マイライブラリ
マイライブラリ

マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Android.BankBot.TgToxic.42

Added to the Dr.Web virus database: 2023-10-26

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.BankBot.TgToxic.1
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(HTTP/1.1) 1####.194.221.94:80
  • TCP(TLS/1.0) rr18---####.g####.com:443
  • TCP(TLS/1.0) 1####.194.221.94:443
  • TCP(TLS/1.0) p####.google####.com:443
  • TCP(TLS/1.0) rr2---s####.g####.com:443
  • TCP(TLS/1.0) rr9---s####.g####.com:443
  • TCP(TLS/1.0) pla####.google####.com:443
  • TCP(TLS/1.2) www.go####.com:443
  • TCP(TLS/1.2) p####.google####.com:443
  • TCP(TLS/1.2) 1####.194.221.94:443
  • UDP p####.google####.com:443
DNS requests:
  • connect####.gst####.com
  • m####.go####.com
  • p####.google####.com
  • pla####.google####.com
  • rr18---####.g####.com
  • rr2---s####.g####.com
  • rr9---s####.g####.com
  • sqs.ap-nort####.amazo####.com
  • www.go####.com
File system changes:
Creates the following files:
  • /data/com.exsfbp.vlkozrqi/####/JI8PPMHF96RZYUOZ1TUY6OL36TO60X8M.dex
  • /data/data/####/.com_exsfbp_vlkozrqi.meta
  • /data/data/####/037QBVPU16BM2SJDS7D4TRNLM8JV8JCD.dex
  • /data/data/####/037QBVPU16BM2SJDS7D4TRNLM8JV8JCD.dex.flock (deleted)
  • /data/data/####/19
  • /data/data/####/1HHEDRG60OIPBJVT851JF4AIP0RIW07C.dex
  • /data/data/####/1HHEDRG60OIPBJVT851JF4AIP0RIW07C.dex.flock (deleted)
  • /data/data/####/1Y6EOWTGALJPJ5XFBUOQL3X7EZQYAZE.dex
  • /data/data/####/1Y6EOWTGALJPJ5XFBUOQL3X7EZQYAZE.dex.flock (deleted)
  • /data/data/####/1Y6EOWTGALJPJ5XFBUOQL3X7EZQYAZE.zip
  • /data/data/####/2023-10-26PM043104.str
  • /data/data/####/29
  • /data/data/####/2WBIPS4DL4R46JOTOMAG62102ASVNURN.dex
  • /data/data/####/2WBIPS4DL4R46JOTOMAG62102ASVNURN.dex.flock (deleted)
  • /data/data/####/2XXGHHJKZGLSOQT7A5FEB19RG6L9MPE7.dex
  • /data/data/####/2XXGHHJKZGLSOQT7A5FEB19RG6L9MPE7.dex.flock (deleted)
  • /data/data/####/3FVOBTAWQEWZ1LPFEJVXXUKSRYPS26DU.dex
  • /data/data/####/3FVOBTAWQEWZ1LPFEJVXXUKSRYPS26DU.dex.flock (deleted)
  • /data/data/####/3KK4EAF6GRX7L7NDTCICV1RDS54W0HK.dex
  • /data/data/####/3KK4EAF6GRX7L7NDTCICV1RDS54W0HK.dex.flock (deleted)
  • /data/data/####/3KK4EAF6GRX7L7NDTCICV1RDS54W0HK.zip
  • /data/data/####/4MLORAM3BA5MOTIBYKGYSG3USSED5CLT.dex
  • /data/data/####/4MLORAM3BA5MOTIBYKGYSG3USSED5CLT.dex.flock (deleted)
  • /data/data/####/4OWQEN68J9JTZVPTWMCNDBXG100WLW6.dex
  • /data/data/####/4OWQEN68J9JTZVPTWMCNDBXG100WLW6.dex.flock (deleted)
  • /data/data/####/4OWQEN68J9JTZVPTWMCNDBXG100WLW6.zip
  • /data/data/####/4TP5FV8B9C6C6SO2ADV94YW2PALPT2X.dex
  • /data/data/####/4TP5FV8B9C6C6SO2ADV94YW2PALPT2X.dex.flock (deleted)
  • /data/data/####/4TP5FV8B9C6C6SO2ADV94YW2PALPT2X.zip
  • /data/data/####/4UWNH0OZCID26XQB72PGIYYOKH7GZYQA.dex
  • /data/data/####/4UWNH0OZCID26XQB72PGIYYOKH7GZYQA.dex.flock (deleted)
  • /data/data/####/5C83C4I3ANS3V1OUDKETEOOUFTKG9WXY.dex
  • /data/data/####/5C83C4I3ANS3V1OUDKETEOOUFTKG9WXY.dex.flock (deleted)
  • /data/data/####/6JPUMNJERZLATX6TM0GO40PPHH9S78VT.dex
  • /data/data/####/6JPUMNJERZLATX6TM0GO40PPHH9S78VT.dex.flock (deleted)
