マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Android.Proxy.39

Added to the Dr.Web virus database: 2022-11-30

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Adware.Dangbei.1.origin
  • Android.Proxy.44.origin
  • Android.Proxy.45.origin
Downloads the following detected threats from the Internet:
  • Adware.GoodAd.1
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) 39.1####.115.163:8080
  • TCP(HTTP/1.1) chec####.cc:80
  • TCP(HTTP/1.1) and####.b####.qq.com:80
  • TCP(HTTP/1.1) 1####.79.196.2:8088
  • TCP(HTTP/1.1) c####.dc.100u####.####.net:80
  • TCP(HTTP/1.1) w####.pcon####.com.cn:80
  • TCP(HTTP/1.1) 360####.org:80
  • TCP(HTTP/1.1) 1####.28.228.62:14305
  • TCP(HTTP/1.1) we####.miguv####.com:80
  • TCP(HTTP/1.1) pic.gtp.xy####.com:8844
  • TCP(HTTP/1.1) 39.1####.138.60:18890
  • TCP(HTTP/1.1) 1####.225.230.119:80
  • TCP(HTTP/1.1) 47.1####.197.219:3918
  • TCP(HTTP/1.1) up####.webxia####.top:80
  • TCP(HTTP/1.1) a####.webxia####.top:80
  • TCP(HTTP/1.1) cdn.dc.100u####.com:80
  • TCP(HTTP/1.1) c5112fe####.c####.front####.com:80
  • TCP(HTTP/1.1) log-re####.com:80
  • TCP(HTTP/1.1) cctvwbn####.v.ws####.com:80
  • TCP(HTTP/1.1) 39.1####.49.89:8080
  • UDP(NTP) 2.and####.p####.####.org:123
  • TCP(TLS/1.0) al####.u####.com:443
  • TCP(TLS/1.0) jwc####.he####.com.cn:443
  • TCP(TLS/1.0) tbsreco####.i####.qq.com:443
  • TCP(TLS/1.0) h####.b####.com:443
  • TCP(TLS/1.0) asl.8888####.com:1444
  • TCP(TLS/1.0) d####.100u####.com:443
  • TCP(TLS/1.0) gmscomp####.google####.com:443
  • TCP(TLS/1.0) sk.ts####.xyz:8642
  • TCP(TLS/1.0) plb####.u####.com:443
  • TCP(TLS/1.0) 249306####.clou####.com:443
  • TCP(TLS/1.2) 74.1####.205.94:443
  • TCP(TLS/1.2) gmscomp####.google####.com:443
  • UDP hsz.hangzho####.com:16000
  • UDP tm2.binst####.live:13
  • UDP 1####.35.96.170:2713
  • UDP 1####.36.130.202:2207
  • UDP tm2.binst####.live:3923
  • UDP 1####.205.162.104:2159
  • TCP 1####.0.10.254:35370
  • UDP 2####.255.255.250:1900
  • TCP 1.1####.176.110:4610
  • TCP 1####.45.136.245:26298
  • TCP 42.1####.4.54:4610
  • TCP 60.20.2####.130:4610
  • UDP tm4.binst####.live:3924
  • UDP as1.binst####.live:13
  • UDP 1####.239.46.60:1587
  • TCP 2####.206.77.200:4610
  • TCP 4####.58.8.245:4610
  • UDP as3.binst####.live:13
  • UDP tm4.binst####.live:13
  • UDP as3.binst####.live:3924
  • UDP 1####.50.135.182:2889
  • TCP 1####.6.20.217:4610
  • TCP 1####.113.22.238:4610
  • TCP 42.58.1####.211:4610
  • UDP 1####.0.10.254:4610
  • TCP 1####.38.177.113:4610
  • TCP 42.1####.193.42:4610
  • UDP as1.binst####.live:3923
DNS requests:
  • 2.and####.p####.####.org
  • 249306####.clou####.com
  • 360####.org
  • a####.juyo####.net
  • a####.juyo####.net.####.8
  • a####.webxia####.top
  • and####.b####.qq.com
  • as1.binst####.live
  • as2.binst####.live
  • as3.binst####.live
  • as4.binst####.live
  • asl.8888####.com
  • c####.dc.100u####.com
  • cctvwbn####.v.ws####.com
  • cdn.dc.100u####.com
  • chec####.cc
  • d####.100u####.com
  • de.gtp.xy####.com
  • gmscomp####.google####.com
  • h####.b####.com
  • hdp.s####.org
  • hsz.hangzho####.com
  • jwc####.he####.com.cn
  • livesho####.kan####.com
  • log-re####.com
  • m####.go####.com
  • pic.gtp.xy####.com
  • plb####.u####.com
  • sk.ts####.xyz
  • st####.tin####.com
  • st####.tin####.com.####.8
  • tbsreco####.i####.qq.com
  • tm1.binst####.live
  • tm2.binst####.live
  • tm3.binst####.live
  • tm4.binst####.live
  • u####.u####.com
  • up####.juyo####.net
  • up####.juyo####.net.####.8
  • up####.webxia####.top
  • w####.pcon####.com.cn
  • we####.miguv####.com
  • www.google####.com
HTTP GET requests:
  • 360####.org/feature/config?api_version=####&app_id=####&app_version=####...
