マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Android.Locker.18067

Added to the Dr.Web virus database: 2024-06-07

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Locker.18064
Network activity:
Connects to:
  • UDP(DNS) <Google DNS>
  • TCP(TLS/1.0) p####.go####.com:443
  • TCP(TLS/1.0) www.and####.com:443
  • TCP(TLS/1.0) googl####.g.doublec####.net:443
  • TCP(TLS/1.0) s####.g.doublec####.net:443
  • TCP(TLS/1.0) yt3.g####.com:443
  • TCP(TLS/1.0) app-mea####.com:443
  • TCP(TLS/1.0) www.googlet####.com:443
  • TCP(TLS/1.0) and####.a####.go####.com:443
  • TCP(TLS/1.0) st####.doublec####.net:443
  • TCP(TLS/1.0) www.go####.com:443
  • TCP(TLS/1.0) a####.google:443
  • TCP(TLS/1.0) p####.l.go####.com:443
  • TCP(TLS/1.0) ssl.gst####.com:443
  • TCP(TLS/1.0) gmscomp####.google####.com:443
  • TCP(TLS/1.0) connect####.gst####.com:443
  • TCP(TLS/1.0) lh3.googleu####.com:443
  • TCP(TLS/1.0) pla####.google####.com:443
  • TCP(TLS/1.0) f####.gst####.com:443
  • TCP(TLS/1.0) i.y####.com:443
  • TCP(TLS/1.0) kst####.googleu####.com:443
  • TCP(TLS/1.0) www.google-####.com:443
  • TCP(TLS/1.0) www.gst####.com:443
  • TCP(TLS/1.2) and####.a####.go####.com:443
  • TCP(TLS/1.2) 1####.250.150.102:443
  • TCP(TLS/1.2) ssl.gst####.com:443
  • TCP(TLS/1.2) gmscomp####.google####.com:443
  • UDP rr2---s####.g####.com:443
  • UDP gmscomp####.google####.com:443
DNS requests:
  • a####.go####.com
  • a####.google
  • a####.google####.com
  • and####.a####.go####.com
  • app-mea####.com
  • clie####.go####.com
  • connect####.gst####.com
  • f####.google####.com
  • f####.gst####.com
  • firebas####.google####.com
  • gmscomp####.google####.com
  • googl####.g.doublec####.net
  • i.y####.com
  • jn####.google####.com
  • kst####.googleu####.com
  • lh3.googleu####.com
  • p####.go####.com
  • p####.google####.com
  • pla####.google####.com
  • rr2---s####.g####.com
  • s####.g.doublec####.net
  • scon####.clie####.go####.com
  • ssl.gst####.com
  • st####.doublec####.net
  • www.and####.com
  • www.go####.com
  • www.google####.com
  • www.google-####.com
  • www.googlet####.com
  • www.gst####.com
  • www.you####.com
  • yt3.g####.com
File system changes:
Creates the following files:
  • /data/data/####/000003.log
  • /data/data/####/015baa3a003ad147_0
  • /data/data/####/015baa3a003ad147_1
  • /data/data/####/0438dc8034130bf8_0
  • /data/data/####/048e9ebc14fd3a78_0
  • /data/data/####/050703ca64266cfe_0
  • /data/data/####/059160e47f883c1f_0
  • /data/data/####/0899dedeadece862_0
  • /data/data/####/092ad7cc7e03bf64_0
  • /data/data/####/0a5c600831a2d625_0
  • /data/data/####/0e0f5b00ddb00654_0
  • /data/data/####/0e21e1e1cad67465_0
  • /data/data/####/0e92320bc7e2aec4_0
  • /data/data/####/110a0a34fc926f06_0
  • /data/data/####/1206a62f37cd7c02_0
  • /data/data/####/124cd6761ec11401_0
  • /data/data/####/12901e44255a8494_0
  • /data/data/####/1300edb5f89d7b1e_0 (deleted)
  • /data/data/####/13e5fa6eb2d25a61_0
  • /data/data/####/13f865f3e0a76bef_0
  • /data/data/####/147015865a6fe5fb_0
  • /data/data/####/14b8322c355e4693_0
