マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Android.RemoteCode.592

Added to the Dr.Web virus database: 2018-07-24

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.RemoteCode.41.origin
Gains access to the ITelephony private interface.
Network activity:
Connecting to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) yua####.oss-cn-####.aliy####.com:80
  • TCP(HTTP/1.1) p####.tc.qq.com:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) 1####.23.136.190:9080
  • TCP(HTTP/1.1) 1####.77.128.96:8088
  • TCP(HTTP/1.1) s####.e.qq.com:80
  • TCP(HTTP/1.1) mi.g####.qq.com:80
  • TCP(TLS/1.0) sh.wagbr####.alibaba####.com:443
DNS requests:
  • and####.b####.qq.com
  • imgc####.qq.com
  • mi.g####.qq.com
  • plb####.u####.com
  • s####.e.qq.com
  • u####.u####.com
  • yua####.oss-cn-####.aliy####.com
HTTP GET requests:
  • mi.g####.qq.com/gdt_mview.fcg?actual_width=####&count=####&r=####&templa...
  • p####.tc.qq.com/qzone/biz/gdt/mod/android/AndroidAllInOne/proguard/his/r...
  • yua####.oss-cn-####.aliy####.com/category/photo/1528354683154.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528354983482.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528355057978.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528355090025.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528355617891.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528355684623.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528355845086.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528355929260.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528356107403.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528356124116.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528356308418.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528356380729.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528356551811.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528356928745.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528356942000.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528357576135.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528357591086.jpg
  • yua####.oss-cn-####.aliy####.com/category/photo/1528357949964.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/clearImage/1528803344805.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/originalImage/1528803344805....
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373660229.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373662183.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373663450.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373685143.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373691389.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373694724.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373757429.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373759499.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373760256.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373761877.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373791815.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373892813.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373956377.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373959059.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373965313.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528373999425.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374006943.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374089331.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374092332.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374093874.