3v9VoHVhO0Z0ijHSHqDVg%3D&deviceId=07f162bb79cb454260a21a9f426a2ca8&s=1 HTTP/1.1) mo####.zhu####.s####.com:80
DNS requests:
  • a####.google####.com
  • acco####.go####.com
  • ag####.m.ta####.com
  • amdc####.m.ta####.com
  • and####.b####.qq.com
  • and####.cli####.go####.com
  • d####.zhu####.s####.com
  • de####.ping####.zhu####.####.com
  • dl.zhu####.s####.com
  • down####.zhu####.s####.com
  • f####.google####.com
  • f####.gst####.com
  • get.s####.com
  • i####.a####.com
  • i####.sogo####.com
  • i####.sogo####.com
  • i####.sogo####.com
  • i####.sogo####.com
  • img.sogo####.com
  • lh3.googleu####.com
  • mo####.zhu####.s####.com
  • msg.umengc####.com
  • mt####.go####.com
  • p####.s####.com
  • qd.sogo####.com
  • rd.e.s####.com
  • s####.g.doublec####.net
  • ssl.gst####.com
  • umen####.m.ta####.com
  • umengj####.m.ta####.com
  • wap.s####.com
  • www.a####.com
  • www.go####.com
  • www.google-####.com
  • www.googlet####.com
  • www.gst####.com
  • yap####.cdn.a####.com
HTTP GET requests:
  • de####.ping####.zhu####.####.com/?_dv=####&_di=Fi7####&_dc=7Fk####
  • dl.zhu####.s####.####.com/oglxr/open/files/year_2018/day_20180606/152833...
  • down####.zhu####.s####.####.com/focusimage/3a/f2/3af22b914b0b7ca32855d40...
  • i####.a####.com.####.com/data3/icon/201710/31/72e069ea46966b1a2459683316...
  • i####.sogo####.com.####.com/app/a/100540008/0068ca66dcac22291a96cc6b9e9e...
  • i####.sogo####.com.####.com/app/a/100540008/02097aaf75a8e94d3688c2b0886d...
  • i####.sogo####.com.####.com/app/a/100540008/14c0e2358dea346075bdd1e8c5de...
  • i####.sogo####.com.####.com/app/a/100540008/14d897bf9ae2a04e35c6c3a4e25d...
  • i####.sogo####.com.####.com/app/a/100540008/26630396ff3f9a06bcf5b8e333f8...
  • i####.sogo####.com.####.com/app/a/100540008/2cfa1a0f00097a19ea57f41c5601...
  • i####.sogo####.com.####.com/app/a/100540008/30cf3c96bf4bc5d6b2d9c12569b5...
  • i####.sogo####.com.####.com/app/a/100540008/33373febe619dde3a488544ee3a0...
  • i####.sogo####.com.####.com/app/a/100540008/34224090419eb89b8574381e2bcc...
  • i####.sogo####.com.####.com/app/a/100540008/39c141fa0caca68a18632be83a44...
  • i####.sogo####.com.####.com/app/a/100540008/56f56522708aaaf61823cc706c24...
  • i####.sogo####.com.####.com/app/a/100540008/574bd3967a88aedbc64eb608cd16...
  • i####.sogo####.com.####.com/app/a/100540008/5c104db52fa67016190549ac7231...
  • i####.sogo####.com.####.com/app/a/100540008/5ca626f0aaacaf485b239f7e92a3...
  • i####.sogo####.com.####.com/app/a/100540008/74edfc2b29924ebd9c951b4f9479...
  • i####.sogo####.com.####.com/app/a/100540008/79aca533edf3f8c8372b29af5377...
  • i####.sogo####.com.####.com/app/a/100540008/7c75fda30e1195f3dbb06e886373...
  • i####.sogo####.com.####.com/app/a/100540008/86a232c9961dc79354fa76295492...
  • i####.sogo####.com.####.com/app/a/100540008/903e11cb4436fc27961dd567f3a6...
  • i####.sogo####.com.####.com/app/a/100540008/904e26929739dec84b6cb93fdae4...
  • i####.sogo####.com.####.com/app/a/100540008/9e8ab83713074c205b2b93e21781...
  • i####.sogo####.com.####.com/app/a/100540008/a4505bdc37aa05b36d84c3f92bbe...
  • i####.sogo####.com.####.com/app/a/100540008/aa60e67dec8379f3f46f250820a3...