  • a####.webxia####.top/epg_v2/epg_20221130.zip
  • a####.webxia####.top/plugins/hdp/202211210958/hdp_474.jar
  • a####.webxia####.top/plugins/libfuck/202205261145/libfuck.so
  • a####.webxia####.top/plugins/libsign/202009211008/libsign.so
  • a####.webxia####.top/plugins/libtvcore/202110111500/libtvcore-666.so
  • c####.dc.100u####.####.net/sdkfile/963215350b45dcec76b719f3188ed64f.apk?...
  • c####.dc.100u####.####.net/sdkfile/c6a500ea752f4443b0328f8a2efb366d.apk?...
  • c5112fe####.c####.front####.com/hdp_config/ad.json
  • c5112fe####.c####.front####.com/hdp_config/channel-configs.json
  • c5112fe####.c####.front####.com/hdp_config/hidden-configs.json
  • c5112fe####.c####.front####.com/hdp_config/operations.json
  • c5112fe####.c####.front####.com/hdp_config/play-order.json
  • c5112fe####.c####.front####.com/hdp_config/plugins-113.json
  • c5112fe####.c####.front####.com/hdp_config/prepare-block.json
  • c5112fe####.c####.front####.com/hdp_config/shopping.json
  • c5112fe####.c####.front####.com/hdp_config/special-flavor/hdp/apk-config...
  • c5112fe####.c####.front####.com/hdp_config/special-flavor/hdp/channel-co...
  • c5112fe####.c####.front####.com/hdp_config/special-flavor/hdp/hidden-con...
  • c5112fe####.c####.front####.com/hdp_config/special-flavor/hdp/play-order...
  • c5112fe####.c####.front####.com/hdp_config/special-flavor/hdp/shopping.j...
  • cctvwbn####.v.ws####.com/cctvwbnd/cctv1_2/index.m3u8
  • cctvwbn####.v.ws####.com/cctvwbnd/cctv1_2_360P/100050.ts?wsApp=####&wsMo...
  • cctvwbn####.v.ws####.com/cctvwbnd/cctv1_2_360P/100051.ts?wsApp=####&wsMo...
  • cctvwbn####.v.ws####.com/cctvwbnd/cctv1_2_360P/100052.ts?wsApp=####&wsMo...
  • cctvwbn####.v.ws####.com/cctvwbnd/cctv1_2_360P/100053.ts?wsApp=####&wsMo...
  • cctvwbn####.v.ws####.com/cctvwbnd/cctv1_2_360P/playlist.m3u8?wsApp=####
  • cdn.dc.100u####.com/sdkfile/1b7731c15284327d35b8363d03bb0b30.jar?t=####&...
  • cdn.dc.100u####.com/sdkfile/8416479a9df618d21f60e5e660660781.apk?t=####&...