  • /data/data/####/1636ac751c417c0a_0
  • /data/data/####/1636ac751c417c0a_1
  • /data/data/####/1677f5dd833d93f6_0
  • /data/data/####/16a132fbae28aa0f_0
  • /data/data/####/16ab1799d989ed6d_0
  • /data/data/####/16ab1799d989ed6d_s
  • /data/data/####/1956fbeea10fcb0d_0
  • /data/data/####/1a567d22308a81ab_0
  • /data/data/####/1b103002a98f6315_0
  • /data/data/####/1b372f219e289375_0
  • /data/data/####/1b6c88978700d620_0
  • /data/data/####/1dd105e7e6a485de_0
  • /data/data/####/1e54a267acbd0182_0
  • /data/data/####/1e63e99843fc27b6_0
  • /data/data/####/1e934468d59c455d_0
  • /data/data/####/2035eea86b9cc08a_0
  • /data/data/####/208332b3a5b199c0_0
  • /data/data/####/208332b3a5b199c0_1
  • /data/data/####/2187aa55c3f1dd1f_0
  • /data/data/####/2292265cfb7a373c_0
  • /data/data/####/22a041ea52089d8b_0
  • /data/data/####/2348c6141d294a0c_0
  • /data/data/####/23918a383c5049f7_0
  • /data/data/####/23bbe1f9eb256c68_0
  • /data/data/####/23bbe1f9eb256c68_1
  • /data/data/####/2431561159572015_0
  • /data/data/####/2476735c36aacd23_0
  • /data/data/####/251721d7b63a8a47_0
  • /data/data/####/25624313fc1f3ce7_0
  • /data/data/####/26a9bbd048246d26_0
  • /data/data/####/27a07621e49729c3_0
  • /data/data/####/2940195bd9870d6e_0
  • /data/data/####/2940195bd9870d6e_1
  • /data/data/####/2998106126ee823f_0
  • /data/data/####/2a0150ca8ba7a341_0
  • /data/data/####/2aa621e62dcd92be_0
  • /data/data/####/2d47d20c7b716088_0
  • /data/data/####/2dd63fad91645da8_0
  • /data/data/####/2f6ad11a6204535c_0
  • /data/data/####/2fb85417961003ae_0
  • /data/data/####/30ae54954ff7e705_0
  • /data/data/####/33ca1a8c0dc96113_0
  • /data/data/####/33ca1a8c0dc96113_1
  • /data/data/####/3479adff0dd69c50_0
  • /data/data/####/35bead04b10b3680_0
  • /data/data/####/36b4f936dd9198df_0
  • /data/data/####/36d866fbf8cb2fbd_0
  • /data/data/####/37d0b13dde4a4859_0
  • /data/data/####/37ed31d2560ca323_0 (deleted)
  • /data/data/####/38d80ff779197ba5_0
  • /data/data/####/3b852079fcec248e_0
  • /data/data/####/3e4386d82a37841c_0
  • /data/data/####/3ebffc7541a42149_0
  • /data/data/####/40054fc8d46766d2_0
  • /data/data/####/405013f5d52d1bed_0
  • /data/data/####/41517028a23d266b_0
  • /data/data/####/437f586e9e62a724_0
  • /data/data/####/4450e58a1cb3e392_0
  • /data/data/####/445b8865f153418f_0
  • /data/data/####/445b8865f153418f_1
  • /data/data/####/4476d81b47490284_0
  • /data/data/####/45a458bdcbe3f941_0
  • /data/data/####/47663f6abb5f4b86_0
  • /data/data/####/4841bf92d278e88e_0
  • /data/data/####/491885bedc4c7d37_0
  • /data/data/####/49d7d88e54917013_0
  • /data/data/####/49d7d88e54917013_s
  • /data/data/####/4b25ad73998bae34_0
  • /data/data/####/4bfafc3213f8a565_0
  • /data/data/####/4c0c7a79e0191f49_0
  • /data/data/####/4d45d87518e706dc_0
  • /data/data/####/4e1a6b30bc5cc955_0
  • /data/data/####/4f514a712f3b9321_0
  • /data/data/####/521b9989624d62af_0
  • /data/data/####/526fa33409b2a63c_0
  • /data/data/####/52b023cfb543f128_0
  • /data/data/####/549e486a5e4107ca_0 (deleted)
  • /data/data/####/551d5c9749ba38b3_0
  • /data/data/####/555caf4bfc2bc819_0
