マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話

03-6550-8770

Profile

Android.Locker.17981

Added to the Dr.Web virus database: 2024-03-22

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Locker.1475.origin
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(TLS/1.0) bend-me####.com:443
  • TCP(TLS/1.0) gmscomp####.google####.com:443
  • TCP(TLS/1.0) rr9---s####.g####.com:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) el.ph####.com:443
  • TCP(TLS/1.0) ads.traffic####.net:443
  • TCP(TLS/1.0) bts.ins####.com:443
  • TCP(TLS/1.0) u####.com:443
  • TCP(TLS/1.0) www.go####.ru:443
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.0) h####.por####.com:443
  • TCP(TLS/1.0) longst####.com:443
  • TCP(TLS/1.0) ss.ph####.com:443
  • TCP(TLS/1.0) s####.g.doublec####.net:443
  • TCP(TLS/1.0) sto####.google####.com:443
  • TCP(TLS/1.0) f####.gst####.com:443
  • TCP(TLS/1.0) cdn1-sm####.ph####.com:443
  • TCP(TLS/1.0) f####.google####.com:443
  • TCP(TLS/1.0) retarge####.com:443
  • TCP(TLS/1.0) connect####.gst####.com:443
  • TCP(TLS/1.0) n####.abimim####.com:443
  • TCP(TLS/1.0) and####.a####.go####.com:443
  • TCP(TLS/1.0) analy####.go####.com:443
  • TCP(TLS/1.0) datin####.com:443
  • TCP(TLS/1.0) 74.1####.131.139:443
  • TCP(TLS/1.0) www.por####.com:443
  • TCP(TLS/1.0) rr6---s####.g####.com:443
  • TCP(TLS/1.2) gmscomp####.google####.com:443
  • TCP(TLS/1.2) 74.1####.131.101:443
  • UDP rr2---s####.g####.com:443
  • UDP gmscomp####.google####.com:443
DNS requests:
  • ads.traffic####.net
  • analy####.go####.com
  • and####.a####.go####.com
  • and####.google####.com
  • bend-me####.com
  • bts.ins####.com
  • cdn1-sm####.ph####.com
  • cdn1d-s####.ph####.com
  • connect####.gst####.com
  • datin####.com
  • ei.ph####.com
  • el.ph####.com
  • f####.google####.com
  • f####.gst####.com
  • gmscomp####.google####.com
  • h####.por####.com
  • longst####.com
  • m####.go####.com
  • m####.traffic####.net
  • p####.google####.com
  • retarge####.com
  • rr2---s####.g####.com
  • rr6---s####.g####.com
  • rr9---s####.g####.com
  • s####.g.doublec####.net
  • ss.ph####.com
  • sto####.google####.com
  • u####.com
  • www.go####.com
  • www.go####.ru
  • www.google####.com
  • www.google-####.com
  • www.googlet####.com
  • www.por####.com
  • xo####.metlcul####.net
File system changes:
Creates the following files:
  • /data/data/####/0059d4c61ef7bea0_0
  • /data/data/####/02e5afe38d4a779b_0
  • /data/data/####/037e16fc97a2d984_0
  • /data/data/####/04e0691b71625092_0 (deleted)
  • /data/data/####/091770d4d798b659_0
  • /data/data/####/095afae11628a4ce_0
  • /data/data/####/09be61823b30f701_0
  • /data/data/####/0a364fb28e1eff70_0
  • /data/data/####/0baea7948606e3b1_0
  • /data/data/####/0fecc5dfd83d3311_0
  • /data/data/####/11e6d0c100ef6553_0
  • /data/data/####/11e6d0c100ef6553_1
  • /data/data/####/138f425a5120ba63_0
  • /data/data/####/13b53e57478e4448_0 (deleted)
  • /data/data/####/13d60a57f85cca72_0
  • /data/data/####/140091e78ced528d_0
  • /data/data/####/143d88573d570912_0
  • /data/data/####/175b1b452710f14f_0
  • /data/data/####/19a3a076856b51e4_0
  • /data/data/####/1a2dd6623901f0e2_0
