Library
My library

+ Add to library

Profile

Android.Hidden.2096

Added to the Dr.Web virus database: 2017-02-28

Virus description added:

Technical information

Malicious functions:
Removes its shortcut from the home screen.
Network activity:
Connecting to:
  • beac####.net
  • ab534d6####.####.net
  • frank####.####.com
  • nyct####.com
  • 25wfbnp####.ru
  • r####.####.com
  • 1####.####.235
  • b####.####.com
  • s####.####.com
  • statcou####.com
  • google-####.com
  • p####.####.com
  • 5####.####.196
  • f####.####.com
  • f####.news
  • m####.####.com
  • l####.direct
  • searcht####.com
  • searcha####.com
  • a####.####.com
  • con####.####.net
  • cloudfr####.####.com
  • c####.####.com
HTTP GET requests:
  • con####.####.net/en_US/fbevents.js
  • b####.####.com/css/subscribe-button-modal.min.css?h=####
  • s####.####.com/g.gif?v=####&j=####&blog=####&post=####&tz=####&srv=####&host=####&ref=####&rand=####
  • s####.####.com/j/sendrolling.js
  • b####.####.com/css/subscribe-button.min.css?h=####
  • s####.####.com/static/layers.bb453bb5c9d28f341a4b.js
  • f####.news/wp-content/themes/15zine/library/js/cb-ext.js?ver=####
  • f####.news/wp-content/plugins/bloom/js/idle-timer.min.js?ver=####
  • f####.news/wp-content/plugins/content_timeline/css/frontend/awesome/fontawesome-webfont.ttf?v=####
  • f####.news/wp-content/themes/15zine/library/css/style.css?ver=####
  • b####.####.com/static/button/i/54/59F/BE6/54DFB5305182A933.json
  • f####.news/wp-content/themes/15zine/plugins/login-with-ajax/login-with-ajax.js?ver=####
  • google-####.com/analytics.js
  • f####.news/wp-includes/js/jquery/ui/widget.min.js?ver=####
  • f####.news/wp-content/plugins/bloom/js/jquery.uniform.min.js?ver=####
  • f####.####.com/s/opensans/v13/k3k702ZOKiLJc3WVjuplzJS3E-kSBmtLoNJPDtbj2Pk.ttf
  • f####.news/wp-content/plugins/content_timeline/js/frontend/jquery.easing.1.3.js?ver=####
  • nyct####.com/js/63601.js
  • r####.####.com/log?key=####&action=####
  • b####.####.com/js/sb.min.js?v=####
  • searcht####.com/jquery-1.11.0.min.js
  • s####.####.com/e-201709.js
  • frank####.####.com/count.js
  • 25wfbnp####.ru/Look%20Search%20Trace_files/style.css
  • f####.news/wp-content/plugins/buddypress/bp-core/js/widget-members.min.js?ver=####
  • c####.####.com/t.php?sc_project=####&java=####&security=####&u1=####&sc_random=####&jg=####&rr=####&resolution=####&h=####&camefrom=####&u=####&t=####...
  • s####.####.com/js/gprofiles.js?ver=####
  • f####.news/wp-content/plugins/content_timeline/css/frontend/timeline.css?ver=####
  • f####.news/wp-content/plugins/addthis/css/output.css?ver=####
  • f####.news/wp-content/plugins/buddypress/bp-core/js/vendor/jquery-scroll-to.min.js?ver=####
  • f####.news/wp-content/themes/15zine/library/css/font-awesome-4.4.0/css/font-awesome.min.css?ver=####
  • beac####.net/wp-content/uploads/2015/12/aeb0434e60c067648f9e887ceca41b9e.jpg
  • m####.####.com/live/boost/ra-5746f043a881b1ec/_ate.track.config_resp
  • f####.news/wp-content/uploads/2015/08/logo-1.png
  • cloudfr####.####.com/x.png
  • s####.####.com/wp-content/js/devicepx-jetpack.js?ver=####
  • f####.####.com/s/ptsansnarrow/v7/Q_pTky3Sc3ubRibGToTAYsLoeaHq4xHkvX1Lp5aKUY8.ttf
  • f####.news/wp-content/themes/15zine/library/js/cb-scripts.min.js?ver=####
  • f####.news/wp-content/uploads/2015/08/logo.png
  • f####.####.com/s/ptsansnarrow/v7/UyYrYy3ltEffJV9QueSi4VLE0juxe_YrR4_5kH0wfhI.ttf
  • f####.news/wp-includes/js/comment-reply.min.js?ver=####
  • s####.####.com/css/services.css?ver=####
  • m####.####.com/live/red_lojson/100eng.json?sh=####&ph=####&ivh=####&dt=####&ict=####&pct=####&cmenu=####&ppd=####&ppl=####&fbe=####&xmv=####&xms=####&...