  • i####.sogo####.com.####.com/app/a/100540008/bd4eaf1ce529c60f9f83bb1007aa...
  • i####.sogo####.com.####.com/app/a/100540008/f5667f298647dce3f2dfc80836ab...
  • i####.sogo####.com.####.com/app/a/100540008/ff69a942d8fce991336a52e0f24e...
  • i####.sogo####.com.####.com/app/a/100540008/ffeb069b3889043a7c6c9a916ee3...
  • i####.sogo####.com.####.com/app/a/100540014/119244a967b74707bb0d5df6a8fd...
  • i####.sogo####.com.####.com/app/a/100540014/2410cd159bb4e000990931c8f553...
  • i####.sogo####.com.####.com/app/a/100540014/6ef902e6a37606cb92fdd01baf88...
  • i####.sogo####.com.####.com/app/a/100540014/756e3bf9dca43b457b40facdeaf2...
  • i####.sogo####.com.####.com/app/a/100540014/a1cbc24a1d7b7d12d02738347913...
  • i####.sogo####.com.####.com/app/a/100540020/00005854950b71b8a32343f3752b...
  • i####.sogo####.com.####.com/app/a/100540020/0041af6bfeb8b896521fb809eb88...
  • i####.sogo####.com.####.com/app/a/100540020/00a0da6177726595a9222784ef33...
  • i####.sogo####.com.####.com/app/a/100540020/26630396ff3f9a06bcf5b8e333f8...
  • i####.sogo####.com.####.com/app/a/100540020/2df9ebec13feaee925ecfbba3462...
  • i####.sogo####.com.####.com/app/a/100540020/30cf3c96bf4bc5d6b2d9c12569b5...
  • i####.sogo####.com.####.com/app/a/100540020/3243dbb4e77a6e29e5b60aab84d0...
  • i####.sogo####.com.####.com/app/a/100540020/32eb50a82f5fd30ee147d00efc5e...
  • i####.sogo####.com.####.com/app/a/100540020/363ee673b5ea4fc0613fa25dad95...
  • i####.sogo####.com.####.com/app/a/100540020/4888616af8568bdff49f9619d891...
  • i####.sogo####.com.####.com/app/a/100540020/4ecdd9708644ce19979a2a006980...
  • i####.sogo####.com.####.com/app/a/100540020/5ca626f0aaacaf485b239f7e92a3...
  • i####.sogo####.com.####.com/app/a/100540020/6020a3e4d715e07b71a79b90b1f5...
  • i####.sogo####.com.####.com/app/a/100540020/60261561e9bb1a9aba28d5d6cf41...
  • i####.sogo####.com.####.com/app/a/100540020/6581431ddad0d6d0fb10c37c39f0...
  • i####.sogo####.com.####.com/app/a/100540020/6eccba93e0c3e0da4b0a8dffdc76...
  • i####.sogo####.com.####.com/app/a/100540020/7c75fda30e1195f3dbb06e886373...
  • i####.sogo####.com.####.com/app/a/100540020/8f65c1752acb388548b4810a23e6...
  • i####.sogo####.com.####.com/app/a/100540020/8f9a8026327722095c53178c5afd...
  • i####.sogo####.com.####.com/app/a/100540020/9e8ab83713074c205b2b93e21781...
  • i####.sogo####.com.####.com/app/a/100540020/a3538c9afa71e8e1f5c9391fe009...
  • i####.sogo####.com.####.com/app/a/100540020/b043572e4ee144396996b67e2b49...
  • i####.sogo####.com.####.com/app/a/100540020/b2fb308212fa29f724e6fdeba294...
  • i####.sogo####.com.####.com/app/a/100540020/cdf07ef76437c58d5bc816174d16...
  • i####.sogo####.com.####.com/app/a/100540020/cfeb554903f39895705401fe5112...
  • i####.sogo####.com.####.com/app/a/100540020/e4e2f16d873fbca9a14f19798859...
  • i####.sogo####.com.####.com/app/a/100540020/eb7ccd14d7a414526c8dfbab14e2...
  • i####.sogo####.com.####.com/app/a/100540020/edfaa26a54e5dd49309b4e25eb7f...
  • i####.sogo####.com.####.com/app/a/11220004/0a9b038f6064ae2ec3f2c5e07973b...
  • i####.sogo####.com.####.com/app/a/11220004/0ab9f8d5691febdd62d9c49ceb24e...