  • /data/data/####/71BMWJZ27L4TLODQ61SJXLLBB42ZQXDD.dex
  • /data/data/####/71BMWJZ27L4TLODQ61SJXLLBB42ZQXDD.dex.flock (deleted)
  • /data/data/####/7VF4FHQCEECVDHDJA7N9PUWCN21WEET6.dex
  • /data/data/####/9Y0HHA2H26SLG81GPVFJ7N4CGK8ZUFEK.dex
  • /data/data/####/9Y0HHA2H26SLG81GPVFJ7N4CGK8ZUFEK.dex.flock (deleted)
  • /data/data/####/A5B4OT8UG52QPXJQOK99DZK6TK3XBOB9.dex
  • /data/data/####/A5B4OT8UG52QPXJQOK99DZK6TK3XBOB9.dex.flock (deleted)
  • /data/data/####/AKQXG6HIYWOR386AJDCXQ1P1U9Y47HV.dex
  • /data/data/####/AKQXG6HIYWOR386AJDCXQ1P1U9Y47HV.dex.flock (deleted)
  • /data/data/####/AKQXG6HIYWOR386AJDCXQ1P1U9Y47HV.zip
  • /data/data/####/AVPYQNRINN9Y1HM1AOWWKG1T9T5KNC3L.dex
  • /data/data/####/AXD0TPF0VO9S8MTJI9FQV1T3CYP9Q5Q3.dex
  • /data/data/####/AXD0TPF0VO9S8MTJI9FQV1T3CYP9Q5Q3.dex.flock (deleted)
  • /data/data/####/B4E7N8GVC0MZ6IBIRPHL1DUIUMYL8HOY.dex
  • /data/data/####/B4E7N8GVC0MZ6IBIRPHL1DUIUMYL8HOY.dex.flock (deleted)
  • /data/data/####/BDW3U5XAADWDJC5ED3NDZF29JRD8CNCS.dex
  • /data/data/####/BDW3U5XAADWDJC5ED3NDZF29JRD8CNCS.dex.flock (deleted)
  • /data/data/####/BJF5TIL7A02OYUGCJ5NIGYOR4NR7OJD.dex
  • /data/data/####/BJF5TIL7A02OYUGCJ5NIGYOR4NR7OJD.dex.flock (deleted)
  • /data/data/####/BJF5TIL7A02OYUGCJ5NIGYOR4NR7OJD.zip
  • /data/data/####/COWT4IVTVRPCE2AW34OQERXD8ZYXZ3A3.dex
  • /data/data/####/COWT4IVTVRPCE2AW34OQERXD8ZYXZ3A3.dex.flock (deleted)
  • /data/data/####/CQ83XCCF0YLIYDI3FYP0AYAC0DF4N2YM.dex
  • /data/data/####/CQ83XCCF0YLIYDI3FYP0AYAC0DF4N2YM.dex.flock (deleted)
  • /data/data/####/DFQX4VBGGVMV9Q78J5X3XPG7LT7YY1Q2.dex
  • /data/data/####/DFQX4VBGGVMV9Q78J5X3XPG7LT7YY1Q2.dex.flock (deleted)
  • /data/data/####/E3HYIJJA7BX611M5YWWGS0H51H5SBWND.dex
  • /data/data/####/E3HYIJJA7BX611M5YWWGS0H51H5SBWND.dex.flock (deleted)
  • /data/data/####/EZ77HX2LNQWQWMMCSZTF68QSRCFRF4F.dex
  • /data/data/####/EZ77HX2LNQWQWMMCSZTF68QSRCFRF4F.dex.flock (deleted)
  • /data/data/####/EZ77HX2LNQWQWMMCSZTF68QSRCFRF4F.zip
  • /data/data/####/FA891YPFTQ3ZUIKJTLQY68L7EX8MWP8I.dex
  • /data/data/####/FA891YPFTQ3ZUIKJTLQY68L7EX8MWP8I.dex.flock (deleted)
  • /data/data/####/FI2DUASXG5AX57Y8NIWNCEIC93U2RUJ8.dex
  • /data/data/####/FI2DUASXG5AX57Y8NIWNCEIC93U2RUJ8.dex.flock (deleted)
  • /data/data/####/FLBIOB3M7LKP9G5U2HWNHLL33WEB21T1.dex
  • /data/data/####/FLBIOB3M7LKP9G5U2HWNHLL33WEB21T1.dex.flock (deleted)
  • /data/data/####/IECPkgStoreInfo
  • /data/data/####/JI8PPMHF96RZYUOZ1TUY6OL36TO60X8M.dex
  • /data/data/####/JUSDXATVP23Z6YGBHXY6IKXR2XCEO9S6.dex
  • /data/data/####/JUSDXATVP23Z6YGBHXY6IKXR2XCEO9S6.dex.flock (deleted)
  • /data/data/####/JXNYX36NVL548H3VK2TENEQI7EFX46G.dex
  • /data/data/####/JXNYX36NVL548H3VK2TENEQI7EFX46G.dex.flock (deleted)
  • /data/data/####/JXNYX36NVL548H3VK2TENEQI7EFX46G.zip
  • /data/data/####/JY6TMUKH89EH1VYKRAGJ8YU4X362FIVG.dex
  • /data/data/####/JY6TMUKH89EH1VYKRAGJ8YU4X362FIVG.dex.flock (deleted)
  • /data/data/####/K2TC3M2V3UDM0D2F6WCU40FU8KMPPSTP.dex
  • /data/data/####/K2TC3M2V3UDM0D2F6WCU40FU8KMPPSTP.dex.flock (deleted)
  • /data/data/####/LZ98Q1XS5BEVVUNKKJ2TRBNXHYOPKZFV.dex