  • /data/data/####/55cf3a7285de66bf_0
  • /data/data/####/5684027ec1d59b0f_0
  • /data/data/####/5684027ec1d59b0f_1
  • /data/data/####/5697abe82b14aa4e_0
  • /data/data/####/56ccab56f4251d87_0
  • /data/data/####/5750b4afdc2d221b_0
  • /data/data/####/580c56e3207dbee7_0
  • /data/data/####/5810318dc3816061_0
  • /data/data/####/58bfa3c42883b81a_0 (deleted)
  • /data/data/####/59b6230d3d7bec91_0
  • /data/data/####/5a58b4e7cac3348f_0
  • /data/data/####/5b5e1ba5b324d210_0
  • /data/data/####/5bc7ef1cd4b353d6_0
  • /data/data/####/5bfd49808a8265aa_0
  • /data/data/####/5c74b7944221badd_0
  • /data/data/####/5ca50924ce3c5c59_0
  • /data/data/####/5ca50924ce3c5c59_0 (deleted)
  • /data/data/####/5d0dc7e642237297_0
  • /data/data/####/5dd1937a984d977e_0
  • /data/data/####/60dc157ec6692cee_0
  • /data/data/####/61a477cb1832f305_0
  • /data/data/####/61a477cb1832f305_1
  • /data/data/####/635cc0a3a7996a20_0
  • /data/data/####/63c8ab27e5884157_0
  • /data/data/####/64571a88f432787b_0
  • /data/data/####/64d4aa2b82b0254e_0 (deleted)
  • /data/data/####/659835d25fb11dc2_0
  • /data/data/####/659835d25fb11dc2_0 (deleted)
  • /data/data/####/68a0d2a50c958fc0_0
  • /data/data/####/69f0405f065629c7_0
  • /data/data/####/69f0405f065629c7_1
  • /data/data/####/6a2f5fc3dbf4d727_0
  • /data/data/####/6a32c8b36b37885f_0
  • /data/data/####/6bed255edf1b0978_0
  • /data/data/####/6c61df2e3dcb2dc2_0
  • /data/data/####/6cf12676ad638724_0
  • /data/data/####/6d52f36b29c9ce6c_0
  • /data/data/####/6d7e033903e1f31d_0
  • /data/data/####/6dbfbdff918b77bc_0
  • /data/data/####/6dbfbdff918b77bc_1
  • /data/data/####/6dc05946d438793b_0
  • /data/data/####/6e1eb4413b92cee0_0
  • /data/data/####/70ea0e8d3ef2ff46_0
  • /data/data/####/713f92efd2339266_0
  • /data/data/####/71468ea31f5a7be1_0
  • /data/data/####/73a905ac2ed6395d_0
  • /data/data/####/75a78f9b2ba06212_0
  • /data/data/####/75b0f1836a91d759_0
  • /data/data/####/75fe90497f83b5a9_0
  • /data/data/####/76b0770fc0758676_0
  • /data/data/####/78532ba342d58720_0 (deleted)
  • /data/data/####/78bdd0decee68567_0
  • /data/data/####/78bdd0decee68567_1
  • /data/data/####/78d1903fb1ba9814_0
  • /data/data/####/7d1093396367c02a_0
  • /data/data/####/7fd09ab67efe1d9a_0
  • /data/data/####/7fec5f9248bfaad5_0
  • /data/data/####/81408aca35f74911_0
  • /data/data/####/8294e5d62154c0da_0
  • /data/data/####/82ad331e64cb9060_0
  • /data/data/####/83b8a51934e7f6cf_0
  • /data/data/####/84f1ee9d60d2ca77_0
  • /data/data/####/85038a9b1250321b_0
  • /data/data/####/860b5d1c0fbe783e_0
  • /data/data/####/864c12aedf31ea33_0
  • /data/data/####/878889f3d742862f_0
  • /data/data/####/878889f3d742862f_1
  • /data/data/####/89a80e39b6fab4c9_0
  • /data/data/####/8a067f6e2fed118f_0
  • /data/data/####/8a067f6e2fed118f_1
  • /data/data/####/8a5f98859410dcb0_0
  • /data/data/####/8a96075c0fea6946_0
  • /data/data/####/8a96075c0fea6946_1
  • /data/data/####/8f02542e2f38f422_0
  • /data/data/####/8f02542e2f38f422_1
  • /data/data/####/8fe7f16b5086983b_0
  • /data/data/####/90143124eec35c78_0 (deleted)