  • i####.sogo####.com.####.com/app/a/11220004/20018e5b5a41d79769ac1c33e0663...
  • i####.sogo####.com.####.com/app/a/11220004/2b42f95caa6d1d45906304b46d9e9...
  • i####.sogo####.com.####.com/app/a/11220004/41d3fa0a5b612bd47f1a0eeae2140...
  • i####.sogo####.com.####.com/app/a/11220004/47489a2b61f6939a292dfd6920b6f...
  • i####.sogo####.com.####.com/app/a/11220004/4bf31df5127838128cea1fb05dae6...
  • i####.sogo####.com.####.com/app/a/11220004/56e143a8ed4e171c6b3a2528883c8...
  • i####.sogo####.com.####.com/app/a/11220004/5a79e4efd20ec5b6790d07358cab9...
  • i####.sogo####.com.####.com/app/a/11220004/66d56ca90c9cabebf2b90858c9040...
  • i####.sogo####.com.####.com/app/a/11220004/6b540beaecc2ed371138c3b7e58c9...
  • i####.sogo####.com.####.com/app/a/11220004/71d0904f8f9aa79d2cddc6ce25bd8...
  • i####.sogo####.com.####.com/app/a/11220004/746a19b8088b265a60340ea988037...
  • i####.sogo####.com.####.com/app/a/11220004/77809956cb6d8a56e9cee93540607...
  • i####.sogo####.com.####.com/app/a/11220004/790d0c1615b0595f7eacd8f298bc8...
  • i####.sogo####.com.####.com/app/a/11220004/8a211ddc7bea1cdf624b8a519741f...
  • i####.sogo####.com.####.com/app/a/11220004/b930abbd5785a34f35db9e264cbcf...
  • i####.sogo####.com.####.com/app/a/11220004/bc90208d40926fb7da1a94ad1adb2...
  • i####.sogo####.com.####.com/app/a/11220004/bee4515b249bea7c67d768f27648b...
  • i####.sogo####.com.####.com/app/a/11220004/c1a9ac5fa1a7325006a5ce37e6efd...
  • i####.sogo####.com.####.com/app/a/11220004/d28b18da44555ac2edd13192b33e5...
  • i####.sogo####.com.####.com/app/a/11220004/d2fb5fb271dfe83344029579eb96d...
  • i####.sogo####.com.####.com/app/a/11220004/e353f4bbc6d12b0e51fc9cf8072e9...
  • i####.sogo####.com.####.com/app/a/11220004/e378f6c5e9c4bfa6fd68a022fe19f...
  • i####.sogo####.com.####.com/app/a/11220004/efe4f801929fa519a835a20cdf5a4...
  • i####.sogo####.com.####.com/app/a/11220004/fbc907204b63d87ad3957b38ec9fc...
  • mo####.zhu####.s####.com/android/app/getcomment.html?iv=####&appid=####&...
  • mo####.zhu####.s####.com/android/checkjarupdate.html?uid=####&vn=####&ch...
  • mo####.zhu####.s####.com/android/config/device.html?iv=####&uid=####&vn=...
  • mo####.zhu####.s####.com/android/config/device_entry.html?iv=####&rom=##...
  • mo####.zhu####.s####.com/android/downbind.html?iv=####&etoken=####&token...
  • mo####.zhu####.s####.com/android/download.html?app_id=####&sogouid=####&...
  • mo####.zhu####.s####.com/android/folder/ads/link.html?iv=####&type=####&...
  • mo####.zhu####.s####.com/android/hotword.html?iv=####&count=####&uid=###...
  • mo####.zhu####.s####.com/android/list/relation.html?s=####&iv=####&l=###...
  • mo####.zhu####.s####.com/android/nav/config.html?iv=####&uid=####&vn=###...
  • mo####.zhu####.s####.com/android/news/channel.html?&uid=####&vn=####&cha...
  • mo####.zhu####.s####.com/android/notify.html?uid=####&vn=####&channel=##...
  • mo####.zhu####.s####.com/android/popup.html?iv=####&gid=####&dpi=####&ui...
  • mo####.zhu####.s####.com/android/rank/toplist.html?id=####&limit=####&gr...
  • mo####.zhu####.s####.com/android/residentRec.html?iv=####&uid=####&vn=##...
  • mo####.zhu####.s####.com/android/serverconfig.html?iv=####&mf=####&on=##...
  • mo####.zhu####.s####.com/android/sosodetail.html?iv=####&sosoid=####&uid...