  • f####.news/wp-content/plugins/ultimate-branding/ultimate-branding-files/modules/custom-admin-bar-files/css/general.css?ver=####
  • s####.####.com/css/hovercard.css?ver=####
  • f####.news/wp-content/plugins/ginger/front/css/cookies-enabler-dialog.css?ver=####
  • statcou####.com/counter/counter.js
  • f####.####.com/s/opensans/v13/cJZKeOuBrn4kERxqtaUH3SZ2oysoEQEeKwjgmXLRnTc.ttf
  • p####.####.com/iap/636aeeb246e063ca
  • a####.####.com/j/roundtrip.js
  • f####.news/
  • s####.####.com/js/300/addthis_widget.js
  • f####.news/wp-content/plugins/disqus-comment-system/media/js/count.js?ver=####
  • f####.news/wp-content/plugins/content_timeline/js/frontend/rollover.js?ver=####
  • searcht####.com/player/videojs/video.min.js
  • f####.news/wp-includes/js/wp-embed.min.js?ver=####
  • f####.news/wp-includes/js/jquery/ui/draggable.min.js?ver=####
  • l####.direct/zkK
  • f####.news/wp-includes/js/jquery/jquery.js?ver=####
  • f####.news/wp-includes/js/jquery/jquery-migrate.min.js?ver=####
  • nyct####.com/Track/Capture.aspx?retType=####&trk_user=####&trk_sw=####&trk_sh=####&trk_ref=####&trk_tit=####&trk_loc=####&trk_agn=####&trk_agv=####&tr...
  • beac####.net/wp-content/uploads/2016/04/d940e7e7f943d0acb8391c8a73a0e5a8.jpg
  • searcha####.com/xml/jsfeed_r.js?aff=####&saff=####
  • s####.####.com/static/sh_mobile.0d19417fd0a004d73df6a35b.html
  • f####.news/wp-content/plugins/category-specific-rss-feed-menu/wp_cat_rss_style.css
  • b####.####.com/subscribebutton/subscribe
  • b####.####.com/img/subscribe-button/button.png?v=####
  • 25wfbnp####.ru/site_real.php?session_param=####
  • f####.news/wp-content/plugins/buddypress/bp-core/js/vendor/jquery-cookie.min.js?ver=####
  • f####.news/wp-content/plugins/content_timeline/js/frontend/jquery.mCustomScrollbar.min.js?ver=####
  • f####.####.com/css?family=####
  • f####.news/wp-content/themes/15zine/plugins/login-with-ajax/widget.css?ver=####
  • b####.####.com/js/subscribebutton.noncc.min.js?h=####
  • f####.news/wp-content/plugins/content_timeline/js/frontend/jquery.mousewheel.min.js?ver=####
  • f####.news/wp-content/themes/15zine/buddypress/css/buddypress.css?ver=####
  • f####.news/wp-content/plugins/jetpack/_inc/social-logos/social-logos.min.css?ver=####
  • f####.news/wp-content/themes/15zine/library/css/font-awesome-4.4.0/fonts/fontawesome-webfont.ttf?v=####
  • f####.news/wp-content/plugins/content_timeline/css/frontend/prettyPhoto.css?ver=####
  • f####.news/wp-content/plugins/jetpack/modules/photon/photon.js?ver=####
  • ab534d6####.####.net/test.png
  • f####.####.com/css?family=####&ver=####
  • f####.news/wp-content/plugins/buddypress/bp-templates/bp-legacy/js/buddypress.min.js?ver=####
  • 5####.####.196/?z=####
  • searcht####.com/videotest.php?aff=####&saff=####&filter=####
  • f####.news/wp-includes/js/jquery/ui/core.min.js?ver=####
  • f####.news/wp-content/plugins/bloom/css/style.css?ver=####
  • f####.news/wp-content/plugins/jetpack/modules/wpgroho.js?ver=####
  • f####.news/wp-content/plugins/addthis-all/frontend/build/addthis_wordpress_public.min.css?ver=####
  • 1####.####.235/live/red_lojson/300lo.json?si=####&bkl=####&bl=####&sid=####&pub=####&rev=####&ln=####&pc=####&cb=####&ab=####&dp=####&fp=####&fr=####&...