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374147757.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374164881.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374195262.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374197853.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374199099.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374280057.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374281221.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374282402.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374328004.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374330669.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528374367448.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528699706839.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528699748250.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528714707803.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528714710342.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528718630972.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528718632097.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528718633282.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528718726859.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803192095.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803193490.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803198294.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803199039.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803270875.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803273797.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803278997.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803310997.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803311836.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803340289.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803344068.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803344805.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803346373.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803347983.jpg
  • yua####.oss-cn-####.aliy####.com/testupload/thumbnail/1528803379675.jpg
HTTP POST requests:
  • and####.b####.qq.com/rqd/async
  • s####.e.qq.com/activate
Modified file system:
Creates the following files:
  • /data/data/####/.imprint
  • /data/data/####/01cddd96215b87be04890f4da9faed5cb757a951c7adef0....0.tmp
  • /data/data/####/01da94fa25e1f65b85d25afc9bd1ce984168133906aa635....0.tmp
  • /data/data/####/03d0469bd751c12a32e440e4d074b491b1d0d1394a8e3ed....0.tmp
  • /data/data/####/03f8135637471faa8ceab61e6a675f7ca1b5e7a184b637f....0.tmp
  • /data/data/####/05d7d18972fad88bb22f65199636aa7f3effa50b161f8c0....0.tmp
  • /data/data/####/06fd038d5514ab4eae456609f27265260a8f5bf1b77de22....0.tmp
  • /data/data/####/07ff83d173cc3c5bcc43d6082c573a0a38809f580cc6b28....0.tmp
  • /data/data/####/0a16ca246aec0fd479115f6852ea97858eeef9f4c269c28....0.tmp
  • /data/data/####/0db4371abfd23223c9d441d97498453545d153024668809....0.tmp
  • /data/data/####/10bb8a6f72970a5bdb9a94994ce41cc9c0a0286c0907972....0.tmp
  • /data/data/####/1278cedb052ca183f798ff61f3ffe90efbe086e559ac66c....0.tmp
  • /data/data/####/160dfcac02343651fc7d30b1da3e79801ac15134c1c09b8....0.tmp
  • /data/data/####/180604e374546b608cde9922d57122d3f97fcaeaee67e7e....0.tmp
  • /data/data/####/184a4273adcea4ad8598c1a0467653289f38b432bf7f80d....0.tmp
  • /data/data/####/189269d56bedd4698f6f9e91b255b0e74edaddc8632aed6....0.tmp
  • /data/data/####/196018ce0f5bb665c446462191dee5e50ec45dc679f2393....0.tmp