  • /data/data/####/LZ98Q1XS5BEVVUNKKJ2TRBNXHYOPKZFV.dex.flock (deleted)
  • /data/data/####/M6QR64LJX1NA40461YM4KHBF61O7XX01.dex
  • /data/data/####/M6QR64LJX1NA40461YM4KHBF61O7XX01.dex.flock (deleted)
  • /data/data/####/MK2L4ILIUSC7FWIYJ5WPUPHLYPEWN9J.dex
  • /data/data/####/MK2L4ILIUSC7FWIYJ5WPUPHLYPEWN9J.dex.flock (deleted)
  • /data/data/####/MK2L4ILIUSC7FWIYJ5WPUPHLYPEWN9J.zip
  • /data/data/####/MO76TCWHPCN4QRO9CYM0IADSUMGFVMNZ.dex
  • /data/data/####/MO76TCWHPCN4QRO9CYM0IADSUMGFVMNZ.dex.flock (deleted)
  • /data/data/####/MSMPOMLIUS8BBOAYJL0H695DYPAO7PZ.dex
  • /data/data/####/MSMPOMLIUS8BBOAYJL0H695DYPAO7PZ.dex.flock (deleted)
  • /data/data/####/MSMPOMLIUS8BBOAYJL0H695DYPAO7PZ.zip
  • /data/data/####/OJBQNFXE9AF6EG39WJXGPBZXUSVVGROL.dex
  • /data/data/####/OJBQNFXE9AF6EG39WJXGPBZXUSVVGROL.dex.flock (deleted)
  • /data/data/####/OZPIQFAGMNK8BJHKMEVFRTI8NAHJ9A5F.dex
  • /data/data/####/OZPIQFAGMNK8BJHKMEVFRTI8NAHJ9A5F.dex.flock (deleted)
  • /data/data/####/PAEAK4DGQLBH75HRBQ0QLZX3Y7EQIVQ.dex
  • /data/data/####/PAEAK4DGQLBH75HRBQ0QLZX3Y7EQIVQ.dex.flock (deleted)
  • /data/data/####/PAEAK4DGQLBH75HRBQ0QLZX3Y7EQIVQ.zip
  • /data/data/####/QQ2J6G1JL1B2O00AXQUWWHN36LKNTD45.dex
  • /data/data/####/QQ2J6G1JL1B2O00AXQUWWHN36LKNTD45.dex.flock (deleted)
  • /data/data/####/QT7OWLCI4HYQHP3YO4T1DVKYH0NP7CND.dex
  • /data/data/####/QT7OWLCI4HYQHP3YO4T1DVKYH0NP7CND.dex.flock (deleted)
  • /data/data/####/S5D1B3SBPSY4AS8EU9RT4UCY9YT11EP.dex
  • /data/data/####/S5D1B3SBPSY4AS8EU9RT4UCY9YT11EP.dex.flock (deleted)
  • /data/data/####/S5D1B3SBPSY4AS8EU9RT4UCY9YT11EP.zip
  • /data/data/####/SO85C2N9JRD8UUUCNGCUQR9T07IHJVYJ.dex
  • /data/data/####/SO85C2N9JRD8UUUCNGCUQR9T07IHJVYJ.dex.flock (deleted)
  • /data/data/####/TIC11Y6D6AW14G1GTNFJV3CWOCGZUNU8.dex
  • /data/data/####/TIC11Y6D6AW14G1GTNFJV3CWOCGZUNU8.dex.flock (deleted)
  • /data/data/####/VD4F2T1IIT4D7SLA5RBHNVQT3Z5W874W.dex
  • /data/data/####/VD4F2T1IIT4D7SLA5RBHNVQT3Z5W874W.dex.flock (deleted)
  • /data/data/####/WU0ZTGSZ0I9E6163ZM5WUYA0ODFWRA6U.dex
  • /data/data/####/X79SR98DLB7UM39X28B0HGK8HC53MCA.dex
  • /data/data/####/X79SR98DLB7UM39X28B0HGK8HC53MCA.dex.flock (deleted)
  • /data/data/####/X79SR98DLB7UM39X28B0HGK8HC53MCA.zip
  • /data/data/####/XV9O7PWDXNBY6VXXIWJ09WOW5KDVAKU.dex
  • /data/data/####/XV9O7PWDXNBY6VXXIWJ09WOW5KDVAKU.dex.flock (deleted)
  • /data/data/####/XV9O7PWDXNBY6VXXIWJ09WOW5KDVAKU.zip
  • /data/data/####/XX5MDV0MC4UX7JJ9CD9BJ4YAP0VM0K38.dex
  • /data/data/####/XX5MDV0MC4UX7JJ9CD9BJ4YAP0VM0K38.dex.flock (deleted)
  • /data/data/####/com.android.launcher3.prefs.xml
  • /data/data/####/e65d16607cfa253d6fa5d86b97158aa9ts99nb.demf
  • /data/data/####/e65d16607cfa253d6fa5d86b97158aa9ts99nb.demf (deleted)
  • /data/data/####/empty_classes.dex
  • /data/data/####/empty_classes.zip
  • /data/data/####/proc_auxv
  • /data/data/####/sealeh.bdc
  • /data/data/####/spUtils.xml
  • /data/data/####/working
Miscellaneous:
Executes the following shell scripts:
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/1Y6EOWTGALJPJ5XFBUOQL3X7EZQYAZE.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/3KK4EAF6GRX7L7NDTCICV1RDS54W0HK.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/4OWQEN68J9JTZVPTWMCNDBXG100WLW6.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/4TP5FV8B9C6C6SO2ADV94YW2PALPT2X.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/AKQXG6HIYWOR386AJDCXQ1P1U9Y47HV.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/EZ77HX2LNQWQWMMCSZTF68QSRCFRF4F.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/JXNYX36NVL548H3VK2TENEQI7EFX46G.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/PAEAK4DGQLBH75HRBQ0QLZX3Y7EQIVQ.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/S5D1B3SBPSY4AS8EU9RT4UCY9YT11EP.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/X79SR98DLB7UM39X28B0HGK8HC53MCA.zip
  • cp /data/user/0/<Package>/app_payload_lib/empty_classes.zip /data/user/0/<Package>/app_payload_lib/<Package>_empty_classes/XV9O7PWDXNBY6VXXIWJ09WOW5KDVAKU.zip
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/037QBVPU16BM2SJDS7D4TRNLM8JV8JCD.dex --oat-file=/data/user/0/<Package>/cache/<Package>/037QBVPU16BM2SJDS7D4TRNLM8JV8JCD.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/1HHEDRG60OIPBJVT851JF4AIP0RIW07C.dex --oat-file=/data/user/0/<Package>/cache/<Package>/1HHEDRG60OIPBJVT851JF4AIP0RIW07C.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/2WBIPS4DL4R46JOTOMAG62102ASVNURN.dex --oat-file=/data/user/0/<Package>/cache/<Package>/2WBIPS4DL4R46JOTOMAG62102ASVNURN.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/2XXGHHJKZGLSOQT7A5FEB19RG6L9MPE7.dex --oat-file=/data/user/0/<Package>/cache/<Package>/2XXGHHJKZGLSOQT7A5FEB19RG6L9MPE7.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/3FVOBTAWQEWZ1LPFEJVXXUKSRYPS26DU.dex --oat-file=/data/user/0/<Package>/cache/<Package>/3FVOBTAWQEWZ1LPFEJVXXUKSRYPS26DU.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/4MLORAM3BA5MOTIBYKGYSG3USSED5CLT.dex --oat-file=/data/user/0/<Package>/cache/<Package>/4MLORAM3BA5MOTIBYKGYSG3USSED5CLT.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/4UWNH0OZCID26XQB72PGIYYOKH7GZYQA.dex --oat-file=/data/user/0/<Package>/cache/<Package>/4UWNH0OZCID26XQB72PGIYYOKH7GZYQA.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/5C83C4I3ANS3V1OUDKETEOOUFTKG9WXY.dex --oat-file=/data/user/0/<Package>/cache/<Package>/5C83C4I3ANS3V1OUDKETEOOUFTKG9WXY.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/6JPUMNJERZLATX6TM0GO40PPHH9S78VT.dex --oat-file=/data/user/0/<Package>/cache/<Package>/6JPUMNJERZLATX6TM0GO40PPHH9S78VT.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/71BMWJZ27L4TLODQ61SJXLLBB42ZQXDD.dex --oat-file=/data/user/0/<Package>/cache/<Package>/71BMWJZ27L4TLODQ61SJXLLBB42ZQXDD.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/7VF4FHQCEECVDHDJA7N9PUWCN21WEET6.dex --oat-file=/data/user/0/<Package>/cache/<Package>/7VF4FHQCEECVDHDJA7N9PUWCN21WEET6.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/9Y0HHA2H26SLG81GPVFJ7N4CGK8ZUFEK.dex --oat-file=/data/user/0/<Package>/cache/<Package>/9Y0HHA2H26SLG81GPVFJ7N4CGK8ZUFEK.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/A5B4OT8UG52QPXJQOK99DZK6TK3XBOB9.dex --oat-file=/data/user/0/<Package>/cache/<Package>/A5B4OT8UG52QPXJQOK99DZK6TK3XBOB9.