  • /data/data/####/901ddc3bbe5ae563_0 (deleted)
  • /data/data/####/90eaecc843997638_0
  • /data/data/####/917b413db9baf440_0
  • /data/data/####/92b526d248277a70_0 (deleted)
  • /data/data/####/93754b2cd16b0cec_0
  • /data/data/####/93a4e6f8868af855_0
  • /data/data/####/954b9483f146bd87_0
  • /data/data/####/988218dc84e50e66_0
  • /data/data/####/988218dc84e50e66_1
  • /data/data/####/98feab2ff86ccff8_0
  • /data/data/####/995164280ba0eb27_0
  • /data/data/####/9986275cd8c6c8b8_0
  • /data/data/####/99d818f58dcae934_0
  • /data/data/####/9af17b21109c1789_0
  • /data/data/####/9b1923cc17534ac0_0
  • /data/data/####/9b2b9d164d695d9b_0
  • /data/data/####/9b2ecf42b9ad13c9_0
  • /data/data/####/9b93882585fd9968_0
  • /data/data/####/9e14749b52c22a61_0
  • /data/data/####/9e14749b52c22a61_1
  • /data/data/####/9ea707a5514672c8_0
  • /data/data/####/9ea707a5514672c8_1
  • /data/data/####/9f2bce2bbb228bcb_0
  • /data/data/####/9f8710558bc38f17_0
  • /data/data/####/CURRENT
  • /data/data/####/Cookies-journal
  • /data/data/####/Databases.db-journal
  • /data/data/####/FxnWYFBYYd.dex
  • /data/data/####/FxnWYFBYYd.dex.flock (deleted)
  • /data/data/####/LOCK
  • /data/data/####/LOG
  • /data/data/####/MANIFEST-000001
  • /data/data/####/QuotaManager-journal
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/YqjieXr.dex
  • /data/data/####/YqjieXr.dex.flock (deleted)
  • /data/data/####/a07300c911848fc2_0
  • /data/data/####/a1e5b2d0a16aa437_0
  • /data/data/####/a2f776742e7ce9e1_0
  • /data/data/####/a4808b8b56cddadd_0
  • /data/data/####/a629e1031ef10344_0
  • /data/data/####/a75c85616d45e482_0
  • /data/data/####/a8e293138c86d3a9_0
  • /data/data/####/a93d07db9120eedb_0
  • /data/data/####/a9f37e253ce40ad5_0
  • /data/data/####/aa9ee0ecdb5917b9_0
  • /data/data/####/ac952f81ac50ea31_0
  • /data/data/####/aca0790415495162_0
  • /data/data/####/ad8f221eb284769d_0
  • /data/data/####/af535d7044b9ba70_0
  • /data/data/####/af75879be0a2e194_0
  • /data/data/####/afa0effe6a59f4f5_0
  • /data/data/####/b16313dff950ccec_0
  • /data/data/####/b1a539049581e685_0
  • /data/data/####/b23d09e4a7917a8e_0
  • /data/data/####/b2e5bdf1f38fe7bf_0
  • /data/data/####/b36d743e6650d0c0_0
  • /data/data/####/b4e5df1dad6b62b7_0 (deleted)
  • /data/data/####/b58ff8b6d12300b3_0
  • /data/data/####/b6bf2814c987d2c2_0
  • /data/data/####/b79ee2769598fa01_0
  • /data/data/####/b7fcc03515343edc_0
  • /data/data/####/b7fcc03515343edc_s
  • /data/data/####/b806bf6174d57822_0
  • /data/data/####/b92c5b3098a37a27_0
  • /data/data/####/b93ed6b3169dde21_0
  • /data/data/####/ba5aea4a59052b7b_0
  • /data/data/####/bb0b67d7a7a33f9a_0
  • /data/data/####/bbe7a0abb0bc0c8c_0
  • /data/data/####/bbe7a0abb0bc0c8c_1
  • /data/data/####/bd20a1f3237fc950_0
  • /data/data/####/be297a1d75caa0c6_0
  • /data/data/####/be65b742fb1c34d8_0
  • /data/data/####/c18d47e1dcf5b3c3_0
  • /data/data/####/c269f499860f1d26_0
  • /data/data/####/c270dc26b6e8d4a4_0
  • /data/data/####/c270dc26b6e8d4a4_1
  • /data/data/####/c32cb189425dd91f_0
  • /data/data/####/c42f479b36dd3c58_0
  • /data/data/####/c4eb76e14a743956_0