  • /data/data/####/1f6451bb05b22204ede60a88002ec34d28b07954232ca6c....0.tmp
  • /data/data/####/20b12d985292025808ebbc941966d5c04133e8ceee97f0f....0.tmp
  • /data/data/####/2235657154d0cae6e23048ea67e491ad96322d82f71d4f7....0.tmp
  • /data/data/####/24c6332844697ab068128404a39b39771a9de7d59acc523....0.tmp
  • /data/data/####/24ee434954d54172f2aa31a63880dad11c51f213bfd11cc....0.tmp
  • /data/data/####/26f079520de42835a63541fb8809898258c2a54eded9095....0.tmp
  • /data/data/####/27d5738930ac39e039b2fe3b77462a08f1393fc22e078a8....0.tmp
  • /data/data/####/2a81e589a8d8952cca54c9114f48c246133deb9c7889101....0.tmp
  • /data/data/####/2aeefefa60b58609277c40446371b70fda81be6e55fcb8f....0.tmp
  • /data/data/####/2b382c52d7fcefc4ab90d3f9056ee200020cf87f03ba496....0.tmp
  • /data/data/####/2b7754747c8fe8e1c0647de90324c73aa2e88346bf69aaf....0.tmp
  • /data/data/####/2b9cdb17af61968a5569f2779e1555870be4af26793cd27....0.tmp
  • /data/data/####/2cb7ea0afadb0f714b58fadc3dffd8f82d0771917213dee....0.tmp
  • /data/data/####/2ed3d180e4480c9598a3bdd4b3033319492311c19c82c19....0.tmp
  • /data/data/####/303378a09435e22f3354ffaa8798ad207d162f9f94ba228....0.tmp
  • /data/data/####/3104f50f0ecc4996c186d1a772cba981844002e620ebca7....0.tmp
  • /data/data/####/31313f1813d1521f375d38882206b0a554483f6e76a4b3a....0.tmp
  • /data/data/####/343aaf74a66c3e7313e9bdebb73af641014f78accc4f935....0.tmp
  • /data/data/####/35e6653eea2d3f8c0f7f933c0f18a221df6585769daf86d....0.tmp
  • /data/data/####/3afef094bd12f44e8c00f465e6bf6e83febd4206ee7a6f8....0.tmp
  • /data/data/####/3b30272a2e89296c5f9732edba1f8c51a590970a8bee942....0.tmp
  • /data/data/####/3bf67465a665625aef725eccfb109b3fa930b3847c0522a....0.tmp
  • /data/data/####/3c8592ce483c77b576e52a7b1f7ac3acc8cd6b5734378c1....0.tmp
  • /data/data/####/3f5cc418464ab33994c923402082e229ad071b11353b672....0.tmp
  • /data/data/####/415e270c013301df340eb21f0ef831fa9c7fa8f1e0a81dc....0.tmp
  • /data/data/####/4271ad19744f3d9ad1b6ff114110a4c24237430ce79a945....0.tmp
  • /data/data/####/429502b343fbc2ffafb2deff4c202e382725cb954dc336d....0.tmp
  • /data/data/####/45250ddc7b3301e9f086feb79f56498f520a5e62c152d4e....0.tmp
  • /data/data/####/46d7bdcc9345f541900ef146b58b78054abd5f229c9d031....0.tmp
  • /data/data/####/471dcd49805ca2773ebc6c619b565c74d0d6f128f85b373....0.tmp
  • /data/data/####/47c254b8e72ef56ae00133ee73fa40fe6814c42af1dcdee....0.tmp
  • /data/data/####/498eeef6d783f608e38d0d1129ab96dbe524c5c3c0faf5f....0.tmp
  • /data/data/####/49cce8935eafa61e6d3990602d272f683dfe5f4258eb012....0.tmp
  • /data/data/####/49e356e8dadad53c9258ef2dbaaa4a18715c4486dde48ce....0.tmp
  • /data/data/####/4b74c0fd5fa441041cd48e492077d4d16933f799e3c0368....0.tmp
  • /data/data/####/4bdd073bd9bae935040368749a0c0cdeb7b26479808d889....0.tmp
  • /data/data/####/4c45fa2bdd30132e8c41092a3b812defd0a5d4cfe3eb339....0.tmp
  • /data/data/####/4f05a93cfdcc75eb7a419a74975a4b9186c5756adbfca6b....0.tmp
  • /data/data/####/52e922a1e880d45bbdc4d4e85f8eb224a1ed7ff1dad8fac....0.tmp
  • /data/data/####/536361c414b1fa2e100711b4df4bab7920e28096f7a2eb6....0.tmp
  • /data/data/####/558d28116ae6791ff8e0c293e541b4a3e00e560295a8e50....0.tmp
  • /data/data/####/55a171dd56779fd154182e79ab0e363216615a0322c89c0....0.tmp
  • /data/data/####/57070918685e0ba73f5470d1d04b0fd232053678861fd2f....0.tmp
  • /data/data/####/596886e5f6441548bd7b5256ab3d5f2deac8d12203e2141....0.tmp
  • /data/data/####/59d14f014e35711ac0bd6d2fb3c1db56340c600fabf540d....0.tmp
  • /data/data/####/5cffcca38884dbb171befaccc310c32551eee81c79587f9....0.tmp
  • /data/data/####/5f7f2ff834b0f1d89fb688b097165afd6cc5f6fa184d0e6....0.tmp