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/AVPYQNRINN9Y1HM1AOWWKG1T9T5KNC3L.dex --oat-file=/data/user/0/<Package>/cache/<Package>/AVPYQNRINN9Y1HM1AOWWKG1T9T5KNC3L.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/AXD0TPF0VO9S8MTJI9FQV1T3CYP9Q5Q3.dex --oat-file=/data/user/0/<Package>/cache/<Package>/AXD0TPF0VO9S8MTJI9FQV1T3CYP9Q5Q3.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/B4E7N8GVC0MZ6IBIRPHL1DUIUMYL8HOY.dex --oat-file=/data/user/0/<Package>/cache/<Package>/B4E7N8GVC0MZ6IBIRPHL1DUIUMYL8HOY.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/BDW3U5XAADWDJC5ED3NDZF29JRD8CNCS.dex --oat-file=/data/user/0/<Package>/cache/<Package>/BDW3U5XAADWDJC5ED3NDZF29JRD8CNCS.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/COWT4IVTVRPCE2AW34OQERXD8ZYXZ3A3.dex --oat-file=/data/user/0/<Package>/cache/<Package>/COWT4IVTVRPCE2AW34OQERXD8ZYXZ3A3.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/CQ83XCCF0YLIYDI3FYP0AYAC0DF4N2YM.dex --oat-file=/data/user/0/<Package>/cache/<Package>/CQ83XCCF0YLIYDI3FYP0AYAC0DF4N2YM.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/DFQX4VBGGVMV9Q78J5X3XPG7LT7YY1Q2.dex --oat-file=/data/user/0/<Package>/cache/<Package>/DFQX4VBGGVMV9Q78J5X3XPG7LT7YY1Q2.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/E3HYIJJA7BX611M5YWWGS0H51H5SBWND.dex --oat-file=/data/user/0/<Package>/cache/<Package>/E3HYIJJA7BX611M5YWWGS0H51H5SBWND.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/FA891YPFTQ3ZUIKJTLQY68L7EX8MWP8I.dex --oat-file=/data/user/0/<Package>/cache/<Package>/FA891YPFTQ3ZUIKJTLQY68L7EX8MWP8I.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/FI2DUASXG5AX57Y8NIWNCEIC93U2RUJ8.dex --oat-file=/data/user/0/<Package>/cache/<Package>/FI2DUASXG5AX57Y8NIWNCEIC93U2RUJ8.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/FLBIOB3M7LKP9G5U2HWNHLL33WEB21T1.dex --oat-file=/data/user/0/<Package>/cache/<Package>/FLBIOB3M7LKP9G5U2HWNHLL33WEB21T1.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/JI8PPMHF96RZYUOZ1TUY6OL36TO60X8M.dex --oat-file=/data/user/0/<Package>/cache/<Package>/JI8PPMHF96RZYUOZ1TUY6OL36TO60X8M.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/JUSDXATVP23Z6YGBHXY6IKXR2XCEO9S6.dex --oat-file=/data/user/0/<Package>/cache/<Package>/JUSDXATVP23Z6YGBHXY6IKXR2XCEO9S6.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/JY6TMUKH89EH1VYKRAGJ8YU4X362FIVG.dex --oat-file=/data/user/0/<Package>/cache/<Package>/JY6TMUKH89EH1VYKRAGJ8YU4X362FIVG.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/K2TC3M2V3UDM0D2F6WCU40FU8KMPPSTP.dex --oat-file=/data/user/0/<Package>/cache/<Package>/K2TC3M2V3UDM0D2F6WCU40FU8KMPPSTP.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/LZ98Q1XS5BEVVUNKKJ2TRBNXHYOPKZFV.dex --oat-file=/data/user/0/<Package>/cache/<Package>/LZ98Q1XS5BEVVUNKKJ2TRBNXHYOPKZFV.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/M6QR64LJX1NA40461YM4KHBF61O7XX01.dex --oat-file=/data/user/0/<Package>/cache/<Package>/M6QR64LJX1NA40461YM4KHBF61O7XX01.