  • mo####.zhu####.s####.com/android/weather.html?iv=####&bts=####&type=####...
  • mo####.zhu####.s####.com/app/redir.jsp?appdown=####&u=####&docid=####&so...
  • mo####.zhu####.s####.com/m/appDetail.html?id=####&iv=####&imei=####&uid=...
  • mo####.zhu####.s####.com/m/author.html?l=####&aid=####&s=####&iv=####&q=...
  • mo####.zhu####.s####.com/m/focus.html?iv=####&tid=####&uid=####&vn=####&...
  • mo####.zhu####.s####.com/m/install.html?iv=####&is_first=####&uid=####&v...
  • mo####.zhu####.s####.com/m/likeApp.html?iv=####&tid=####&uid=####&vn=###...
  • mo####.zhu####.s####.com/m/recommend.html?s=####&token=####&iv=####&c=##...
  • mo####.zhu####.s####.com/misc/root/gets.html?key=####&ret=####&uid=####&...
  • mo####.zhu####.s####.com/nvw?url=####&st=9I/L####
  • mo####.zhu####.s####.com/nvw?url=####&st=z9xB####
  • mo####.zhu####.s####.com/vw?url=####&posid=####&fp=####&st=####
  • mo####.zhu####.s####.com/vw?url=####&posid=####&fp=####&st=YKLx####&devi...
  • mo####.zhu####.s####.com/vw?url=####&posid=####&fp=####&st=g/x5####&devi...
  • mo####.zhu####.s####.com/vw?url=####&posid=####&fp=####&st=xSN5####&devi...
  • qd.sogo####.com.####.com/pic/1484795405989.png
  • qd.sogo####.com.####.com/pic/1513331302318.png
  • qd.sogo####.com.####.com/pic/1514429131737.png
  • qd.sogo####.com.####.com/pic/1519789487356.png
  • www.a####.com/dl_app.php?s=####&channel=####
  • yap####.cdn.a####.####.com/data3/apk/201710/31/com.jzzs.ParentsHelper_98...
HTTP POST requests:
  • amdc####.m.ta####.com/amdc/mobileDispatch?appkey=####&deviceId=####&plat...
  • and####.b####.qq.com/rqd/async
  • get.s####.com/q
  • mo####.zhu####.s####.com/android/app/usercomment.html?iv=####&pn=####&an...
  • mo####.zhu####.s####.com/android/checkapptotal.html?iv=####&sdkversion=#...
  • mo####.zhu####.s####.com/android/checkupdate.html?andid=####
  • mo####.zhu####.s####.com/android/folder/game/type.html?iv=####&gid=####&...
  • mo####.zhu####.s####.com/android/loadscreen.html?dpi=####&iv=####&uid=##...
  • mo####.zhu####.s####.com/android/updateNotify.html?iv=####&dpi=####&sdkv...
Modified file system:
Creates the following files:
  • /data/data/####/-1017771617-2024168122
  • /data/data/####/-1197960752-1120848836
  • /data/data/####/-1197960752-1435151934
  • /data/data/####/-1197960752-644251315
  • /data/data/####/-1221932669-1678241213
  • /data/data/####/-1452697297-1317234558
  • /data/data/####/-1452697297-809623708
  • /data/data/####/-1452697297121949519
  • /data/data/####/-14526972971721449708
  • /data/data/####/-14526972971868747563
  • /data/data/####/-1519586046-1315798517
  • /data/data/####/-1578119070-2095282106
  • /data/data/####/-15781190701563975570
  • /data/data/####/-15798097152017743047
  • /data/data/####/-1687534419-178156307
  • /data/data/####/-1707433842-2070018797
  • /data/data/####/-17074338421336182175
  • /data/data/####/-17613069953415277
  • /data/data/####/-1781058449-1816341330
  • /data/data/####/-1824760081-1429855303
  • /data/data/####/-1960683570-193531529
  • /data/data/####/-251760615478359756
  • /data/data/####/-585032223-1816341330
  • /data/data/####/-598776023-314351897
  • /data/data/####/-616505053-462315550
  • /data/data/####/-6165050531582910283
  • /data/data/####/-99730714-178156307
  • /data/data/####/1067005471-1083587637
  • /data/data/####/1067005471-1240467643
  • /data/data/####/1067005471-1389116703
  • /data/data/####/1067005471-1450259532
  • /data/data/####/1067005471-2089571649
  • /data/data/####/1067005471-571004369
  • /data/data/####/1067005471-589778822
  • /data/data/####/1067005471-647110227
  • /data/data/####/1067005471-719579862
  • /data/data/####/10670054711171054526
  • /data/data/####/10670054711506277234