  • chec####.cc/jd?a=####&av=####&d=####&p=####&v=####&vc=####
  • up####.webxia####.top/data/channels_new_v2/carousel/238_product.zip
  • up####.webxia####.top/data/channels_new_v2/cctv/886_product.zip
  • up####.webxia####.top/data/channels_new_v2/local/711_product.zip
  • up####.webxia####.top/data/channels_new_v2/shopping/125_product.zip
  • w####.pcon####.com.cn/ipJson.jsp?json=####
  • we####.miguv####.com/gateway/playurl/v3/play/playurl?contId=####&rateTyp...
HTTP HEAD requests:
  • a####.webxia####.top/app/HDP_201.apk
  • up####.webxia####.top/data/channels_new_v2/carousel/238_product.zip
  • up####.webxia####.top/data/channels_new_v2/cctv/886_product.zip
  • up####.webxia####.top/data/channels_new_v2/local/711_product.zip
  • up####.webxia####.top/data/channels_new_v2/shopping/125_product.zip
HTTP POST requests:
  • al####.u####.com:443/unify_logs
  • and####.b####.qq.com/rqd/async?aid=####
  • asl.8888####.com:1444/sdk_login?t=####
  • d####.100u####.com:443/pluginsync
  • d####.100u####.com:443/reportcomp
  • d####.100u####.com:443/sdk
  • h####.b####.com:443/app.gif
  • log-re####.com/report
  • pic.gtp.xy####.com:8844/Device/info
  • pic.gtp.xy####.com:8844/i?ts=####
  • plb####.u####.com:443/umpx_internal
  • sk.ts####.xyz:8642/config?&st=####
  • tbsreco####.i####.qq.com:443/getconfig
File system changes:
Creates the following files:
  • /data/data/####/._098add4a8c1da3c3b37b1afff5fa7c39.html
  • /data/data/####/._2ab2393cbd987f25f26deaffbf46b81f.html
  • /data/data/####/._4e00c380665f9ea39dbe949c1393dc6c.html
  • /data/data/####/._72e95c40f478f167d7c4250954f50a87.html
  • /data/data/####/._ad_duolebo.png
  • /data/data/####/._ad_haomaishou.png
  • /data/data/####/._ad_jusha.png
  • /data/data/####/._ad_yangguang.png
  • /data/data/####/._ad_yougou_other.png
  • /data/data/####/._ad_yougouwu.png
  • /data/data/####/._bootstrap.min.css
  • /data/data/####/._bootstrap.min.js
  • /data/data/####/._brower.js
  • /data/data/####/._css
  • /data/data/####/._dropzone.js
  • /data/data/####/._head.png
  • /data/data/####/._img
  • /data/data/####/._img_bottom.png
  • /data/data/####/._index1.html
  • /data/data/####/._index2.html
  • /data/data/####/._jquery.min.js
  • /data/data/####/._js
  • /data/data/####/._modal.js
  • /data/data/####/._plus.jpg
  • /data/data/####/._shop.json
  • /data/data/####/._upload.css
  • /data/data/####/._upload.png
  • /data/data/####/.cl
  • /data/data/####/.ef0b4ddacc046d054f437ba0af966623
  • /data/data/####/.imprint
  • /data/data/####/.jg.ic
  • /data/data/####/02ceec046e2c0500d1df6489c97f33c2.0.tmp
  • /data/data/####/02ceec046e2c0500d1df6489c97f33c2.1.tmp
  • /data/data/####/098add4a8c1da3c3b37b1afff5fa7c39.html
  • /data/data/####/1004
  • /data/data/####/1173963099.apk
  • /data/data/####/1173963099.apk.temp
  • /data/data/####/1173963099.dex
  • /data/data/####/1173963099.dex.flock (deleted)
  • /data/data/####/1522313656.dex
  • /data/data/####/1522313656.dex.flock (deleted)
  • /data/data/####/1522313656.jar
  • /data/data/####/1522313656.jar.temp
  • /data/data/####/1669787758688
  • /data/data/####/1669787758783
  • /data/data/####/1669787759048
  • /data/data/####/1671157483.apk