  • /data/data/####/6004e5637ad491fb70d76a553710cf4eaface8e16094f8a....0.tmp
  • /data/data/####/61c7aeaca0e7a15aababc642d58c1ef6486d9992f2b052f....0.tmp
  • /data/data/####/61ffeb00ff2632d0fa43184635f3d58690fcfed23889cd2....0.tmp
  • /data/data/####/64126872d21e29e637f06dff2dc4a3c03bebd0ed3a044d1....0.tmp
  • /data/data/####/65975a23d5c99850e8bdf4dd07f8821fa07dcee09d21c9a....0.tmp
  • /data/data/####/6665911328576f9d7df91e095bc973d58efb83c459ad536....0.tmp
  • /data/data/####/67e3674c2e776c935b73b16c266a43a6ace7f3171af694c....0.tmp
  • /data/data/####/6a7619a47eb7154840cb8638a8e29245f6192ace3727688....0.tmp
  • /data/data/####/6ad34506e20bec78e863e8f26cb4e27105d951ba24a591a....0.tmp
  • /data/data/####/6c91338ddb65083ba1e5fed43b56522cf9b8556edc0a26b....0.tmp
  • /data/data/####/6d408f2a33dee3527a16f96d7a5de8a83de42510a21a9a4....0.tmp
  • /data/data/####/6d6b84061903062f2b778e997cd9c0af4a0ccc2696585bf....0.tmp
  • /data/data/####/6e364ace0e158785d8b123279e15ec5af4956808f8e434b....0.tmp
  • /data/data/####/6e9d8fef30109c3714007322be9e51a862d8d4abc931f31....0.tmp
  • /data/data/####/709a6ba477999549e81d614a4f4596b521518e2797418e5....0.tmp
  • /data/data/####/70a034a7ed721a97021b33ef5b6b1d947cd323c73ca6cde....0.tmp
  • /data/data/####/71c1ff722b3e72f3967420fcdebeab8ffa7e1ba27af30c2....0.tmp
  • /data/data/####/73c8ae1832e37e8a2fd68c3ed501944b43d721c59b89dab....0.tmp
  • /data/data/####/778ec76a25e56f5f9d6ae1f66b1cf25ce765627b1f9676e....0.tmp
  • /data/data/####/7a783d01b547766281b4096e98eaf4e68238d96bfe56f96....0.tmp
  • /data/data/####/7d005e2582093e2e69417fcf7f3ac678521fb628d80298b....0.tmp
  • /data/data/####/7f90ac676e4333c9e4abe47cd0ede2eb0e55607569a837a....0.tmp
  • /data/data/####/80731ddc82945238bbeb450040e9fee19a2907da98fa44f....0.tmp
  • /data/data/####/810ee642e65cea58700a4e4a669d7031a054f5f4ecb7a28....0.tmp
  • /data/data/####/8643910fe18c0687e3a3f6208acc1b1d2d61c851a81cf57....0.tmp
  • /data/data/####/866fc77603ba2d1e92e369abe630a2e340e6c6d394cbacd....0.tmp
  • /data/data/####/897a9b6f1538fbaadf1f3062c8f0ac90693bda095d9049f....0.tmp
  • /data/data/####/8f6309c6f38efd317a96c050fc7279620a8a8d673eb565f....0.tmp
  • /data/data/####/9c9de7ecaa525026937a25fe942c7ce63ac8a46981b6ff3....0.tmp
  • /data/data/####/9cb03979aa31fa005c6baf64378ed945664dcc95a6e5530....0.tmp
  • /data/data/####/9d01f7377efc6ff0f9ea0a93347d8d1cb05ca8e379afa8e....0.tmp
  • /data/data/####/9f08f3ae5c3a8bb583734d5a25879fa111ac7f13714f8aa....0.tmp
  • /data/data/####/9fb9dd691b61ebd17a3860ebc8147c6feaf6063cd23a92f....0.tmp
  • /data/data/####/BuglySdkInfos.xml
  • /data/data/####/GDTSDK.db
  • /data/data/####/GDTSDK.db-journal
  • /data/data/####/UM_PROBE_DATA.xml
  • /data/data/####/a1d27be1664c0b041103bd4e60f9d2c3d79676293102295....0.tmp
  • /data/data/####/a513addf8f62df60bcca18fd4029c22f520a5829dca8d1c....0.tmp
  • /data/data/####/a5dab0eb7a4de710408f9ffb218ec6b24e3f9edf47ec554....0.tmp
  • /data/data/####/a7c4d30df9e9fa4897aad5a0e08b174ad505faed5c73b3c....0.tmp
  • /data/data/####/a==7.5.0&&5.5.8_1532458182598_envelope.log
  • /data/data/####/ac1e104eb2027829c6b8e3419933866733abd96ab55d1b2....0.tmp
  • /data/data/####/ace7bedd9f2a5a427996ae06d56369eb147398357d94281....0.tmp
  • /data/data/####/af59a9cbc9329135692e10e964aca8a4bff90511040d6b8....0.tmp
  • /data/data/####/b072184ac1de11e54f6f4382a8842567ced6eda7c58323b....0.tmp
  • /data/data/####/b3cd81bf978014edc87c7e181396064c2bed897dd4b4894....0.tmp
  • /data/data/####/b70d60b96e1f5db9eae6933a8322b1b34bc15b9b38b90b7....0.tmp
  • /data/data/####/bafebccce3ffc33196538f06b81090627ed122eedf85610....0.tmp