  • /data/data/####/10670054711563466695
  • /data/data/####/10670054711765430144
  • /data/data/####/10670054711842551603
  • /data/data/####/10670054711936399975
  • /data/data/####/106700547131804759
  • /data/data/####/1067005471902182357
  • /data/data/####/1067005472-1846463052
  • /data/data/####/1067005472-2058292611
  • /data/data/####/1067005472-448654721
  • /data/data/####/10670054721009012093
  • /data/data/####/1067005472611732286
  • /data/data/####/1067005473-1160489028
  • /data/data/####/1067005473-1172422301
  • /data/data/####/1067005473-1261117741
  • /data/data/####/1067005473-1387285855
  • /data/data/####/1067005473-1417997747
  • /data/data/####/1067005473-1426690100
  • /data/data/####/1067005473-1475869958
  • /data/data/####/1067005473-167029060
  • /data/data/####/1067005473-1766652320
  • /data/data/####/1067005473-2022507119
  • /data/data/####/1067005473-2117615099
  • /data/data/####/1067005473-220866662
  • /data/data/####/1067005473-233073431
  • /data/data/####/1067005473-442583552
  • /data/data/####/1067005473-567298229
  • /data/data/####/1067005473-823628902
  • /data/data/####/1067005473-824640331
  • /data/data/####/1067005473-897109966
  • /data/data/####/10670054731231096755
  • /data/data/####/10670054731231807448
  • /data/data/####/10670054731279794846
  • /data/data/####/10670054731321703718
  • /data/data/####/10670054731328747130
  • /data/data/####/10670054731696872702
  • /data/data/####/10670054731831566611
  • /data/data/####/1067005473410665126
  • /data/data/####/1067005473816317244
  • /data/data/####/1067005473924237492
  • /data/data/####/1151725069-1342345541
  • /data/data/####/1190131415-1319773466
  • /data/data/####/1334224300-2126854170
  • /data/data/####/14322127601331002214
  • /data/data/####/1492760150953415277
  • /data/data/####/1493990517-1650722521
  • /data/data/####/1656158370-813466101
  • /data/data/####/1718495731-1258859595
  • /data/data/####/1755234209-16827094
  • /data/data/####/1755234209510067521
  • /data/data/####/1892751594-1342345541
  • /data/data/####/1904028606-599419819
  • /data/data/####/2077963232635710396
  • /data/data/####/240865559478359756
  • /data/data/####/330720519-807171471
  • /data/data/####/368351037-1315798517
  • /data/data/####/470208628-936309685
  • /data/data/####/641867305-178156307
  • /data/data/####/75137560-2127665764
  • /data/data/####/75137560-768733356
  • /data/data/####/751375601523019191
  • /data/data/####/75137560233435943
  • /data/data/####/776561672495799621
  • /data/data/####/7936201921876400418
  • /data/data/####/793620192683614571
  • /data/data/####/9829667481368250279
  • /data/data/####/ACCS_BINDumeng;58eee65d07fe654c91002627.xml
  • /data/data/####/ACCS_SDK.xml
  • /data/data/####/ACCS_SDK_CHANNEL.xml
  • /data/data/####/AGOO_BIND.xml
  • /data/data/####/Agoo_AppStore.xml
  • /data/data/####/Alvin2.xml
  • /data/data/####/Badge.Main.xml
  • /data/data/####/ContextData.xml
  • /data/data/####/DaemonServer
  • /data/data/####/MessageStore.db-journal
  • /data/data/####/MsgLogStore.db-journal
  • /data/data/####/NotificationCenter_Pre.xml
  • /data/data/####/PB_SP.xml
  • /data/data/####/PingBackManager_Pre.xml
  • /data/data/####/SGLocSDK.xml
  • /data/data/####/SOGOUPLUS_CONFIG.xml
  • /data/data/####/account.db-journal
  • /data/data/####/accs.db-journal
  • /data/data/####/agoo.pid
  • /data/data/####/androidtool.db-journal
  • /data/data/####/app_config.xml
  • /data/data/####/app_config.xml.bak
  • /data/data/####/app_preference.xml
  • /data/data/####/app_usage.db
  • /data/data/####/app_usage.db-journal
  • /data/data/####/bugly_db_-journal
  • /data/data/####/com.sogo.appmall.push_service_setting.xml
  • /data/data/####/credit_share_preferences.xml