  • /data/data/####/c89876f3211aa6f9_0
  • /data/data/####/c8cb69338f620616_0
  • /data/data/####/c91ec75626ffb902_0
  • /data/data/####/cb6bfe10e458291b_0
  • /data/data/####/cbe4186090e48953_0
  • /data/data/####/cdd9ef40770b85bf_0
  • /data/data/####/com.boxnpu_preferences.xml
  • /data/data/####/d11081d7701b0335_0
  • /data/data/####/d2b0948d3caa0252_0
  • /data/data/####/d3081016549c26da_0
  • /data/data/####/d47abf4e99759411_0
  • /data/data/####/d4b894033292c1d4_0
  • /data/data/####/d514a66f6667fe82_0
  • /data/data/####/d5ec0082e446057a_0
  • /data/data/####/d6e82456084e5124_0
  • /data/data/####/d6e82456084e5124_1
  • /data/data/####/d848c457b31c120a_0
  • /data/data/####/d870b82407a9aa0b_0
  • /data/data/####/d921cc85cafa4d7d_0
  • /data/data/####/d921cc85cafa4d7d_1
  • /data/data/####/d960bafde34340b9_0
  • /data/data/####/da434f9a2d3b4c0f_0
  • /data/data/####/dbc830e9e52cc82c_0
  • /data/data/####/dcf1ee2b28e8e9a0_0
  • /data/data/####/dcf1ee2b28e8e9a0_1
  • /data/data/####/df00135d8daf9cb2_0
  • /data/data/####/df2c18ffd96e2a09_0
  • /data/data/####/dfa8b9b7f74bbb5a_0
  • /data/data/####/dfb04b550f94b669_0
  • /data/data/####/e04c954ddf492aea_0
  • /data/data/####/e0d2e1ffb983055e_0
  • /data/data/####/e0e247355435470a_0
  • /data/data/####/e2338aa768c3cd0c_0
  • /data/data/####/e3538071db9b31bb_0
  • /data/data/####/e3538071db9b31bb_1
  • /data/data/####/e49b73494151f26d_0
  • /data/data/####/e57af0c5a1ba7ac2_0
  • /data/data/####/e607a0977b119a99_0
  • /data/data/####/e607a0977b119a99_1
  • /data/data/####/e6a3c1edb4a9d94b_0
  • /data/data/####/ec1c212c7961c584_0
  • /data/data/####/ede7ca38fc8cc6d7_0
  • /data/data/####/edf062f3c642b5e3_0
  • /data/data/####/edfadef5e5d88f7d_0
  • /data/data/####/f07c219b17cb5f0c_0
  • /data/data/####/f07c219b17cb5f0c_1
  • /data/data/####/f13d26ff9186d8c7_0
  • /data/data/####/f13d26ff9186d8c7_1
  • /data/data/####/f27185831114c858_0
  • /data/data/####/f3329f06499ce4f8_0 (deleted)
  • /data/data/####/f554859bc5ce3d24_0
  • /data/data/####/f554859bc5ce3d24_1
  • /data/data/####/f68c7de2bee7612b_0
  • /data/data/####/f6a4ac604bbb310f_0
  • /data/data/####/f7297a7c91e73715_0
  • /data/data/####/f75bb25b20d58db7_0
  • /data/data/####/f9b5d7e534896597_0
  • /data/data/####/fa37276f9f2dbccb_0
  • /data/data/####/fab806e0afe4c9b6_0
  • /data/data/####/fbef686b272361f6_0
  • /data/data/####/fc157837aea287dc_0
  • /data/data/####/fc157837aea287dc_1
  • /data/data/####/fc235a1d8d8f4b57_0
  • /data/data/####/ff36081cd8b7385d_0
  • /data/data/####/ff61ee39c6ceb40f_0
  • /data/data/####/ffa1d2b7f6cc250b_0
  • /data/data/####/index
  • /data/data/####/index.txt
  • /data/data/####/lEYEO.dex
  • /data/data/####/lEYEO.dex.flock (deleted)
  • /data/data/####/metrics_guid
  • /data/data/####/temp-index
  • /data/data/####/the-real-index
  • /data/data/####/the-real-index (deleted)
  • /data/misc/####/primary.prof
Miscellaneous:
Accesses camera interface.
Gets information about network.
Displays its own windows over windows of other apps.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android