  • /data/data/####/bc1dbceba83a7cfddbcb666a8ce6dd8543449564662f4ee....0.tmp
  • /data/data/####/bc98ff16e26a9e0dcddabdafa7dc1ac778daff90973e761....0.tmp
  • /data/data/####/bed2815901e18baf638a98076cf79ac9544faa74ba93cab....0.tmp
  • /data/data/####/bugly_db_legu-journal
  • /data/data/####/c3a6eab9990486e5a147e1f01cebae1bf68644c08cda592....0.tmp
  • /data/data/####/c73f59d1e52440c5533473106bdcf83abb55c5d57186ada....0.tmp
  • /data/data/####/c7c5786279d03ca868d5b3361effba6c85250c49545c179....0.tmp
  • /data/data/####/c91569e2adf52ca6e2faa60ee98d7a3b11c7758c550fdd1....0.tmp
  • /data/data/####/c9b8a3f4fa24bc14ebb0c7e19b2d7d50ac4f573c1f2dcbd....0.tmp
  • /data/data/####/c9cb10b8e3e55d2076215ea6edf5d18af26a704210a1750....0.tmp
  • /data/data/####/c9ce93e9aba44a0cceec1bf0af0334e3bb96a9b09572733....0.tmp
  • /data/data/####/cf4fe2826a484f0934796d2764b595f8f608058df528e40....0.tmp
  • /data/data/####/cf7e43ed193d0bdf9101195e86d8f7acc82a6e51499e1c2....0.tmp
  • /data/data/####/d0a151877bb2a6fed174c934af559cc470a53ebddc56d6c....0.tmp
  • /data/data/####/d4506fb868ebb9e53e4dc66ce20dc0759bb0e17e381b409....0.tmp
  • /data/data/####/d4a6948a2787a4d804c155bcaf6dbf1816b25eac5d9154d....0.tmp
  • /data/data/####/d5d8e9a725db1f45bb71048626276025d9cd04623c11e1e....0.tmp
  • /data/data/####/d7a8c908cce4c74678e2fd9eb8ec16290783d2bc84de7b1....0.tmp
  • /data/data/####/d987d843aedd5fd42e4803d3f2166fb92e638c56397e804....0.tmp
  • /data/data/####/da2f74f6336cfe9bdf51759c56b8178977a089c454b862b....0.tmp
  • /data/data/####/daemon
  • /data/data/####/database-name-journal
  • /data/data/####/dcfd1ef62e63f09f05bd0600603dda0c17306f6b52c4498....0.tmp
  • /data/data/####/devCloudSetting.cfg
  • /data/data/####/devCloudSetting.sig
  • /data/data/####/e1e16d5ddf2f3493852f8fe2c5183dc415b48db314bdb1e....0.tmp
  • /data/data/####/e28866f8b922cba0b14ee750fa09706c387be9d46dd040e....0.tmp
  • /data/data/####/e28dc6430823f87542530648f9ccbc56c3d87b20d6f5ba8....0.tmp
  • /data/data/####/e3aeeecc85f789ddbff063e72244f8f240c43869e3c7231....0.tmp
  • /data/data/####/e439a68d2aba141b0dc0f469ec6706f2ce01cf230531dbd....0.tmp
  • /data/data/####/e52240c6e38536a15929d18224e4116e56e41280b201961....0.tmp
  • /data/data/####/e551b5bf138a0c1e50bba172a5c8a39bebe5292316ee219....0.tmp
  • /data/data/####/e709a50fdf61043e2674f7e283f3a245a56a874cba4e6c0....0.tmp
  • /data/data/####/e905cff8165baa53dff50dd2091a98b03a6c045833038ea....0.tmp
  • /data/data/####/e90b608365f73b364636297b02948528be121815abf5ff3....0.tmp
  • /data/data/####/eb5232aaa9ec379586d7d09744d8dadd480b40c52ef5af5....0.tmp
  • /data/data/####/eb7ab317f271cac6f626738444e0c8c88fc9a8f586f6be6....0.tmp
  • /data/data/####/ecda299a2af8474e805a2bc8ee5328db6e240760d1b63ae....0.tmp
  • /data/data/####/ecf102ca7e3e5e5b504ddc0feb85e91deffb9263f564228....0.tmp
  • /data/data/####/ee996bfbc207d37c2c9bc1df229687d11eedd90bf5ab09f....0.tmp
  • /data/data/####/eed3ba452991f5a286c61b8f2cc8afe58b739e7b682ab05....0.tmp
  • /data/data/####/ef278b88154f4e0e2ed77df3b33efc0709943c5e82d38bc....0.tmp
  • /data/data/####/ef4b9e61d07de4ba39ef2a4780374697a9317d8900fb754....0.tmp
  • /data/data/####/ef6ba9b2b1b67cb4518acb089347859700d5511b3504538....0.tmp
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f090c20e378c646e0179a2ceac93833ed5040e9d69aebb2....0.tmp
  • /data/data/####/f2ffa1b793f701faa34e7a1af260cbe12fd4d008930cff7....0.tmp
  • /data/data/####/f43a7d0630d5b8765c4d42bbbd8b28b34cf306fe212338a....0.tmp
  • /data/data/####/f43dc07df08c1056aa856a103048b72938eb9a02d50da78....0.tmp
  • /data/data/####/f6538f322fca67f5faf99fc5c2206c893a7d1545b09d103....0.tmp