  • f####.news/wp-content/plugins/buddypress/bp-core/js/jquery-query.min.js?ver=####
  • f####.news/wp-includes/js/wp-emoji-release.min.js?ver=####
  • f####.news/wp-admin/admin-ajax.php?action=####&ver=####
  • r####.####.com/log?key=####&action=####&token=####
  • p####.####.com/iap/636aeeb246e063ca?cookieQ=####
  • f####.news/wp-content/plugins/content_timeline/css/frontend/jquery.mCustomScrollbar.css?ver=####
  • google-####.com/r/collect?v=####&_v=####&a=####&t=####&_s=####&dl=####&ul=####&de=####&dt=####&sd=####&sr=####&vp=####&je=####&_u=####&jid=####&cid=##...
  • f####.news/wp-content/plugins/jetpack/css/jetpack.css?ver=####
  • f####.news/wp-content/plugins/buddypress/bp-core/js/confirm.min.js?ver=####
  • f####.news/wp-content/plugins/content_timeline/js/frontend/jquery.prettyPhoto.js?ver=####
  • f####.news/wp-includes/js/jquery/ui/mouse.min.js?ver=####
  • f####.news/wp-content/plugins/content_timeline/js/frontend/jquery.timeline.min.js?ver=####
  • f####.news/wp-content/themes/15zine/library/js/modernizr.custom.min.js?ver=####
  • f####.news/wp-content/plugins/ginger/front/js/cookies-enabler.min.js?ver=####
  • f####.news/wp-content/plugins/bloom/js/custom.js?ver=####
HTTP POST requests:
  • 25wfbnp####.ru/apk_sub.php?get_hash=####
  • 25wfbnp####.ru/cpc_v2.php?get_hash=####
  • 5####.####.196/?z=####
Modified file system:
Creates the following files:
  • /data/data/####/cache/webviewCacheChromium/f_00002f
  • /data/data/####/cache/webviewCacheChromium/f_00002e
  • /data/data/####/cache/webviewCacheChromium/f_00002d
  • /data/data/####/cache/webviewCacheChromium/f_00002c
  • /data/data/####/cache/webviewCacheChromium/f_00002b
  • /data/data/####/cache/webviewCacheChromium/f_00002a
  • /data/data/####/cache/webviewCacheChromium/f_000052
  • /data/data/####/cache/webviewCacheChromium/f_000053
  • /data/data/####/cache/webviewCacheChromium/f_000050
  • /data/data/####/cache/webviewCacheChromium/f_000051
  • /data/data/####/cache/webviewCacheChromium/f_000056
  • /data/data/####/cache/webviewCacheChromium/f_000057
  • /data/data/####/cache/webviewCacheChromium/f_000054
  • /data/data/####/cache/webviewCacheChromium/f_000055
  • /data/data/####/cache/webviewCacheChromium/data_3
  • /data/data/####/cache/webviewCacheChromium/data_2
  • /data/data/####/cache/webviewCacheChromium/f_000058
  • /data/data/####/cache/webviewCacheChromium/f_000059
  • /data/data/####/databases/webviewCookiesChromium.db-journal
  • /data/data/####/cache/webviewCacheChromium/f_00005b
  • /data/data/####/cache/webviewCacheChromium/f_00005c
  • /data/data/####/cache/webviewCacheChromium/f_00005a
  • /data/data/####/cache/webviewCacheChromium/f_00005f
  • /data/data/####/cache/webviewCacheChromium/f_00005d
  • /data/data/####/cache/webviewCacheChromium/f_00005e
  • /data/data/####/databases/webview.db-journal
  • /data/data/####/cache/webviewCacheChromium/f_000026
  • /data/data/####/cache/webviewCacheChromium/f_000025
  • /data/data/####/cache/webviewCacheChromium/f_000024
  • /data/data/####/cache/webviewCacheChromium/f_000023
  • /data/data/####/cache/webviewCacheChromium/f_000022
  • /data/data/####/cache/webviewCacheChromium/f_000021