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/MO76TCWHPCN4QRO9CYM0IADSUMGFVMNZ.dex --oat-file=/data/user/0/<Package>/cache/<Package>/MO76TCWHPCN4QRO9CYM0IADSUMGFVMNZ.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/OJBQNFXE9AF6EG39WJXGPBZXUSVVGROL.dex --oat-file=/data/user/0/<Package>/cache/<Package>/OJBQNFXE9AF6EG39WJXGPBZXUSVVGROL.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/OZPIQFAGMNK8BJHKMEVFRTI8NAHJ9A5F.dex --oat-file=/data/user/0/<Package>/cache/<Package>/OZPIQFAGMNK8BJHKMEVFRTI8NAHJ9A5F.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/QQ2J6G1JL1B2O00AXQUWWHN36LKNTD45.dex --oat-file=/data/user/0/<Package>/cache/<Package>/QQ2J6G1JL1B2O00AXQUWWHN36LKNTD45.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/QT7OWLCI4HYQHP3YO4T1DVKYH0NP7CND.dex --oat-file=/data/user/0/<Package>/cache/<Package>/QT7OWLCI4HYQHP3YO4T1DVKYH0NP7CND.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/SO85C2N9JRD8UUUCNGCUQR9T07IHJVYJ.dex --oat-file=/data/user/0/<Package>/cache/<Package>/SO85C2N9JRD8UUUCNGCUQR9T07IHJVYJ.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/TIC11Y6D6AW14G1GTNFJV3CWOCGZUNU8.dex --oat-file=/data/user/0/<Package>/cache/<Package>/TIC11Y6D6AW14G1GTNFJV3CWOCGZUNU8.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/VD4F2T1IIT4D7SLA5RBHNVQT3Z5W874W.dex --oat-file=/data/user/0/<Package>/cache/<Package>/VD4F2T1IIT4D7SLA5RBHNVQT3Z5W874W.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/WU0ZTGSZ0I9E6163ZM5WUYA0ODFWRA6U.dex --oat-file=/data/user/0/<Package>/cache/<Package>/WU0ZTGSZ0I9E6163ZM5WUYA0ODFWRA6U.dex --compiler-filter=verify-none --instruction-set=x86
  • dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/XX5MDV0MC4UX7JJ9CD9BJ4YAP0VM0K38.dex --oat-file=/data/user/0/<Package>/cache/<Package>/XX5MDV0MC4UX7JJ9CD9BJ4YAP0VM0K38.dex --compiler-filter=verify-none --instruction-set=x86
  • getprop ro.dalvik.vm.isa.arm
  • getprop ro.dalvik.vm.isa.arm64
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/037QBVPU16BM2SJDS7D4TRNLM8JV8JCD.dex --oat-file=/data/user/0/<Package>/cache/<Package>/037QBVPU16BM2SJDS7D4TRNLM8JV8JCD.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/1HHEDRG60OIPBJVT851JF4AIP0RIW07C.dex --oat-file=/data/user/0/<Package>/cache/<Package>/1HHEDRG60OIPBJVT851JF4AIP0RIW07C.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/2WBIPS4DL4R46JOTOMAG62102ASVNURN.dex --oat-file=/data/user/0/<Package>/cache/<Package>/2WBIPS4DL4R46JOTOMAG62102ASVNURN.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/2XXGHHJKZGLSOQT7A5FEB19RG6L9MPE7.dex --oat-file=/data/user/0/<Package>/cache/<Package>/2XXGHHJKZGLSOQT7A5FEB19RG6L9MPE7.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/3FVOBTAWQEWZ1LPFEJVXXUKSRYPS26DU.dex --oat-file=/data/user/0/<Package>/cache/<Package>/3FVOBTAWQEWZ1LPFEJVXXUKSRYPS26DU.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/4MLORAM3BA5MOTIBYKGYSG3USSED5CLT.dex --oat-file=/data/user/0/<Package>/cache/<Package>/4MLORAM3BA5MOTIBYKGYSG3USSED5CLT.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/4UWNH0OZCID26XQB72PGIYYOKH7GZYQA.dex --oat-file=/data/user/0/<Package>/cache/<Package>/4UWNH0OZCID26XQB72PGIYYOKH7GZYQA.