  • /data/data/####/1b5491b9c9da3bb7_0
  • /data/data/####/1b57e9a0e92112a8_0
  • /data/data/####/1c51e192d205be56_0
  • /data/data/####/1cc714778e2dfa59_0
  • /data/data/####/1cdc9560e0282cb4_0 (deleted)
  • /data/data/####/1ecf4e4d63dfe6af_0
  • /data/data/####/1edf8f22f71ae995_0
  • /data/data/####/1f4083e14aaf2f8b_0
  • /data/data/####/1fda99d0c2eaf8cb_0
  • /data/data/####/1fda99d0c2eaf8cb_1
  • /data/data/####/20228e4c5f180e22_0
  • /data/data/####/21247a0e54e66ce3_0
  • /data/data/####/2505f1bdf1528e50_0
  • /data/data/####/25384bbcf95f97f6_0
  • /data/data/####/268ddc666ec24fa2_0
  • /data/data/####/274200cc292bb2ee_0
  • /data/data/####/2940195bd9870d6e_0
  • /data/data/####/2940195bd9870d6e_1
  • /data/data/####/29bf5707f6f5e718_0
  • /data/data/####/2a672c609bf75212_0
  • /data/data/####/2b50071db951b078_0
  • /data/data/####/2bcdb6fe46c8f096_0
  • /data/data/####/2cc80dabc69f58b6_0
  • /data/data/####/2e56ae2b907de178_0
  • /data/data/####/2e56ae2b907de178_1
  • /data/data/####/2e761f694438a3a6_0
  • /data/data/####/2e7d2766f49ea3ae_0
  • /data/data/####/2fd39fa451651e9f_0
  • /data/data/####/302fbdf32d767003_0
  • /data/data/####/319f43a56b837545_0
  • /data/data/####/32eb476c0f39ee00_0
  • /data/data/####/331f90a99c54505f_0
  • /data/data/####/335c0f26a21285bb_0
  • /data/data/####/33722cf88a938c86_0
  • /data/data/####/33b47afb1195617a_0
  • /data/data/####/3692ed522706643a_0
  • /data/data/####/3696f68521dc36bb_0
  • /data/data/####/37b297640f939f40_0
  • /data/data/####/37e76bcc2d338728_0
  • /data/data/####/38dcf66e81d010b5_0
  • /data/data/####/39362e6494ed19cc_0
  • /data/data/####/39362e6494ed19cc_1
  • /data/data/####/3a199c315dbaf2f3_0
  • /data/data/####/3a2bcc3591a3e292_0
  • /data/data/####/3a31d6041484cb8a_0
  • /data/data/####/3a31d6041484cb8a_1
  • /data/data/####/3b3a4603efda1d48_0
  • /data/data/####/3b596f27fa059cc0_0
  • /data/data/####/3e1b969cf3990a6f_0
  • /data/data/####/3ea4d78ea985ea67_0
  • /data/data/####/3fe060681b94bb40_0
  • /data/data/####/3ff34dc9d2ab4b3d_0
  • /data/data/####/40beb0ad5d29023c_0
  • /data/data/####/416a7d90cbbbda1b_0 (deleted)
  • /data/data/####/41921419ec2e437b_0
  • /data/data/####/41e007fd4700d87e_0
  • /data/data/####/43d01cff72467a0d_0
  • /data/data/####/44a8721f73bca5d9_0
  • /data/data/####/454a11e8855b60b1_0
  • /data/data/####/461b605a9f07e4d2_0
  • /data/data/####/46618695e86f2d0a_0
  • /data/data/####/48272cc2a8051d34_0
  • /data/data/####/482f58354005718a_0
  • /data/data/####/482f58354005718a_1
  • /data/data/####/489504df7985392e_0
  • /data/data/####/4adcae051808854d_0
  • /data/data/####/4baac7b2158954a0_0
  • /data/data/####/4bcd0c66adc69813_0
  • /data/data/####/4bcd0c66adc69813_1
  • /data/data/####/4cb013792b196a35_0
  • /data/data/####/4cb013792b196a35_1
  • /data/data/####/4cee9940b26be54e_0
  • /data/data/####/4e54ba40b5b8a4f5_0
  • /data/data/####/4ed0070704a56e97_0
  • /data/data/####/4f339779106045cf_0
  • /data/data/####/5026cef840ebe16c_0
  • /data/data/####/5107d8b8b3e1fd3c_0
  • /data/data/####/51601d3d55b76398_0
  • /data/data/####/518fac0b5057aba6_0
  • /data/data/####/518fac0b5057aba6_1