  • /data/data/####/1671157483.apk.temp
  • /data/data/####/1671157483.dex
  • /data/data/####/1671157483.dex.flock (deleted)
  • /data/data/####/20221130.rep
  • /data/data/####/2a02b077baa09b3b178b64e03536627e.xml
  • /data/data/####/2ab2393cbd987f25f26deaffbf46b81f.html
  • /data/data/####/3153939189.apk
  • /data/data/####/3153939189.apk.temp
  • /data/data/####/3153939189.dex
  • /data/data/####/3153939189.dex.flock (deleted)
  • /data/data/####/3226d782c1e4b89db899601ecf83d6b2.0.tmp
  • /data/data/####/3226d782c1e4b89db899601ecf83d6b2.1.tmp
  • /data/data/####/3ada7ab781be820563481d3d3807694d.0.tmp
  • /data/data/####/3ada7ab781be820563481d3d3807694d.1.tmp
  • /data/data/####/3d6e812910c876b187f884cd4f9c1d90.0.tmp
  • /data/data/####/3d6e812910c876b187f884cd4f9c1d90.1
  • /data/data/####/3e2be8b767c9ea8b4b0f38e70adcda86.0.tmp
  • /data/data/####/3e2be8b767c9ea8b4b0f38e70adcda86.1
  • /data/data/####/41b252a5aec128eac961189993a52fe4
  • /data/data/####/426824f9dfaf2a7fd21b016212fe3ba9.0
  • /data/data/####/426824f9dfaf2a7fd21b016212fe3ba9.1
  • /data/data/####/4e00c380665f9ea39dbe949c1393dc6c.html
  • /data/data/####/70105d1fa158ceb49c49de4cad42bce9.0.tmp
  • /data/data/####/70105d1fa158ceb49c49de4cad42bce9.1
  • /data/data/####/70105d1fa158ceb49c49de4cad42bce9.1.tmp
  • /data/data/####/72e95c40f478f167d7c4250954f50a87.html
  • /data/data/####/745a2f442935879b71d7c1592e411ba9.xml
  • /data/data/####/81166c7727d38735d681dea1e2076af0.0.tmp
  • /data/data/####/81166c7727d38735d681dea1e2076af0.1.tmp
  • /data/data/####/8c1103cd577ab245485ea1921ec2f5b6.0.tmp
  • /data/data/####/8c1103cd577ab245485ea1921ec2f5b6.1.tmp
  • /data/data/####/93c931bed0d21be66f0a523c573d7ef3.0.tmp
  • /data/data/####/93c931bed0d21be66f0a523c573d7ef3.1
  • /data/data/####/93c931bed0d21be66f0a523c573d7ef3.1.tmp
  • /data/data/####/96b8ba2225840405ce6f7e4ccd7d22ee.0.tmp
  • /data/data/####/96b8ba2225840405ce6f7e4ccd7d22ee.1.tmp
  • /data/data/####/CBGr2.xml
  • /data/data/####/HDP_d35a5f.mmap3
  • /data/data/####/HDP_d35a5f_20221130.xlog
  • /data/data/####/UM_PROBE_DATA.xml
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/__Baidu_Stat_SDK_SendRem.xml
  • /data/data/####/__local_ap_info_cache.json
  • /data/data/####/__local_last_session.json
  • /data/data/####/__local_stat_cache.json
  • /data/data/####/__send_data_1669787746648
  • /data/data/####/a.xml
  • /data/data/####/a==8.1.6&&3.5.7_1669787744109_envelope.log
  • /data/data/####/abc.dex
  • /data/data/####/abc.dex.flock (deleted)
  • /data/data/####/abc.jar
  • /data/data/####/ad_duolebo.png
  • /data/data/####/ad_haomaishou.png
  • /data/data/####/ad_jusha.png
  • /data/data/####/ad_yangguang.png
  • /data/data/####/ad_yougou_other.png
  • /data/data/####/ad_yougouwu.png
  • /data/data/####/baidu_mtj_sdk_record.xml
  • /data/data/####/bfb0e63a6c4e352158be3df98d18dae5.xml
  • /data/data/####/bootstrap.min.css
  • /data/data/####/bootstrap.min.js
  • /data/data/####/brower.js
  • /data/data/####/bugly_db_-journal
  • /data/data/####/carousel.zip
  • /data/data/####/carousel.zip.tmp
  • /data/data/####/carousel_238_product.php
  • /data/data/####/cctv.zip
  • /data/data/####/cctv.zip.tmp