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/5C83C4I3ANS3V1OUDKETEOOUFTKG9WXY.dex --oat-file=/data/user/0/<Package>/cache/<Package>/5C83C4I3ANS3V1OUDKETEOOUFTKG9WXY.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/6JPUMNJERZLATX6TM0GO40PPHH9S78VT.dex --oat-file=/data/user/0/<Package>/cache/<Package>/6JPUMNJERZLATX6TM0GO40PPHH9S78VT.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/71BMWJZ27L4TLODQ61SJXLLBB42ZQXDD.dex --oat-file=/data/user/0/<Package>/cache/<Package>/71BMWJZ27L4TLODQ61SJXLLBB42ZQXDD.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/7VF4FHQCEECVDHDJA7N9PUWCN21WEET6.dex --oat-file=/data/user/0/<Package>/cache/<Package>/7VF4FHQCEECVDHDJA7N9PUWCN21WEET6.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/9Y0HHA2H26SLG81GPVFJ7N4CGK8ZUFEK.dex --oat-file=/data/user/0/<Package>/cache/<Package>/9Y0HHA2H26SLG81GPVFJ7N4CGK8ZUFEK.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/A5B4OT8UG52QPXJQOK99DZK6TK3XBOB9.dex --oat-file=/data/user/0/<Package>/cache/<Package>/A5B4OT8UG52QPXJQOK99DZK6TK3XBOB9.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/AVPYQNRINN9Y1HM1AOWWKG1T9T5KNC3L.dex --oat-file=/data/user/0/<Package>/cache/<Package>/AVPYQNRINN9Y1HM1AOWWKG1T9T5KNC3L.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/AXD0TPF0VO9S8MTJI9FQV1T3CYP9Q5Q3.dex --oat-file=/data/user/0/<Package>/cache/<Package>/AXD0TPF0VO9S8MTJI9FQV1T3CYP9Q5Q3.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/B4E7N8GVC0MZ6IBIRPHL1DUIUMYL8HOY.dex --oat-file=/data/user/0/<Package>/cache/<Package>/B4E7N8GVC0MZ6IBIRPHL1DUIUMYL8HOY.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/BDW3U5XAADWDJC5ED3NDZF29JRD8CNCS.dex --oat-file=/data/user/0/<Package>/cache/<Package>/BDW3U5XAADWDJC5ED3NDZF29JRD8CNCS.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/COWT4IVTVRPCE2AW34OQERXD8ZYXZ3A3.dex --oat-file=/data/user/0/<Package>/cache/<Package>/COWT4IVTVRPCE2AW34OQERXD8ZYXZ3A3.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/CQ83XCCF0YLIYDI3FYP0AYAC0DF4N2YM.dex --oat-file=/data/user/0/<Package>/cache/<Package>/CQ83XCCF0YLIYDI3FYP0AYAC0DF4N2YM.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/DFQX4VBGGVMV9Q78J5X3XPG7LT7YY1Q2.dex --oat-file=/data/user/0/<Package>/cache/<Package>/DFQX4VBGGVMV9Q78J5X3XPG7LT7YY1Q2.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/E3HYIJJA7BX611M5YWWGS0H51H5SBWND.dex --oat-file=/data/user/0/<Package>/cache/<Package>/E3HYIJJA7BX611M5YWWGS0H51H5SBWND.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/FA891YPFTQ3ZUIKJTLQY68L7EX8MWP8I.dex --oat-file=/data/user/0/<Package>/cache/<Package>/FA891YPFTQ3ZUIKJTLQY68L7EX8MWP8I.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/FI2DUASXG5AX57Y8NIWNCEIC93U2RUJ8.dex --oat-file=/data/user/0/<Package>/cache/<Package>/FI2DUASXG5AX57Y8NIWNCEIC93U2RUJ8.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/FLBIOB3M7LKP9G5U2HWNHLL33WEB21T1.dex --oat-file=/data/user/0/<Package>/cache/<Package>/FLBIOB3M7LKP9G5U2HWNHLL33WEB21T1.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/JI8PPMHF96RZYUOZ1TUY6OL36TO60X8M.dex --oat-file=/data/user/0/<Package>/cache/<Package>/JI8PPMHF96RZYUOZ1TUY6OL36TO60X8M.