  • /data/data/####/51977fb6c3420c06_0
  • /data/data/####/54b903747f661690_0
  • /data/data/####/5524e24847ac8138_0 (deleted)
  • /data/data/####/554fc100bf62286d_0
  • /data/data/####/56199bc988541b73_0
  • /data/data/####/56199bc988541b73_1
  • /data/data/####/56c5d77ae254a86f_0
  • /data/data/####/57086f58d8589ebd_0
  • /data/data/####/5816d2625538cec3_0
  • /data/data/####/5816d2625538cec3_1
  • /data/data/####/58246537f2bb0f4e_0
  • /data/data/####/58b30bc08e758eae_0
  • /data/data/####/59b8e941d231c9d1_0
  • /data/data/####/5a3a429b549a98c0_0
  • /data/data/####/5a3a429b549a98c0_1
  • /data/data/####/5a6ec868f2ae9749_0
  • /data/data/####/5b3c9faadf07966b_0
  • /data/data/####/5b3c9faadf07966b_1
  • /data/data/####/5b8e498d769b2c74_0
  • /data/data/####/5ca5d0b6a1b4e269_0
  • /data/data/####/5fa35c56c4f1ca2d_0
  • /data/data/####/61a537e0025801b5_0
  • /data/data/####/62c7a4b13f61aac3_0
  • /data/data/####/62d25b9213a36caa_0
  • /data/data/####/62f41d8a03f269ec_0
  • /data/data/####/6361971b6eff071b_0
  • /data/data/####/637acc10f9f1ace0_0
  • /data/data/####/64c9cbb28868be6a_0
  • /data/data/####/64e989a30733a008_0
  • /data/data/####/64e989a30733a008_1
  • /data/data/####/657abb729240006f_0
  • /data/data/####/66dcbc6f2d519685_0
  • /data/data/####/6798242373964f72_0
  • /data/data/####/689326c30218c5e1_0
  • /data/data/####/68f69369a46e9056_0
  • /data/data/####/6a183740cfc79df8_0
  • /data/data/####/6a75ce0b2c176985_0
  • /data/data/####/6ab9399ad24728e1_0
  • /data/data/####/6b44d6a66a589119_0
  • /data/data/####/6b44d6a66a589119_1
  • /data/data/####/6b762af762457d02_0
  • /data/data/####/6d6381b1d0fd4f41_0
  • /data/data/####/6d6381b1d0fd4f41_1
  • /data/data/####/6e0e18b6803538da_0
  • /data/data/####/6ea6687ec6b96dce_0
  • /data/data/####/6f5d323ed3eb8927_0
  • /data/data/####/6fb890c8825238e7_0
  • /data/data/####/6fb890c8825238e7_1
  • /data/data/####/70fc6d057ae6906b_0
  • /data/data/####/712bf486386bcc46_0
  • /data/data/####/71a4cf0f2daa983b_0
  • /data/data/####/72a80c29e7e4b304_0
  • /data/data/####/72f79cb21f6b814e_0
  • /data/data/####/73719fc6d66b82df_0
  • /data/data/####/740f9f0a5fb14d9b_0
  • /data/data/####/74317f94aa15fca0_0
  • /data/data/####/74e952e675561c87_0
  • /data/data/####/75b55804c44ec152_0
  • /data/data/####/75b55804c44ec152_1
  • /data/data/####/75c17dbde35a71b1_0
  • /data/data/####/75cdd6d4f3bf1d4b_0
  • /data/data/####/78e3bceb48df965f_0
  • /data/data/####/794928905c481d14_0
  • /data/data/####/79e48ef11f019e3b_0
  • /data/data/####/79fbda025aa6fb4c_0
  • /data/data/####/7aab4d1e49f73e87_0
  • /data/data/####/7bb7f09cf7ea7b74_0
  • /data/data/####/7c037596121fcc87_0
  • /data/data/####/7c575b908ae55085_0
  • /data/data/####/7d2f483fb21b60f2_0
  • /data/data/####/7e2e81b993e7036e_0
  • /data/data/####/7e2e81b993e7036e_1
  • /data/data/####/7e48091a74668621_0
  • /data/data/####/7ede7b6d91fafd59_0
  • /data/data/####/7f0327b36e927cd9_0
  • /data/data/####/80a68082ca141b4b_0
  • /data/data/####/82691b748d9f9bf0_0
  • /data/data/####/84081b4972bbfdea_0
  • /data/data/####/8534d70a1f65cd9c_0
  • /data/data/####/86de11722216820b_0
  • /data/data/####/8888bac454c36fa6_0