  • /data/data/####/cctv_886_product.php
  • /data/data/####/cd92128f321c5632f5cc941a4e49d596.0.tmp
  • /data/data/####/cd92128f321c5632f5cc941a4e49d596.1.tmp
  • /data/data/####/cf876f83517b46fb810b7fc1e0a27848.0.tmp
  • /data/data/####/cf876f83517b46fb810b7fc1e0a27848.1.tmp
  • /data/data/####/channel.xml
  • /data/data/####/channel.xml.bak
  • /data/data/####/classes.dex
  • /data/data/####/classes.dex;classes2.dex
  • /data/data/####/classes.dex;classes3.dex
  • /data/data/####/crashrecord.xml
  • /data/data/####/d2d84b2ea077889941abe45590580d3d.0.tmp
  • /data/data/####/d2d84b2ea077889941abe45590580d3d.1.tmp
  • /data/data/####/d31f9a1d4d0a2189b963a499cbd5b63b
  • /data/data/####/d606e37f9e73d6de9b7733a1ae1a4a088ccb45fbac210ee...64.apk
  • /data/data/####/d606e37f9e73d6de9b7733a1ae1a4a088ccb45fbac210ee...64.dex
  • /data/data/####/d606e37f9e73d6de9b7733a1ae1a4a088ccb45fbac210ee...leted)
  • /data/data/####/dW1weF9pbnRlcm5hbF8xNjY5Nzg3NzQxMTA3;
  • /data/data/####/dropzone.js
  • /data/data/####/eb0e69936ff1ff8e7a0531a1c01d3d34.0.tmp
  • /data/data/####/eb0e69936ff1ff8e7a0531a1c01d3d34.1.tmp
  • /data/data/####/epg_20221130.zip
  • /data/data/####/exchangeIdentity.json
  • /data/data/####/exid.dat
  • /data/data/####/f837245c30b856f3db5ea3b6c335fb24.0.tmp
  • /data/data/####/f837245c30b856f3db5ea3b6c335fb24.1.tmp
  • /data/data/####/f8a0d104172e02b6a632314053f9d372.0.tmp
  • /data/data/####/f8a0d104172e02b6a632314053f9d372.1.tmp
  • /data/data/####/file_sp_new.xml
  • /data/data/####/file_sp_new.xml.bak
  • /data/data/####/hdp.db-journal (deleted)
  • /data/data/####/hdp.db-wal
  • /data/data/####/hdp.dex
  • /data/data/####/hdp.dex.flock (deleted)
  • /data/data/####/hdp.jar
  • /data/data/####/hdpfans.com_preferences.xml
  • /data/data/####/hdpfans.com_preferences.xml.bak
  • /data/data/####/hdpfans.com_preferences.xml.bak (deleted)
  • /data/data/####/head.png
  • /data/data/####/i==1.2.0&&3.5.7_1669787740917_envelope.log
  • /data/data/####/img_bottom.png
  • /data/data/####/index1.html
  • /data/data/####/index2.html
  • /data/data/####/info.xml
  • /data/data/####/journal.tmp
  • /data/data/####/jquery.min.js
  • /data/data/####/libcuid.so
  • /data/data/####/libfuck.so
  • /data/data/####/libjiagu.so
  • /data/data/####/libsign.so
  • /data/data/####/libtvcore.so
  • /data/data/####/libztvb321.2.2.2.so
  • /data/data/####/local.zip (deleted)
  • /data/data/####/local.zip.download
  • /data/data/####/local.zip.tmp
  • /data/data/####/local.zip.tmp (deleted)
  • /data/data/####/local_711_product.php
  • /data/data/####/local_crash_lock (deleted)
  • /data/data/####/m.xml
  • /data/data/####/metrics_guid
  • /data/data/####/modal.js
  • /data/data/####/pid.txt
  • /data/data/####/plugins.xml
  • /data/data/####/plus.jpg
  • /data/data/####/prefs.lock
  • /data/data/####/proc_auxv
  • /data/data/####/region.xml
  • /data/data/####/region.xml.bak
  • /data/data/####/sai.xml
  • /data/data/####/security_info
  • /data/data/####/shop.json
  • /data/data/####/shopping.zip
  • /data/data/####/shopping.zip.tmp
  • /data/data/####/shopping_125_product.php
  • /data/data/####/t==8.1.6&&3.5.7_1669787742979_envelope.log