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/JUSDXATVP23Z6YGBHXY6IKXR2XCEO9S6.dex --oat-file=/data/user/0/<Package>/cache/<Package>/JUSDXATVP23Z6YGBHXY6IKXR2XCEO9S6.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/JY6TMUKH89EH1VYKRAGJ8YU4X362FIVG.dex --oat-file=/data/user/0/<Package>/cache/<Package>/JY6TMUKH89EH1VYKRAGJ8YU4X362FIVG.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/K2TC3M2V3UDM0D2F6WCU40FU8KMPPSTP.dex --oat-file=/data/user/0/<Package>/cache/<Package>/K2TC3M2V3UDM0D2F6WCU40FU8KMPPSTP.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/LZ98Q1XS5BEVVUNKKJ2TRBNXHYOPKZFV.dex --oat-file=/data/user/0/<Package>/cache/<Package>/LZ98Q1XS5BEVVUNKKJ2TRBNXHYOPKZFV.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/M6QR64LJX1NA40461YM4KHBF61O7XX01.dex --oat-file=/data/user/0/<Package>/cache/<Package>/M6QR64LJX1NA40461YM4KHBF61O7XX01.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/MO76TCWHPCN4QRO9CYM0IADSUMGFVMNZ.dex --oat-file=/data/user/0/<Package>/cache/<Package>/MO76TCWHPCN4QRO9CYM0IADSUMGFVMNZ.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/OJBQNFXE9AF6EG39WJXGPBZXUSVVGROL.dex --oat-file=/data/user/0/<Package>/cache/<Package>/OJBQNFXE9AF6EG39WJXGPBZXUSVVGROL.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/OZPIQFAGMNK8BJHKMEVFRTI8NAHJ9A5F.dex --oat-file=/data/user/0/<Package>/cache/<Package>/OZPIQFAGMNK8BJHKMEVFRTI8NAHJ9A5F.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/QQ2J6G1JL1B2O00AXQUWWHN36LKNTD45.dex --oat-file=/data/user/0/<Package>/cache/<Package>/QQ2J6G1JL1B2O00AXQUWWHN36LKNTD45.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/QT7OWLCI4HYQHP3YO4T1DVKYH0NP7CND.dex --oat-file=/data/user/0/<Package>/cache/<Package>/QT7OWLCI4HYQHP3YO4T1DVKYH0NP7CND.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/SO85C2N9JRD8UUUCNGCUQR9T07IHJVYJ.dex --oat-file=/data/user/0/<Package>/cache/<Package>/SO85C2N9JRD8UUUCNGCUQR9T07IHJVYJ.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/TIC11Y6D6AW14G1GTNFJV3CWOCGZUNU8.dex --oat-file=/data/user/0/<Package>/cache/<Package>/TIC11Y6D6AW14G1GTNFJV3CWOCGZUNU8.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/VD4F2T1IIT4D7SLA5RBHNVQT3Z5W874W.dex --oat-file=/data/user/0/<Package>/cache/<Package>/VD4F2T1IIT4D7SLA5RBHNVQT3Z5W874W.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/WU0ZTGSZ0I9E6163ZM5WUYA0ODFWRA6U.dex --oat-file=/data/user/0/<Package>/cache/<Package>/WU0ZTGSZ0I9E6163ZM5WUYA0ODFWRA6U.dex --compiler-filter=verify-none --instruction-set=x86
  • sh -c dex2oat --dex-file=/data/user/0/<Package>/app_payload_lib/<Package>/XX5MDV0MC4UX7JJ9CD9BJ4YAP0VM0K38.dex --oat-file=/data/user/0/<Package>/cache/<Package>/XX5MDV0MC4UX7JJ9CD9BJ4YAP0VM0K38.dex --compiler-filter=verify-none --instruction-set=x86
Loads the following dynamic libraries:
  • libcovault-appsec
Uses special library to hide executable bytecode.
Gets information about network.
Gets information about installed apps.
Intercepts notifications.
Requests the system alert window permission.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android