  • /data/data/####/fcb6a515ef133ab1bc4c7e8e2e379c8f00419c05438812f....0.tmp
  • /data/data/####/fe16144f60a4177bf661903c275958fc497ab79a6b7a556....0.tmp
  • /data/data/####/gdt_plugin.jar
  • /data/data/####/gdt_plugin.jar.sig
  • /data/data/####/gdt_plugin.tmp
  • /data/data/####/gdt_plugin.tmp.sig
  • /data/data/####/gdt_suid
  • /data/data/####/i==1.2.0&&5.5.8_1532458182382_envelope.log
  • /data/data/####/info.xml
  • /data/data/####/journal.tmp
  • /data/data/####/libnfix.so
  • /data/data/####/libshella-2.8.so
  • /data/data/####/local_crash_lock
  • /data/data/####/mix.dex
  • /data/data/####/native_record_lock
  • /data/data/####/sdkCloudSetting.cfg
  • /data/data/####/sdkCloudSetting.sig
  • /data/data/####/security_info
  • /data/data/####/settings.cfg.xml
  • /data/data/####/share_data.xml
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/um_pri.xml
  • /data/data/####/umdat.xml
  • /data/data/####/umeng_common_config.xml
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/update_lc
  • /data/data/####/webview.db-journal
  • /data/media/####/.a.dat
  • /data/media/####/.adfwe.dat
  • /data/media/####/.cca.dat
  • /data/media/####/.umm.dat
  • /data/media/####/1528803344805.jpg
  • /data/system/####/wallpaper
Miscellaneous:
Executes next shell scripts:
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
  • /system/bin/sh -c getprop ro.aa.romver
  • /system/bin/sh -c getprop ro.board.platform
  • /system/bin/sh -c getprop ro.build.fingerprint
  • /system/bin/sh -c getprop ro.build.nubia.rom.name
  • /system/bin/sh -c getprop ro.build.rom.id
  • /system/bin/sh -c getprop ro.build.tyd.kbstyle_version
  • /system/bin/sh -c getprop ro.build.version.emui
  • /system/bin/sh -c getprop ro.build.version.opporom
  • /system/bin/sh -c getprop ro.gn.gnromvernumber
  • /system/bin/sh -c getprop ro.lenovo.series
  • /system/bin/sh -c getprop ro.lewa.version
  • /system/bin/sh -c getprop ro.meizu.product.model
  • /system/bin/sh -c getprop ro.miui.ui.version.name
  • /system/bin/sh -c getprop ro.vivo.os.build.display.id
  • /system/bin/sh -c type su
  • <Package Folder>/files/daemon <Package>/com.lockstudio.sticklocker.service.CoreService
  • chmod 700 <Package Folder>/tx_shell/libnfix.so
  • chmod 700 <Package Folder>/tx_shell/libshella-2.8.so
  • chmod 700 <Package Folder>/tx_shell/libufix.so
  • chmod 755 <Package Folder>/files/daemon
  • getprop ro.aa.romver
  • getprop ro.board.platform
  • getprop ro.build.fingerprint
  • getprop ro.build.nubia.rom.name
  • getprop ro.build.rom.id
  • getprop ro.build.tyd.kbstyle_version
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.gn.gnromvernumber
  • getprop ro.lenovo.series
  • getprop ro.lewa.version
  • getprop ro.meizu.product.model
  • getprop ro.miui.ui.version.name
  • getprop ro.vivo.os.build.display.id
  • getprop ro.yunos.version
  • logcat -d -v threadtime
  • ls /
  • ls /sys/class/thermal
  • ps
  • sh <Package Folder>/files/daemon <Package>/com.lockstudio.sticklocker.service.CoreService
Loads the following dynamic libraries:
  • Bugly
  • libnfix
  • libshella-2.8
  • libufix
  • nfix
  • ufix
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • AES-GCM-NoPadding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS7Padding
  • AES-GCM-NoPadding
  • RSA-ECB-PKCS1Padding
Uses special library to hide executable bytecode.
Gains access to geolocation.
Gains access to network information.
Gains access to telephone information (number, imei, etc.).
Displays its own windows over windows of other applications.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android