  • /data/data/####/tbs_download_config.xml
  • /data/data/####/tbs_download_config.xml.bak
  • /data/data/####/tbs_download_config.xml.bak (deleted)
  • /data/data/####/tbs_emergence.xml
  • /data/data/####/tbs_preloadx5_check_cfg_file.xml
  • /data/data/####/tbs_pv_config
  • /data/data/####/tbscoreinstall.txt
  • /data/data/####/tbslock.txt
  • /data/data/####/tvsou-10.json
  • /data/data/####/tvsou-101.json
  • /data/data/####/tvsou-102.json
  • /data/data/####/tvsou-105.json
  • /data/data/####/tvsou-106.json
  • /data/data/####/tvsou-107.json
  • /data/data/####/tvsou-109.json
  • /data/data/####/tvsou-11.json
  • /data/data/####/tvsou-1101.json
  • /data/data/####/tvsou-1105.json
  • /data/data/####/tvsou-111.json
  • /data/data/####/tvsou-1111.json
  • /data/data/####/tvsou-117.json
  • /data/data/####/tvsou-118.json
  • /data/data/####/tvsou-12.json
  • /data/data/####/tvsou-120.json
  • /data/data/####/tvsou-1202.json
  • /data/data/####/tvsou-1206.json
  • /data/data/####/tvsou-13.json
  • /data/data/####/tvsou-1310.json
  • /data/data/####/tvsou-14.json
  • /data/data/####/tvsou-15.json
  • /data/data/####/tvsou-16.json
  • /data/data/####/tvsou-1601.json
  • /data/data/####/tvsou-1602.json
  • /data/data/####/tvsou-1607.json
  • /data/data/####/tvsou-1704.json
  • /data/data/####/tvsou-1705.json
  • /data/data/####/tvsou-1707.json
  • /data/data/####/tvsou-18.json
  • /data/data/####/tvsou-1804.json
  • /data/data/####/tvsou-1805.json
  • /data/data/####/tvsou-1901.json
  • /data/data/####/tvsou-1902.json
  • /data/data/####/tvsou-1903.json
  • /data/data/####/tvsou-1904.json
  • /data/data/####/tvsou-1905.json
  • /data/data/####/tvsou-1907.json
  • /data/data/####/tvsou-1908.json
  • /data/data/####/tvsou-2004.json
  • /data/data/####/tvsou-2005.json
  • /data/data/####/tvsou-2006.json
  • /data/data/####/tvsou-2008.json
  • /data/data/####/tvsou-2100.json
  • /data/data/####/tvsou-2101.json
  • /data/data/####/tvsou-2107.json
  • /data/data/####/tvsou-2109.json
  • /data/data/####/tvsou-211.json
  • /data/data/####/tvsou-212.json
  • /data/data/####/tvsou-213.json
  • /data/data/####/tvsou-214.json
  • /data/data/####/tvsou-230.json
  • /data/data/####/tvsou-2302.json
  • /data/data/####/tvsou-2304.json
  • /data/data/####/tvsou-244.json
  • /data/data/####/tvsou-3.json
  • /data/data/####/tvsou-301.json
  • /data/data/####/tvsou-303.json
  • /data/data/####/tvsou-304.json
  • /data/data/####/tvsou-306.json
  • /data/data/####/tvsou-307.json
  • /data/data/####/tvsou-308.json
  • /data/data/####/tvsou-4.json
  • /data/data/####/tvsou-401.json
  • /data/data/####/tvsou-402.json
  • /data/data/####/tvsou-403.json
  • /data/data/####/tvsou-404.json
  • /data/data/####/tvsou-405.json
  • /data/data/####/tvsou-42.json
  • /data/data/####/tvsou-43.json
  • /data/data/####/tvsou-44.json
  • /data/data/####/tvsou-507.json
  • /data/data/####/tvsou-600.json
  • /data/data/####/tvsou-601.json
  • /data/data/####/tvsou-602.json
  • /data/data/####/tvsou-603.json
  • /data/data/####/tvsou-604.json
  • /data/data/####/tvsou-606.json
  • /data/data/####/tvsou-607.json
  • /data/data/####/tvsou-608.json
  • /data/data/####/tvsou-611.json