  • /data/data/####/cache/webviewCacheChromium/f_000020
  • /data/data/####/cache/webviewCacheChromium/f_000029
  • /data/data/####/cache/webviewCacheChromium/f_000028
  • /data/data/####/cache/webviewCacheChromium/index
  • /data/data/####/cache/webviewCacheChromium/f_000081
  • /data/data/####/cache/webviewCacheChromium/f_000080
  • /data/data/####/cache/webviewCacheChromium/f_00000a
  • /data/data/####/cache/webviewCacheChromium/f_00000c
  • /data/data/####/cache/webviewCacheChromium/f_00000b
  • /data/data/####/cache/webviewCacheChromium/f_00000e
  • /data/data/####/cache/webviewCacheChromium/f_000083
  • /data/data/####/cache/webviewCacheChromium/f_00000f
  • /data/data/####/cache/webviewCacheChromium/f_000034
  • /data/data/####/cache/webviewCacheChromium/f_000035
  • /data/data/####/cache/webviewCacheChromium/f_000036
  • /data/data/####/cache/webviewCacheChromium/f_000037
  • /data/data/####/cache/webviewCacheChromium/f_000030
  • /data/data/####/cache/webviewCacheChromium/f_000031
  • /data/data/####/cache/webviewCacheChromium/f_000032
  • /data/data/####/cache/webviewCacheChromium/f_000033
  • /data/data/####/cache/webviewCacheChromium/f_000038
  • /data/data/####/cache/webviewCacheChromium/f_000039
  • /data/data/####/cache/webviewCacheChromium/f_000084
  • /data/data/####/cache/webviewCacheChromium/data_0
  • /data/data/####/shared_prefs/MyPref.xml
  • /data/data/####/cache/webviewCacheChromium/f_000016
  • /data/data/####/cache/webviewCacheChromium/f_000013
  • /data/data/####/cache/webviewCacheChromium/f_000010
  • /data/data/####/cache/webviewCacheChromium/f_000011
  • /data/data/####/cache/webviewCacheChromium/f_00003d
  • /data/data/####/cache/webviewCacheChromium/f_00003e
  • /data/data/####/cache/webviewCacheChromium/f_00003f
  • /data/data/####/cache/webviewCacheChromium/f_000082
  • /data/data/####/cache/webviewCacheChromium/f_000085
  • /data/data/####/cache/webviewCacheChromium/f_00003a
  • /data/data/####/cache/webviewCacheChromium/f_00003b
  • /data/data/####/cache/webviewCacheChromium/f_00003c
  • /data/data/####/cache/webviewCacheChromium/f_00001b
  • /data/data/####/cache/webviewCacheChromium/f_000017
  • /data/data/####/cache/webviewCacheChromium/f_000009
  • /data/data/####/cache/webviewCacheChromium/f_000008
  • /data/data/####/cache/webviewCacheChromium/f_000001
  • /data/data/####/cache/webviewCacheChromium/f_000003
  • /data/data/####/cache/webviewCacheChromium/f_000002
  • /data/data/####/cache/webviewCacheChromium/f_000005
  • /data/data/####/cache/webviewCacheChromium/f_000004
  • /data/data/####/cache/webviewCacheChromium/f_000007
  • /data/data/####/cache/webviewCacheChromium/f_000006
  • /data/data/####/cache/webviewCacheChromium/data_1
  • /data/data/####/cache/webviewCacheChromium/f_00001c
  • /data/data/####/cache/webviewCacheChromium/f_000014
  • /data/data/####/shared_prefs/MyPref.xml.bak
  • /data/data/####/cache/webviewCacheChromium/f_00000d
  • /data/data/####/cache/webviewCacheChromium/f_000018
  • /data/data/####/cache/webviewCacheChromium/f_000019
  • /data/data/####/cache/webviewCacheChromium/f_00006c
  • /data/data/####/cache/webviewCacheChromium/f_00006b