  • /data/data/####/8888bac454c36fa6_1
  • /data/data/####/890422e5a717293c_0
  • /data/data/####/89faca86f37c5f9c_0
  • /data/data/####/8fbaff932e2a093c_0
  • /data/data/####/909f6ab9a49cd500_0
  • /data/data/####/937ed6ccc621cbc9_0 (deleted)
  • /data/data/####/9402ef73a016ffbb_0
  • /data/data/####/949d0cb185d4e4b1_0
  • /data/data/####/95cae56d052c205b_0
  • /data/data/####/95da412bea0e8ab3_0
  • /data/data/####/984f98b3899add5d_0 (deleted)
  • /data/data/####/98795220a7d19a3b_0
  • /data/data/####/9afc16a6650352e0_0
  • /data/data/####/9afc16a6650352e0_1
  • /data/data/####/9b7c4858192afa64_0
  • /data/data/####/9b7c4858192afa64_1
  • /data/data/####/9c32f12ca1dacc6a_0
  • /data/data/####/9e61552832a50985_0
  • /data/data/####/CURRENT
  • /data/data/####/Cookies-journal
  • /data/data/####/Databases.db-journal
  • /data/data/####/MANIFEST-000001
  • /data/data/####/MEsYXnEHO.dex
  • /data/data/####/MEsYXnEHO.dex.flock (deleted)
  • /data/data/####/NFugYf.dex
  • /data/data/####/NFugYf.dex.flock (deleted)
  • /data/data/####/QuotaManager-journal
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/a0a51bfd37a8bf5d_0
  • /data/data/####/a0a51bfd37a8bf5d_1
  • /data/data/####/a1a0eb390b604316_0
  • /data/data/####/a1a0eb390b604316_1
  • /data/data/####/a317d8b09bea59df_0
  • /data/data/####/a4555d2b5494510d_0
  • /data/data/####/a5d8e52c5974f79d_0
  • /data/data/####/a6439409e723f487_0
  • /data/data/####/a6439409e723f487_1
  • /data/data/####/a7a4c167d1dbc8c0_0
  • /data/data/####/a8442524169968a8_0
  • /data/data/####/aa88e9253c4c929a_0
  • /data/data/####/ab6e521f783bdc12_0
  • /data/data/####/ae97ee15aa894569_0
  • /data/data/####/ae97ee15aa894569_1
  • /data/data/####/aeafe34adc808330_0
  • /data/data/####/aeafe34adc808330_1
  • /data/data/####/b0cff18d493d843b_0
  • /data/data/####/b1b027071aae7656_0
  • /data/data/####/b1b027071aae7656_1
  • /data/data/####/b213848c284bb250_0
  • /data/data/####/b2ef32771f2f18e7_0
  • /data/data/####/b3987c1bd4e21ce5_0
  • /data/data/####/b3ef8bb1645fc7c4_0
  • /data/data/####/b5aa2122b1bda3d7_0
  • /data/data/####/b6005ed34a8f2253_0
  • /data/data/####/b658721792b71eff_0
  • /data/data/####/b65bd9cc5588b496_0
  • /data/data/####/b7c0eb9b82370bb2_0
  • /data/data/####/b81038b40c149ec9_0
  • /data/data/####/b81038b40c149ec9_1
  • /data/data/####/b847531a252dd22e_0
  • /data/data/####/b847531a252dd22e_1
  • /data/data/####/b97521682eb94942_0
  • /data/data/####/b9fa3f927c775ca3_0
  • /data/data/####/ba9f38eed44431d3_0 (deleted)
  • /data/data/####/bdc7dca1fe9a5a3a_0
  • /data/data/####/bdc7dca1fe9a5a3a_1
  • /data/data/####/be97427b03d8575a_0
  • /data/data/####/be984df175e6b08c_0
  • /data/data/####/bffd55d67a733d21_0
  • /data/data/####/c07d78cdfd2fcace_0
  • /data/data/####/c07d78cdfd2fcace_1
  • /data/data/####/c0ff0da31d0bd76b_0
  • /data/data/####/c1c1f2b3add18b61_0
  • /data/data/####/c24a544b58357c9f_0
  • /data/data/####/c24a544b58357c9f_1
  • /data/data/####/c30477915f41e1d4_0
  • /data/data/####/c3ad037f6aa07275_0
  • /data/data/####/c41f142177a71782_0
  • /data/data/####/c41f142177a71782_1
  • /data/data/####/c42ced0c58dfae8b_0