  • /data/data/####/tvsou-7.json
  • /data/data/####/tvsou-702.json
  • /data/data/####/tvsou-705.json
  • /data/data/####/tvsou-708.json
  • /data/data/####/tvsou-804.json
  • /data/data/####/tvsou-805.json
  • /data/data/####/tvsou-806.json
  • /data/data/####/tvsou-9.json
  • /data/data/####/tvsou-900.json
  • /data/data/####/tvsou-902.json
  • /data/data/####/tvsou-904.json
  • /data/data/####/tvsou-905.json
  • /data/data/####/tvsou-906.json
  • /data/data/####/tvsou-907.json
  • /data/data/####/tvsou-908.json
  • /data/data/####/ua.db
  • /data/data/####/ua.db-journal
  • /data/data/####/uifa.xml
  • /data/data/####/um_pri.xml
  • /data/data/####/umeng_common_config.xml
  • /data/data/####/umeng_common_location.xml
  • /data/data/####/umeng_general_config.xml
  • /data/data/####/umeng_it.cache
  • /data/data/####/unknown.xml
  • /data/data/####/update-config.xml
  • /data/data/####/upload.css
  • /data/data/####/upload.png
  • /data/data/####/xj.xml
  • /data/data/####/xj.xml.bak
  • /data/media/####/.confd
  • /data/media/####/.confd-journal
  • /data/media/####/.cuid2
  • /data/media/####/.ef0b4ddacc046d054f437ba0af966623
  • /data/media/####/.timestamp
  • /data/media/####/crash.txt
  • /data/media/####/dvc
  • /data/media/####/logs.csv
  • /data/media/####/tbslog.txt
  • /data/misc/####/primary.prof
Miscellaneous:
Executes the following shell scripts:
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq
  • /system/bin/cat /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_min_freq
  • /system/bin/sh -c getprop
  • /system/bin/sh -c type su
  • cat /sys/class/net/eth0/address
  • cat /sys/class/net/wlan0/address
  • chmod 777 /data/user/0/<Package>/files/.honor
  • chmod 777 /data/user/0/<Package>/files/.honor/1173963099.apk
  • chmod 777 /data/user/0/<Package>/files/.honor/1522313656.jar
  • chmod 777 /data/user/0/<Package>/files/.honor/1671157483.apk
  • chmod 777 /data/user/0/<Package>/files/.honor/3153939189.apk
  • getprop
  • getprop ro.build.display.id
  • getprop ro.build.version.emui
  • getprop ro.build.version.opporom
  • getprop ro.miui.ui.version.name
  • getprop ro.product.cpu.abi
  • getprop ro.smartisan.version
  • getprop ro.vivo.os.version
  • ls /
  • ls /sys/class/thermal
  • sh
Loads the following dynamic libraries:
  • libUrlDecode
  • libc++_shared
  • libfuck
  • libijkffmpeg
  • libijkplayer
  • libijksdl
  • libjiagu
  • libmarsxlog
  • libtvcore
  • libztvb321.2.2.2
Uses the following algorithms to encrypt data:
  • AES
  • AES-CBC-PKCS5Padding
  • AES-CBC-PKCS7Padding
  • AES-ECB-PKCS5Padding
  • AES-GCM-NoPadding
  • DES-CBC-PKCS5Padding
  • DES-ECB-PKCS5Padding
  • RSA-ECB-PKCS1Padding
Uses the following algorithms to decrypt data:
  • AES
  • AES-CBC-PKCS7Padding
  • AES-GCM-NoPadding
  • DES
  • DES-CBC-PKCS5Padding
  • DES-ECB-PKCS5Padding
Accesses the ITelephony private interface.
Uses special library to hide executable bytecode.
Gets information about location.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Displays its own windows over windows of other apps.
Manages Wi-Fi connectivity.
Requests the system alert window permission.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android