  • /data/data/####/cache/webviewCacheChromium/f_00006a
  • /data/data/####/cache/webviewCacheChromium/f_000015
  • /data/data/####/cache/webviewCacheChromium/f_000012
  • /data/data/####/cache/webviewCacheChromium/f_00006f
  • /data/data/####/cache/webviewCacheChromium/f_00006e
  • /data/data/####/cache/webviewCacheChromium/f_00006d
  • /data/data/####/cache/webviewCacheChromium/f_00001a
  • /data/data/####/cache/webviewCacheChromium/f_000069
  • /data/data/####/cache/webviewCacheChromium/f_000068
  • /data/data/####/cache/webviewCacheChromium/f_000063
  • /data/data/####/cache/webviewCacheChromium/f_000062
  • /data/data/####/cache/webviewCacheChromium/f_000061
  • /data/data/####/cache/webviewCacheChromium/f_000060
  • /data/data/####/cache/webviewCacheChromium/f_000067
  • /data/data/####/cache/webviewCacheChromium/f_000066
  • /data/data/####/cache/webviewCacheChromium/f_000065
  • /data/data/####/cache/webviewCacheChromium/f_000064
  • /data/data/####/cache/webviewCacheChromium/f_000078
  • /data/data/####/cache/webviewCacheChromium/f_000079
  • /data/data/####/cache/webviewCacheChromium/f_000070
  • /data/data/####/cache/webviewCacheChromium/f_000071
  • /data/data/####/cache/webviewCacheChromium/f_000072
  • /data/data/####/cache/webviewCacheChromium/f_000073
  • /data/data/####/cache/webviewCacheChromium/f_000074
  • /data/data/####/cache/webviewCacheChromium/f_000075
  • /data/data/####/cache/webviewCacheChromium/f_000076
  • /data/data/####/cache/webviewCacheChromium/f_000077
  • /data/data/####/cache/webviewCacheChromium/f_00004e
  • /data/data/####/cache/webviewCacheChromium/f_00004d
  • /data/data/####/cache/webviewCacheChromium/f_00004f
  • /data/data/####/cache/webviewCacheChromium/f_00004a
  • /data/data/####/cache/webviewCacheChromium/f_00004c
  • /data/data/####/cache/webviewCacheChromium/f_00004b
  • /data/data/####/cache/webviewCacheChromium/f_00001f
  • /data/data/####/cache/webviewCacheChromium/f_00001d
  • /data/data/####/cache/webviewCacheChromium/f_00001e
  • /data/data/####/cache/webviewCacheChromium/f_000049
  • /data/data/####/cache/webviewCacheChromium/f_000048
  • /data/data/####/cache/webviewCacheChromium/f_000045
  • /data/data/####/cache/webviewCacheChromium/f_000044
  • /data/data/####/cache/webviewCacheChromium/f_000047
  • /data/data/####/cache/webviewCacheChromium/f_000046
  • /data/data/####/cache/webviewCacheChromium/f_000041
  • /data/data/####/cache/webviewCacheChromium/f_000040
  • /data/data/####/cache/webviewCacheChromium/f_000043
  • /data/data/####/cache/webviewCacheChromium/f_000042
  • /data/data/####/cache/webviewCacheChromium/f_00007a
  • /data/data/####/cache/webviewCacheChromium/f_00007b
  • /data/data/####/cache/webviewCacheChromium/f_00007c
  • /data/data/####/cache/webviewCacheChromium/f_00007d
  • /data/data/####/cache/webviewCacheChromium/f_00007e
  • /data/data/####/cache/webviewCacheChromium/f_00007f
  • /data/data/####/cache/webviewCacheChromium/f_000027
Miscellaneous:
Uses administrator priveleges.
Contains functionality to send SMS messages automatically.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android