  • /data/data/####/c6babc5302fe693d_0
  • /data/data/####/c7da7fc1fd72af35_0
  • /data/data/####/c821be02766c151b_0
  • /data/data/####/c9571618a156fdb7_0
  • /data/data/####/c96d7944a0933d1f_0
  • /data/data/####/c9d6c153bc7b89a0_0 (deleted)
  • /data/data/####/cc08e9a3c537a6a6_0
  • /data/data/####/ccb6ae163afebfc0_0
  • /data/data/####/cda5b7ba9a1d9bf9_0
  • /data/data/####/ce99954b54aff87b_0
  • /data/data/####/ceb6213f42de03c2_0
  • /data/data/####/ceb6213f42de03c2_1
  • /data/data/####/com.opa_preferences.xml
  • /data/data/####/d00edb6132ba214e_0
  • /data/data/####/d29498d32466c4a2_0
  • /data/data/####/d479f41ddbccc691_0
  • /data/data/####/d479f41ddbccc691_1
  • /data/data/####/d63f51ef9e6f585e_0
  • /data/data/####/da656b5775b93a3c_0
  • /data/data/####/dac9d998e0af9cbc_0
  • /data/data/####/dac9d998e0af9cbc_1
  • /data/data/####/dad378f1f69a5264_0
  • /data/data/####/dc3420c113929a5b_0
  • /data/data/####/dd6bbb1148414656_0
  • /data/data/####/df445bb47e6c77d0_0
  • /data/data/####/df7e2e4358d66685_0
  • /data/data/####/dfd08011f5008da9_0
  • /data/data/####/e2f61eadbaae44d0_0
  • /data/data/####/e2f61eadbaae44d0_1
  • /data/data/####/e344eb5ebb45b0d4_0
  • /data/data/####/e3dc622da5b5c717_0
  • /data/data/####/e5f977e9c0d009d0_0
  • /data/data/####/e671fd2c0dadf5b3_0
  • /data/data/####/e779e52261925042_0
  • /data/data/####/e8e19e85d90de041_0
  • /data/data/####/e901a8b1d3f4b0bf_0
  • /data/data/####/ea3d8d50f8615d85_0
  • /data/data/####/ebcbdd115cf1772c_0
  • /data/data/####/ebef35fb2b0f0bf4_0
  • /data/data/####/ec0ddf9232389d9f_0
  • /data/data/####/ecaadf166bf6d571_0
  • /data/data/####/ee62a3850636e459_0
  • /data/data/####/ee62a3850636e459_1
  • /data/data/####/efe5565df5b492f2_0
  • /data/data/####/efe5d2620356fe71_0
  • /data/data/####/efe5d2620356fe71_1
  • /data/data/####/effd37cf07a9b470_0 (deleted)
  • /data/data/####/f30f5b0a85ec9b2d_0
  • /data/data/####/f3b9acb96c8e8ad4_0
  • /data/data/####/f3bc64089fc60292_0
  • /data/data/####/f3bc64089fc60292_1
  • /data/data/####/f537354abb242bc6_0
  • /data/data/####/f59083fab2974a70_0
  • /data/data/####/f5fa9c6556e1c73b_0
  • /data/data/####/f5fa9c6556e1c73b_1
  • /data/data/####/f66190232104951a_0
  • /data/data/####/f66190232104951a_1
  • /data/data/####/f6b6da8a8cf1066e_0
  • /data/data/####/f752dc463338e643_0
  • /data/data/####/f752dc463338e643_1
  • /data/data/####/f7885de88148296b_0
  • /data/data/####/f82b6317d1ea8738_0
  • /data/data/####/f9d0e6498978d551_0
  • /data/data/####/fa198057ec24c743_0
  • /data/data/####/faff8e477b83b670_0
  • /data/data/####/fb22d47945ad80e1_0
  • /data/data/####/fb4bfe216ca7edb7_0
  • /data/data/####/fb89879884532688_0
  • /data/data/####/fbd3ba0341e0b989_0
  • /data/data/####/fc4970b776326822_0
  • /data/data/####/fcb7185336ff17e5_0
  • /data/data/####/fe9487e45db452ad_0
  • /data/data/####/index
  • /data/data/####/ljefrG.dex
  • /data/data/####/ljefrG.dex.flock (deleted)
  • /data/data/####/metrics_guid
  • /data/data/####/temp-index
  • /data/data/####/the-real-index
  • /data/misc/####/primary.prof
Miscellaneous:
Gets information about network.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android