  • /data/data/####/downloads_classic.db-journal
  • /data/data/####/eudemon
  • /data/data/####/home_app_n
  • /data/data/####/home_app_p
  • /data/data/####/home_game_n
  • /data/data/####/home_game_p
  • /data/data/####/home_lb_n
  • /data/data/####/home_lb_p
  • /data/data/####/home_sf_n
  • /data/data/####/home_sf_p
  • /data/data/####/hotword
  • /data/data/####/localRoot.json
  • /data/data/####/local_crash_lock
  • /data/data/####/location_config.xml
  • /data/data/####/message_accs_db
  • /data/data/####/message_accs_db-journal
  • /data/data/####/nav_app_selected
  • /data/data/####/nav_app_unselected
  • /data/data/####/nav_game_selected
  • /data/data/####/nav_game_unselected
  • /data/data/####/nav_manage_selected
  • /data/data/####/nav_manage_unselected
  • /data/data/####/nav_rank_selected
  • /data/data/####/nav_rank_unselected
  • /data/data/####/nav_select_selected
  • /data/data/####/nav_select_unselected
  • /data/data/####/patchmanage.db
  • /data/data/####/patchmanage.db-journal
  • /data/data/####/pb_db
  • /data/data/####/pb_db-journal
  • /data/data/####/pback
  • /data/data/####/searchKeyords
  • /data/data/####/security_info
  • /data/data/####/soso.db
  • /data/data/####/soso.db-journal
  • /data/data/####/tab_config.json
  • /data/data/####/temp
  • /data/data/####/unupdateapp_v2.db
  • /data/data/####/unupdateapp_v2.db-journal
  • /data/data/####/webview.db-journal
  • /data/data/####/webviewCookiesChromium.db
  • /data/data/####/webviewCookiesChromium.db-journal
  • /data/data/####/webviewCookiesChromiumPrivate.db
  • /data/data/####/webviewCookiesChromiumPrivate.db-journal
  • /data/media/####/.nomedia
  • /data/media/####/.sg_firstlauch.cfg
  • /data/media/####/1f8cc82c42fe4224812da13959a57445
  • /data/media/####/23ee68374b26411685bcf4bd9267cc63
  • /data/media/####/Alvin2.xml
  • /data/media/####/ContextData.xml
  • /data/media/####/af54fe673f074daf8d416652294dbb57
  • /data/media/####/comcqjdldlhsougou300.apk
  • /data/media/####/d4b19f1a9f04400985b6300653da1214
  • /data/media/####/deviceToken
Miscellaneous:
Executes next shell scripts:
  • /system/bin/sh -c getprop ro.board.platform
  • /system/bin/sh -c type su
  • <Package Folder>/files/DaemonServer -s <Package Folder>/lib/ -n runServer -p startservice -n <Package>/com.taobao.accs.ChannelService --user 0 -f <Package Folder> -t 600 -c agoo.pid -P <Package Folder> -K 1009527 -U tb_accs_eudemon_1.1.3 -L http://agoodm.m.taobao.com/agoo/report -D {"package":"<Package>","appKey":"umeng:58eee65d07fe654c91002627","utdid":"Wxi/UpLv0UkDAGdzx1EvlO2J","sdkVersion":"221"} -I agoodm.m.taobao.com -O 80 -T -Z
  • cat /sys/class/net/wlan0/address
  • chmod 500 <Package Folder>/files/DaemonServer
  • chmod 777 <Package Folder>/cache
  • chmod 777 <Package Folder>/files
  • getprop ro.board.platform
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.kernel.qemu
  • getprop ro.miui.ui.version.name
  • getprop ro.smartisan.version
  • getprop ro.vivo.os.version
  • sh
Loads the following dynamic libraries:
  • Bugly
  • diff
  • rutx
  • sogouenc
  • tnet-3.1
  • uninstall
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS5Padding
  • AES-ECB-PKCS5Padding
  • AES-GCM-NoPadding
  • DES-CBC-PKCS5Padding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS5Padding
  • AES-GCM-NoPadding
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Gains access to information about APN settings.
Gains access to information about active device administrators.
Gains access to information about installed applications.
Gains access to information about running applications.
Adds tasks to the system scheduler.
Displays its own windows over windows of other applications.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android